What problem does it solve?
This Skill audits an existing multi-tenant system to determine whether one tenant can reach another tenant's data, metadata, or privileged surfaces. It focuses on evidence-backed isolation review rather than design advice, so findings are grounded in real code, schemas, and operational paths.
Core Features & Use Cases
- Cross-surface isolation review: Checks identity, data, API, storage, logs, analytics, support tooling, exports, imports, background jobs, search, AI retrieval, billing, feature flags, and audit paths.
- Evidence-based findings: Produces severity-ranked isolation issues with file and line evidence plus a concrete tenant A to tenant B leak scenario.
- Negative testing and coverage gaps: Builds an isolation test matrix, defines denial-oriented tests, and reports an explicit not-inspected list for surfaces not reviewed.
- Use Case: Use this skill before onboarding a regulated enterprise customer, after a suspected cross-tenant incident, or when a new tenant-facing surface such as export, search, or AI chat is introduced.
Quick Start
Review the repository or design artifact and assess whether tenant isolation is sound across every surface, then return severity-ranked findings, negative tests, and a not-inspected list.