cyberneticlibrary

Find business logic vulnerabilities

sast-businesslogicskillsetup L30
reasonless-throne486/sast-skills
What it does

Detect business logic vulnerabilities in code

Best for

Finding exploitable gaps in payment, workflow, and authorization logic that scanners miss

Inputs
  • · Codebase under analysis
  • · sast/architecture.md (run sast-analysis first)
Outputs
  • · sast/businesslogic-results.md with findings
  • · Consolidated batch results from subagents
Preconditions
  • · sast/architecture.md must exist
  • · sast-analysis skill must run first
Failure modes
  • · Missing architecture.md causes skill to abort
  • · Incomplete threat modeling misses attack scenarios
  • · Race condition flaws require concurrent request testing
Trust signals
  • · Three-phase approach: threat modeling + batched verify + merge
  • · Covers 9 attack categories with concrete examples
  • · Uses subagents for parallel exploitation testing