What problem does it solve? Shallow endpoint scanning misses the high-impact business logic flaws that live inside workflows like billing, invites, and account recovery. This Skill turns a single workflow name into a deep, structured manual testing plan covering actors, objects, states, shapes, timing, and side effects. ## Core Features & Use Cases - Workflow Playbooks: Pre-built attack priorities and first tests for 15 workflows including recovery, invite, billing, graphql, import, export, roles, ai, race, oauth, saml, upload, and webhook. - Six-Boundary Test Loop: Systematically covers actor, object, state, shape, time, and side-effect boundaries so no class of business logic flaw is skipped. - Actionable Output Contract: Produces an attack matrix, first 10 manual tests, chain candidates, evidence list, and stop conditions ready to run in Burp or Caido. - Use Case: During a bug bounty engagement, invoke /deep-hunt billing to get targeted tests like refund-without-entitlement-revocation, coupon race conditions, and stale idempotency key reuse instead of generic endpoint fuzzing. ## Quick Start Ask the agent to run /deep-hunt billing against your authorized target and execute the returned first ten manual tests in Burp Suite.