Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Web application logic testing - business logic flaws, race conditions, access control, cache poisoning/deception, and information disclosure.
.claude/skills/transilienceai-web-app-logic/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-08 | ✗→✓ | ▲ Improved | 12% | 0% |
| case-01 | ✓→✓ | = Same ✓ | 31% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 4% | 0% |
| case-03 | ✓→✓ | = Same ✓ | 26% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 17% | 0% |
Test for logic flaws and application-specific vulnerabilities that automated scanners miss.
| Type | Key Vectors | |------|-------------| | Business Logic | Workflow bypass, price manipulation, feature abuse | | Race Conditions | TOCTOU, limit bypass, double-spend, parallel requests | | Access Control | IDOR, horizontal/vertical privilege escalation, forced browsing | | Cache Poisoning | Unkeyed headers/parameters, fat GET, response splitting | | Cache Deception | Path confusion, static extension tricks, normalization | | Info Disclosure | Error messages, debug endpoints, source code, metadata |
reference/business-logic*.md - Business logic testing techniquesreference/race-conditions*.md - Race condition exploitationreference/access-control*.md - Access control bypass methodsreference/web-cache-poisoning*.md - Cache poisoning techniquesreference/web-cache-deception*.md - Cache deception attacksreference/information-disclosure*.md - Information disclosure testingOther measured skills in the registry, with their headline benchmark lift.