business-logic-vuln
Entry P1 category router for business logic testing. Use when workflow abuse, race conditions, pricing flaws, or multi-step state attacks matter more than parser-level input injection.
来源信息
- 仓库
- Kur1sulab/blackbox
- 最近来源活动
- 2026年8月12日 15:17
- 检测到的 SKILL.md 语言
- 英语
- 星标
- 3
- 分支
- 1
安装方式
默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。
检查来源文件
决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。
正在显示 SKILL.md
SKILL.md
来源说明 · 只读预览- name
- business-logic-vuln
- description
- Entry P1 category router for business logic testing. Use when workflow abuse, race conditions, pricing flaws, or multi-step state attacks matter more than parser-level input injection.
# Business Logic Router
This is the routing entry point for business-logic and state-machine issues.
## When to Use
- The target involves coupons, inventory, payment, approvals, quotas, invites, trials, or state transitions
- The issue is not parser-level; it is about when checks happen and which business conditions are checked
- You suspect race conditions, workflow bypass, price tampering, negative values, stacked discounts, or multi-step flaws
## Skill Map
- [Business Logic Vulnerabilities](../hack-business-logic-vulnerabilities/SKILL.md)
## Recommended Flow
1. First map key business states and one-time actions
2. Then check for check-then-act windows, sequence dependencies, or missing cross-step authorization
3. If the chain depends on APIs, uploads, or object permissions, return to the corresponding router skill to complete the path
## Related Categories
- [api-sec](../hack-api-sec/SKILL.md)
- [auth-sec](../hack-auth-sec/SKILL.md)
- [file-access-vuln](../hack-file-access-vuln/SKILL.md)
在 GitHub 查看