Skip to main content
Exécutez n'importe quel Skill dans Manus
en un clic

hunt-business-logic

// Hunting skill for business logic vulnerabilities. Built from 12 public bug bounty reports. Covers coupon-race-stacking (Instacart, Stripe, Reverb), negative-quantity-in-cart price tampering (Upserve, Eternal/Zomato), decimal/fraction price-field overflow (Shipt), client-side checkout amount trust on PayPal redirect (WordPress.org), price-per-unit mass-assignment (Krisp), and archived-price swap / cart-TOCTOU (Stripe). Use when hunting business logic — heavy emphasis on financial-impact-demonstrated cases.

$ git log --oneline --stat
stars:1 380
forks:195
updated:25 mai 2026 à 20:56
SKILL.md
readonly