hunt-business-logic

Detect business logic vulnerabilities in checkout, verification, and access control flows.

Updated Jun 24, 2026
One-click install
npx skills add https://github.com/Skobyn/talon --skill hunt-business-logic-skobyn
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hunt-business-logic
Source: https://github.com/Skobyn/talon/tree/main/skills/hunt-business-logic
Command: npx skills add https://github.com/Skobyn/talon --skill hunt-business-logic-skobyn

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This skill helps identify and address business logic vulnerabilities that can lead to significant financial and privacy breaches.

Core Features & Use Cases

  • Business Logic Vulnerability Detection: Identifies coupon-race-stacking, negative quantity tampering, and price field overflows.
  • Targeted at High-Value Platforms: Focuses on e-commerce, payment platforms, and gig economy apps.
  • Attack Surface Analysis: Provides signals to watch for, including URL patterns, response headers, and tech stack indicators.
  • Hunting Methodology: Outlines a systematic approach to mapping authentication boundaries, identifying verification flows, and validating business impact.

Quick Start

To initiate a business logic vulnerability hunt, use the 'hunt-business-logic' command with your target application in plain English.

Frequently Asked Questions about hunt-business-logic

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect business logic vulnerabilities in payment platforms?

Business logic vulnerabilities in payment platforms are detected by analyzing checkout flows for coupon-race-stacking, negative quantity tampering, and price field overflows. This skill targets financial transaction intersection points to identify high-impact security flaws.

What is a systematic hunting methodology for e-commerce security testing?

Systematic hunting methodology maps authentication boundaries, identifies verification flows, and validates business impact. It targets e-commerce platforms by analyzing URL patterns, response headers, and tech stack indicators to uncover vulnerabilities.

Can this skill identify access control flaws in gig economy apps?

Yes, it identifies access control flaws in gig economy apps by targeting identity verification and access control intersection points. The analysis focuses on high-value platforms to detect vulnerabilities leading to significant privacy breaches.

What specific business logic vulnerabilities should I look for during bug bounty hunting?

During bug bounty hunting, look for business logic vulnerabilities like coupon-race-stacking, negative quantity tampering, and price field overflows. These flaws typically occur at financial transaction and identity verification intersection points.

Does hunting for business logic vulnerabilities require prior security testing expertise?

Hunting for business logic vulnerabilities requires expertise in security testing to validate business impact effectively. The skill demands understanding authentication boundaries and verification flows to focus on high-impact vulnerabilities across targeted platforms.

How do I map attack surfaces for internal verification systems?

Map attack surfaces for internal verification systems by analyzing URL patterns, response headers, and tech stack indicators. This skill provides specific signals and outlines a methodology for mapping authentication boundaries and identifying verification flows.