web-app-logic

Map web application logic vulnerabilities to actionable test scenarios.

3|1|Updated May 26, 2026
One-click install
npx skills add https://github.com/LeoWSY-hashblue/-communitytools-custom --skill web-app-logic-leowsy-hashblue
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: web-app-logic
Source: https://github.com/LeoWSY-hashblue/-communitytools-custom/tree/main/skills/web-app-logic
Command: npx skills add https://github.com/LeoWSY-hashblue/-communitytools-custom --skill web-app-logic-leowsy-hashblue

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Web App Logic Testing helps security teams quickly identify and exploit common logic flaws in web applications.

Core Features & Use Cases

  • Comprehensive coverage of business logic, access control, race conditions, and cache deception.
  • Provides end-to-end workflows from discovery to PoC to reporting.
  • Use cases include IDOR, parameter pollution, multi-step bypass, and information leakage scenarios.

Quick Start

Describe the target web application and request a starter PoC to test business logic, access control, and information-disclosure scenarios.

Frequently Asked Questions about web-app-logic

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find business logic flaws in a web application?▼

To find business logic flaws, this skill maps web application logic vulnerabilities to actionable test scenarios, covering access control, multi-step bypass, and parameter pollution from discovery to reporting.

What is the best way to test for IDOR and information disclosure vulnerabilities?▼

Testing for IDOR and information disclosure involves structured discovery and repeatable testing guidance. This skill provides end-to-end workflows to safely evaluate these access control and leakage scenarios.

How can I safely detect race conditions and web cache poisoning?▼

You can safely detect race conditions and cache deception by requesting a starter proof of concept. The skill enforces structured discovery with safety checks before evaluating these logic vulnerabilities.

Can I generate a PoC for web application access control bypasses?▼

Yes, you can generate a starter PoC for web application access control bypasses. Describe the target web application to receive actionable test scenarios for multi-step bypass and IDOR evaluation.

Does web logic testing require specific frameworks or dependencies?▼

Web logic testing using this skill requires no specific dependencies or external components. You only need to describe the target web application to begin the AI-assisted evaluation of logic flaws.

What is included in the workflow for reporting web security logic flaws?▼

The reporting workflow for web security logic flaws includes reconnaissance, reference material curation, proof of concept generation, and clearly defined outcomes to map vulnerabilities to actionable test scenarios.