# Pentest Business Logic Abuse

> Business logic and workflow abuse assessment for state-machine manipulation, race conditions, replay, quota abuse, order-of-operations flaws, delegated execution abuse, and unauthorized state transitions. Hands off to recon, input/protocol, exploit, or reporting workflows when those become the owner phase.

- Skill: `crtvrffnrt/pentest-business-logic-abuse` (Agent Skill)
- Install (CLI): `npx skillmds@latest add crtvrffnrt/pentest-business-logic-abuse`
- Raw SKILL.md: https://api.skillmd.com/api/skills/crtvrffnrt/pentest-business-logic-abuse/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: crtvrffnrt (https://skillmd.com/u/crtvrffnrt)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/crtvrffnrt/pentest-business-logic-abuse

---


# Business Logic Abuse

## Use When
- The main question is workflow bypass, race condition, replay, quota abuse, confused deputy behavior, or unauthorized state transition.
- A mapped workflow has meaningful business impact if steps are reordered, skipped, repeated, or delegated.

## Handoff Criteria
- Hand off to `pentest-web-application-logic-mapper` when the workflow is not mapped well enough to test.
- Hand off to `pentest-input-protocol-manipulation` when parser or payload behavior becomes the main blocker.
- Hand off to `pentest-exploit-execution-payload-control` only after a deterministic business-logic primitive exists.

## Output Schema
- Workflow model: `step`, `required controls`, `bypass hypothesis`
- Abuse sequence: ordered requests/events with timing notes
- Impact proof: unauthorized state change and resulting capability

## Instructions
1. Model intended state transitions before adversarial testing.
2. Identify assumptions in sequencing, concurrency, and cross-system coordination.
3. Execute minimal abuse sequences that challenge those assumptions.
4. Confirm impact through observable unauthorized state or action outcomes.
5. Validate whether fixes require control relocation, not only input filtering.
6. Hand off only confirmed primitives for exploit execution.

## Verification Gate
- Treat logic abuse as system-behavior testing, not payload-only testing.
- Use time-aware evidence for race and replay cases.
- Include reversible test design for stateful systems.
- Report logic flaws only with demonstrated unauthorized effect.
- Use controls for expected state, unauthorized state, and replay/race timing.
- Keep concurrency low and stop when capability is proven.

