pentest-business-logic

Official

Find and validate business-logic vulnerabilities.

Authorjd-opensource
Version1.0.0
Installs0

System Documentation

What problem does it solve?

Identify and test business logic vulnerabilities that arise from flawed workflow enforcement, inappropriate rule validation, and brittle state-machine behavior in applications.

Core Features & Use Cases

  • Workflow Mapping: Map multi-step processes (checkout, onboarding, approvals) from recon deliverables and source code, documenting expected state transitions and constraints.
  • Rule Extraction: Identify server-side business constraints (pricing, quantity, role gating, time-based rules, discounts) to validate enforceability.
  • Step Circumvention: Attempt to bypass prerequisite steps, reorder actions, or replay complete flows to verify server-side safeguards.
  • Data Integrity Abuse: Submit boundary and crafted inputs (negative quantities, zero prices, type confusion) to reveal validation gaps.
  • Function Limit Bypass: Test per-user or per-session limits (coupon uses, referrals, votes) under stress or parallel requests.
  • File Upload Logic: Assess file type handling and payload boundaries for uploads, including polyglot considerations.
  • Payment Testing: Validate price calculations, discounts, and payment state transitions across the flow.

Quick Start

Run a controlled business-logic security assessment on a target application by mapping workflows and validating constraints with Burp and Playwright.

Dependency Matrix

Required Modules

None required

Components

references

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: pentest-business-logic
Download link: https://github.com/jd-opensource/JoySafeter/archive/main.zip#pentest-business-logic

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 223,000+ vetted skills library on demand.