Business logic vulnerability testing for web/mobile/API engagements. Covers workflow bypass, state machine violations, multi-step process abuse, price/quantity/discount manipulation, currency confusion, coupon stacking, refund/chargeback abuse, race conditions on logic boundaries, parameter tampering for hidden flows, role/tenant boundary violations, time-of-check vs use, anti-automation defeat, fraud-detection evasion, and subscription/quota abuse. Use when scoping an application after surface-level OWASP Top 10 has been covered, or when the asset is a transactional/marketplace/fintech/e-commerce/SaaS app where logic flaws produce direct financial impact.
72
89%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Security
2 findings: 1 critical severity, 1 medium severity. Installing this skill is not recommended: please review these findings carefully if you do intend to do so.
Detected high-risk code patterns in the skill content — including its prompts, tool definitions, and resources — such as data exfiltration, backdoors, remote code execution, credential theft, system compromise, supply chain attacks, and obfuscation techniques.
This document is high-risk: it provides detailed, actionable techniques for abusing business logic (refund/payout abuse, race conditions, coupon/cart tampering, mass-assignment, endpoint enumeration and anti-rate-limit bypasses) that enable theft, privilege escalation, and large-scale exploitation.
The skill is specifically designed for direct financial operations, giving the agent the ability to move money or execute financial transactions — such as payment processing, cryptocurrency operations, banking integrations, or market order execution.
The document explicitly describes and provides actionable examples for financial operations: skipping/forging payment tokens (checkout/paymentRef), creating refunds with arbitrary amounts, converting refunds to store credit, changing payout account IBAN and racing a withdraw, and invoking /withdraw or /payout endpoints. Those examples are specific, actionable API-level instructions that would enable sending/redirecting funds or issuing refunds — i.e., direct financial execution.
24d7968
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.