logic-scan

Detect business logic vulnerabilities in web application workflows.

1|Updated Mar 20, 2026
One-click install
npx skills add https://github.com/enderphan94/pentest-kit --skill logic-scan
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: logic-scan
Source: https://github.com/enderphan94/pentest-kit/tree/main/skills/logic-scan
Command: npx skills add https://github.com/enderphan94/pentest-kit --skill logic-scan

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill streamlines the process of identifying business logic flaws in web applications, helping security teams find critical vulnerabilities automatically.

Core Features & Use Cases

  • Workflow Testing: Checks multi-step workflows for bypasses, race conditions, and privilege escalations.
  • Parameter Manipulation: Detects manipulation possibilities for prices, quantities, and discounts.
  • Vulnerability Reporting: Compiles detailed JSON and Markdown reports of findings to assist security reviews.
  • Use Case: Security analysts can quickly evaluate an e-commerce platform for logical flaws that could lead to financial exploits or data breaches by running targeted workflows with minimal manual effort.

Quick Start

Run the logic-scan skill on your target URL to perform a comprehensive business logic security test.

Frequently Asked Questions about logic-scan

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate business logic vulnerability assessments for web applications?

You can automate business logic vulnerability assessments by running targeted workflows against a target URL to detect bypasses, race conditions, and privilege escalations with minimal manual setup.

What are business logic vulnerabilities and how does automated security testing find them?

Business logic vulnerabilities are flaws in multi-step workflows allowing parameter manipulation or privilege escalation, found by applying automated security testing to detect bypasses and race conditions.

How do I test e-commerce workflows for price and discount manipulation flaws?

Test e-commerce workflows for price and discount manipulation by running automated parameter manipulation checks across multi-step processes to identify financial exploit possibilities.

Can I generate JSON and Markdown reports for penetration testing findings?

Yes, you can generate detailed JSON and Markdown reports of vulnerability findings to assist security reviews and document penetration testing results comprehensively.

Does business logic scanning require extensive manual configuration to detect privilege escalation?

No, business logic scanning requires minimal setup to automatically identify and report critical flaws like privilege escalations without extensive manual configuration.

What is the best way to detect race conditions during security auditing?

The best way to detect race conditions during security auditing is using automated workflow testing that checks multi-step processes for bypasses and timing flaws.