CtrlK
BlogDocsLog inGet started
Tessl Logo

offensive-business-logic

Business logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback abuse, race conditions on logic boundaries, parameter tampering for hidden flows, role/tenant boundary violations, time-of-check vs use, anti-automation defeat, fraud-detection evasion, and subscription/quota abuse. Use when scoping an application after surface-level OWASP Top 10 has been covered, or when the asset is a transactional/marketplace/fintech/e-commerce/SaaS app where logic flaws produce direct financial impact.

72

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-structured offensive methodology with executable examples throughout. Its main weakness is progressive disclosure: a long monolithic SKILL.md with no split reference files, plus minor conciseness and validation-checkpoint gaps.

Suggestions

Split the per-category attack catalogs (price/currency, refund/payout, race conditions, subscription/quota, etc.) into one-level-deep reference files (e.g., references/price-manipulation.md) and keep SKILL.md as an overview with a Quick Workflow plus pointers.

Add explicit validation/verification checkpoints to the workflow (e.g., 'confirm the finding reproduces in a clean session before quantifying impact', 'verify state delta via a follow-up GET') to close the workflow-clarity gap.

Trim the motivational intro and consolidate the Engagement Approach / Reporting Hooks prose to reduce token overhead without losing the concrete guidance.

DimensionReasoningScore

Conciseness

Dense and largely action-oriented with minimal concept padding, assuming Claude's competence; a few prose sections (Engagement Approach, Reporting Hooks, motivational intro) could be trimmed, so not fully lean.

4 / 5

Actionability

Copy-paste-ready HTTP requests, bash one-liners, and Python snippets cover the common cases across every attack category, with placeholders justified for a pentest context.

5 / 5

Workflow Clarity

A clear 5-step Quick Workflow and a day-by-day Engagement Approach give a strong sequence, plus a finding-documentation checklist; explicit validate-then-proceed checkpoints are only weakly present, leaving minor validation gaps.

4 / 5

Progressive Disclosure

Well-sectioned with clear headers and a Key References block, but it is a ~390-line monolith with no bundle files; per-category detail that could live in one-level-deep reference files is all inlined.

3 / 5

Total

16

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

An excellent, third-person description that is highly specific, well-triggered, and clearly niche. It answers both what and when with concrete natural-language triggers and minimal conflict risk.

DimensionReasoningScore

Specificity

Lists many concrete actions — workflow bypass, state machine violations, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback abuse, race conditions, parameter tampering, role/tenant boundary violations, TOCTOU, anti-automation defeat, fraud-detection evasion, subscription/quota abuse — giving comprehensive coverage.

5 / 5

Completeness

Explicitly answers both what ('Business logic vulnerability testing... Covers [list]') and when ('Use when scoping an application after surface-level OWASP Top 10 has been covered, or when the asset is a transactional/marketplace/fintech/e-commerce/SaaS app...') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural terms a pentester would say ('business logic vulnerability', 'fintech/e-commerce/SaaS app', 'OWASP Top 10') appear with synonyms across web/mobile/API; file extensions are N/A for this domain so coverage is comprehensive.

5 / 5

Distinctiveness Conflict Risk

Clear niche (offensive business-logic testing) with distinct triggers tied to transactional/fintech/e-commerce/SaaS assets and a post-OWASP-Top-10 scoping condition, minimizing overlap with generic web-app skills.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
SnailSploit/Claude-Red
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.