CtrlK
BlogDocsLog inGet started
Tessl Logo

hunt-business-logic

Hunting skill for business logic vulnerabilities. Built from 12 public bug bounty reports. Covers coupon-race-stacking (Instacart, Stripe, Reverb), negative-quantity-in-cart price tampering (Upserve, Eternal/Zomato), decimal/fraction price-field overflow (Shipt), client-side checkout amount trust on PayPal redirect (WordPress.org), price-per-unit mass-assignment (Krisp), and archived-price swap / cart-TOCTOU (Stripe). Use when hunting business logic — heavy emphasis on financial-impact-demonstrated cases.

69

Quality

85%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

Quality

Content

78%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

Highly actionable content with concrete payloads, a sequenced methodology, and a validation gate, but it is a monolithic single file with no progressive disclosure into reference files, which limits navigation for a 237-line skill.

Suggestions

Split the Disclosed Report Citations and Real Impact Examples into a references/ file (e.g. REPORTS.md) and link to it from the body to improve progressive disclosure.

Tighten the Real Impact Examples narratives to impact-only summaries, moving payload/root-cause detail into the citation references to improve conciseness.

Add a per-step validation or 'expected signal' note to each methodology step so the workflow has checkpoints throughout, not only at Gate 0.

DimensionReasoningScore

Conciseness

The body is mostly lean and assumes Claude's competence, but the Real Impact Examples and Disclosed Report Citations sections carry narrative and per-report detail that could be trimmed; not verbose enough for 3 but not fully tight enough for 5.

4 / 5

Actionability

Provides copy-paste-ready bash/curl/http payloads, concrete grep patterns, and specific endpoint examples that cover the common hunting cases comprehensively.

5 / 5

Workflow Clarity

A clear 7-step methodology is sequenced with a strong Gate 0 validation checkpoint and a refine-before-submitting feedback loop, but individual steps lack per-step validate-retry loops, so it falls just short of a 5.

4 / 5

Progressive Disclosure

No bundle files (references/scripts/assets) exist and the 237-line body keeps detailed citations and scenarios inline; section headers give structure but there are no one-level-deep external references to signal, so it sits between minimal and good organization.

3 / 5

Total

16

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description that names concrete vulnerability subclasses, real platforms, and an explicit use-trigger clause. Trigger-term coverage is good but could add a few more natural synonyms users might say.

DimensionReasoningScore

Specificity

Lists multiple concrete vulnerability subclasses (coupon-race-stacking, negative-quantity-in-cart price tampering, decimal/fraction price-field overflow, client-side checkout amount trust, price-per-unit mass-assignment, archived-price swap / cart-TOCTOU) each tied to named platforms, giving comprehensive coverage of concrete actions.

5 / 5

Completeness

Clearly answers 'what' (enumerated subclasses and covered cases) and 'when' via the explicit trigger clause 'Use when hunting business logic — heavy emphasis on financial-impact-demonstrated cases.'

5 / 5

Trigger Term Quality

Includes natural phrases a user would say ('hunting business logic', 'business logic vulnerabilities') but leans technical and omits common synonyms like 'logic flaw' or 'abuse case' that users might naturally voice.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche (business-logic vuln hunting framed around demonstrated financial impact) with distinct triggers and minimal overlap risk against adjacent hunt-* skills.

5 / 5

Total

19

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

15

/

16

Passed

Repository
elementalsouls/Claude-BugHunter
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.