CLAUDE CODE MARKETPLACES
SkillsMarketplacesMCPDigestLearnJobsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Web & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web CrawlingAutomation & Workflows
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Learn
  • Feedback
  • Privacy Policy
  • Jobs
  • Advertise

Built for the Claude Code community with Claude Code by @mertduzgun

Independent project, not affiliated with Anthropic
  1. Skills
  2. /
  3. yaklang
  4. /
  5. hack-skills
  6. /
  7. Business Logic Vulnerabilities

Business Logic Vulnerabilities

Editor's Note

This is the playbook for finding bugs scanners never catch: race conditions, price manipulation, workflow bypasses, and state machine gaps. You load it when hunting business logic flaws in checkout flows, coupon systems, multi-step auth, or anywhere trust lives client-side. The main file gives you the attack surface (negative quantities, integer overflows, decimal exploits), METHODOLOGY.md walks through the five-phase workflow and attack matrix, CHECKLIST.md has per-module line items, and SCENARIOS.md drills into payment precision bugs, captcha bypass, password reset flaws, and Turbo Intruder patterns for SMS bombing. Real cases included, like the 0.02 quantity trick that bought ¥500 items for ¥10. This is human-reasoning work, not automation.

Install

npx skills add https://github.com/yaklang/hack-skills --skill business-logic-vulnerabilities
Votes
0
Installs527
GitHub Stars636
Categories
Backend & APIsSecurityDebuggingAutomation & WorkflowsRustCloud & InfrastructureMobile DevelopmentCLI & TerminalOffice & DocumentsFinance & Trading
First SeenMay 16, 2026
View on GitHub

Comments

Login to comment

Related Backend & APIs Skills

View all →
vercel-react-best-practices

vercel-labs/agent-skills

5
402.7k
26.6k
3
React and Next.js performance optimization guide with 64 prioritized rules across 8 categories.
azure-storage

microsoft/azure-skills

0
320.2k
964
Unified access to Azure blob storage, file shares, queues, tables, and data lake services.
entra-app-registration

microsoft/azure-skills

0
320k
964
Microsoft Entra ID app registration, OAuth 2.0 configuration, and MSAL integration for secure application authentication.
azure-resource-visualizer

microsoft/azure-skills

0
319.7k
964
Transform Azure resource groups into detailed architecture diagrams showing resource relationships and configurations.
azure-aigateway

microsoft/azure-skills

0
319.7k
964
Configure Azure API Management as an AI Gateway for models, MCP tools, and agents with built-in governance policies.
remotion-best-practices

remotion-dev/skills

0
312.3k
3.2k
Domain-specific knowledge base for building videos with Remotion and React.