What problem does it solve?
This Skill addresses the gap left by automated security scanners, which fail to detect nuanced business logic vulnerabilities that can lead to direct financial loss, unauthorized access, or service abuse. It provides a structured, field-validated approach to identifying these high-impact flaws that are often missed in standard testing workflows.
Core Features & Use Cases
- Field-Validated Methodology: Built from 12 real public bug bounty reports with confirmed financial impact, covering proven high-payout patterns like coupon race stacking, price tampering, verification bypass, and payment webhook abuse.
- Targeted Attack Surface Guidance: Includes specific URL patterns, response signals, JS patterns, and tech stack indicators to quickly identify vulnerable endpoints in e-commerce, SaaS, marketplace, and payment processing platforms.
- Actionable Testing Workflows: Step-by-step hunting methodology, ready-to-use payloads, bypass techniques for common defenses, and a pre-report validation gate to ensure findings have concrete, reproducible impact.
- Use Case: A bug bounty hunter testing an e-commerce platform can use this Skill to systematically identify price tampering flaws in the checkout flow, bypass email verification gates, and test for payment webhook signature validation gaps to submit high-severity, financially impactful reports.
Quick Start
Use the hunt-business-logic skill to systematically test an e-commerce checkout flow for price tampering and verification bypass vulnerabilities.