testing-for-business-logic-vulnerabilities

mukul975/testing-for-business-logic-vulnerabilities · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Identify flaws in application business logic that allow price manipulation, workflow bypass, and privilege escalation beyond what automated scanners can detect.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 1.8 KB
  • 📁scripts
  • ⚙️agent.py 9.0 KB
  • 📄LICENSE 11.0 KB

Related

  1. exploiting-race-condition-vulnerabilities · mukul975 bundle
    Detect and exploit race condition vulnerabilities in web applications using Turbo Intruder's single-packet attack technique to bypass rate limits, duplicate transactions, and exploit time-of-check-to-time-of-use flaws.
    24.6k
    repo stars
  2. testing-for-email-header-injection · mukul975 bundle
    Test web application email functionality for SMTP header injection vulnerabilities that allow attackers to inject additional email headers, modify recipients, and abuse contact forms for spam relay.
    24.6k
    repo stars
  3. attack-chain · zhaoxuya520 bundle
    Orchestrates multi-stage attack-path planning and execution across reconnaissance, initial access, privilege escalation, lateral movement, and impact assessment for authorized penetration testing.
    12.8k
    repo stars
  4. cross-site-scripting-xss-complete-deep-dive · shulkwisec bundle
    Provides a complete deep-dive into Cross-Site Scripting (XSS) with exact payloads and bypass techniques for every PortSwigger lab variant, from apprentice to expert level.
    21
    repo stars
  5. burpsuite-project-parser · trailofbits bundle
    Searches and extracts data from Burp Suite project files (.burp) using the burpsuite-project-file-parser extension, enabling regex searches on response headers and bodies, extraction of security audit findings, and analysis of proxy history and site map data.
    6k
    repo stars
  6. csrf · shulkwisec
    Detect and exploit Cross-Site Request Forgery vulnerabilities by testing for missing or predictable CSRF tokens, absent SameSite cookie attributes, and JSON endpoints accepting text/plain Content-Type, with payloads and bypass techniques for security testing.
    21
    repo stars

Frequently asked questions

How do I install the testing-for-business-logic-vulnerabilities skill?

Run npx skillmds add mukul975/testing-for-business-logic-vulnerabilities in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the testing-for-business-logic-vulnerabilities skill do?

Identify flaws in application business logic that allow price manipulation, workflow bypass, and privilege escalation beyond what automated scanners can detect. It is listed under Security, Productivity, Penetration Testing on SkillMD.

Is testing-for-business-logic-vulnerabilities safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with testing-for-business-logic-vulnerabilities?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is testing-for-business-logic-vulnerabilities free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published testing-for-business-logic-vulnerabilities?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.