From pentest-framework
Tests web app business logic and authorization for flaws like IDOR, privilege escalation, workflow bypass, payment manipulation, and rate limiting using AI agent crawling.
npx claudepluginhub sabania/pentest-cli --plugin pentest-frameworkThis skill is limited to using the following tools:
AI-driven analysis of a target application's business logic. This skill does NOT rely on the pentest CLI — instead, it uses an intelligent agent to crawl, understand, and test the application's workflows for logic flaws.
Identifies business logic flaws in web apps allowing price manipulation, workflow bypass, and privilege escalation during authorized penetration tests beyond automated scanners.
Tests business logic in web apps for price manipulation, workflow bypass, and privilege escalation during authorized penetration tests with Burp Suite and curl.
Tests web apps for business logic flaws enabling price manipulation, workflow bypass, and privilege escalation beyond automated scanners. Guides pentesting with Burp Suite, curl, and manual API tampering.
Share bugs, ideas, or general feedback.
AI-driven analysis of a target application's business logic. This skill does NOT rely on the pentest CLI — instead, it uses an intelligent agent to crawl, understand, and test the application's workflows for logic flaws.
The target URL is provided via $ARGUMENTS. If no URL is provided, ask the user for one.
Parse the target URL from $ARGUMENTS.
Delegate to logic-agent using the Agent tool. The agent performs the following AI-driven analysis:
Phase 1 — Application Crawling & Understanding:
Phase 2 — IDOR Testing:
Phase 3 — Horizontal Privilege Escalation:
Phase 4 — Payment & Pricing Manipulation:
Phase 5 — Workflow Bypass:
Phase 6 — Rate Limiting Bypass:
Phase 7 — Feature Access Control:
Report business logic flaws with detailed exploitation scenarios: