Find business logic vulnerabilities
sast-businesslogicskillsetup L3★0
reasonless-throne486/sast-skills ↗What it does
Detect business logic vulnerabilities in code
Best for
Finding exploitable gaps in payment, workflow, and authorization logic that scanners miss
Inputs
- · Codebase under analysis
- · sast/architecture.md (run sast-analysis first)
Outputs
- · sast/businesslogic-results.md with findings
- · Consolidated batch results from subagents
Preconditions
- · sast/architecture.md must exist
- · sast-analysis skill must run first
Failure modes
- · Missing architecture.md causes skill to abort
- · Incomplete threat modeling misses attack scenarios
- · Race condition flaws require concurrent request testing
Trust signals
- · Three-phase approach: threat modeling + batched verify + merge
- · Covers 9 attack categories with concrete examples
- · Uses subagents for parallel exploitation testing