Agent Skillsyaklang/hack-skills › business-logic-vuln

business-logic-vuln

GitHub

业务逻辑漏洞测试的路由入口,针对优惠券、支付等场景中的竞态条件、工作流绕过及多步状态攻击进行检测,侧重业务流程而非输入解析。

skills/business-logic-vuln/SKILL.md yaklang/hack-skills

Trigger Scenarios

涉及优惠券、库存、支付等业务逻辑的测试 怀疑存在竞态条件、工作流绕过或价格篡改

Install

npx skills add yaklang/hack-skills --skill business-logic-vuln -g -y
More Options

Use without installing

npx skills use yaklang/hack-skills@business-logic-vuln

指定 Agent (Claude Code)

npx skills add yaklang/hack-skills --skill business-logic-vuln -a claude-code -g -y

安装 repo 全部 skill

npx skills add yaklang/hack-skills --all -g -y

预览 repo 内 skill

npx skills add yaklang/hack-skills --list

SKILL.md

Frontmatter
{
    "name": "business-logic-vuln",
    "description": "Entry P1 category router for business logic testing. Use when workflow abuse, race conditions, pricing flaws, or multi-step state attacks matter more than parser-level input injection."
}

Business Logic Router

This is the routing entry point for business-logic and state-machine issues.

When to Use

  • The target involves coupons, inventory, payment, approvals, quotas, invites, trials, or state transitions
  • The issue is not parser-level; it is about when checks happen and which business conditions are checked
  • You suspect race conditions, workflow bypass, price tampering, negative values, stacked discounts, or multi-step flaws

Skill Map

Recommended Flow

  1. First map key business states and one-time actions
  2. Then check for check-then-act windows, sequence dependencies, or missing cross-step authorization
  3. If the chain depends on APIs, uploads, or object permissions, return to the corresponding router skill to complete the path

Related Categories

Version History

  • c9a4b9e Current 2026-07-06 00:22

Same Skill Collection

skills/401-403-bypass-techniques/SKILL.md
skills/active-directory-acl-abuse/SKILL.md
skills/active-directory-certificate-services/SKILL.md
skills/active-directory-kerberos-attacks/SKILL.md
skills/ai-ml-security/SKILL.md
skills/android-pentesting-tricks/SKILL.md
skills/anti-debugging-techniques/SKILL.md
skills/api-auth-and-jwt-abuse/SKILL.md
skills/api-authorization-and-bola/SKILL.md
skills/api-recon-and-docs/SKILL.md
skills/api-sec/SKILL.md
skills/arbitrary-write-to-rce/SKILL.md
skills/auth-sec/SKILL.md
skills/authbypass-authentication-flaws/SKILL.md
skills/binary-protection-bypass/SKILL.md
skills/browser-exploitation-v8/SKILL.md
skills/business-logic-vulnerabilities/SKILL.md
skills/classical-cipher-analysis/SKILL.md
skills/clickjacking/SKILL.md
skills/cmdi-command-injection/SKILL.md
skills/code-obfuscation-deobfuscation/SKILL.md
skills/container-escape-techniques/SKILL.md
skills/cors-cross-origin-misconfiguration/SKILL.md
skills/crlf-injection/SKILL.md
skills/csp-bypass-advanced/SKILL.md
skills/csrf-cross-site-request-forgery/SKILL.md
skills/csv-formula-injection/SKILL.md
skills/dangling-markup-injection/SKILL.md
skills/defi-attack-patterns/SKILL.md
skills/dependency-confusion/SKILL.md
skills/deserialization-insecure/SKILL.md
skills/dns-rebinding-attacks/SKILL.md
skills/email-header-injection/SKILL.md
skills/expression-language-injection/SKILL.md
skills/file-access-vuln/SKILL.md
skills/format-string-exploitation/SKILL.md
skills/graphql-and-hidden-parameters/SKILL.md
skills/hack/SKILL.md
skills/hash-attack-techniques/SKILL.md
skills/heap-exploitation/SKILL.md
skills/http-host-header-attacks/SKILL.md
skills/http-parameter-pollution/SKILL.md
skills/http2-specific-attacks/SKILL.md
skills/idor-broken-object-authorization/SKILL.md
skills/injection-checking/SKILL.md
skills/insecure-source-code-management/SKILL.md
skills/ios-pentesting-tricks/SKILL.md
skills/jndi-injection/SKILL.md
skills/jwt-oauth-token-attacks/SKILL.md

Metadata

Files
0
Version
c9a4b9e
Hash
f03a613f
Indexed
2026-07-06 00:22

Главная - Вики-сайт
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-05 03:55
浙ICP备14020137号-1 $Гость$