Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel…
Install the "sast-businesslogic" agent skill from https://github.com/utkusen/sast-skills/tree/main/sast-files/.agents/skills/sast-businesslogic into .claude/skills/sast-businesslogic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sast-businesslogic", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add utkusen/sast-skills --skill sast-businesslogic -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "sast-businesslogic" agent skill from https://github.com/utkusen/sast-skills/tree/main/sast-files/.agents/skills/sast-businesslogic into .agents/skills/sast-businesslogic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sast-businesslogic", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add utkusen/sast-skills --skill sast-businesslogic -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "sast-businesslogic" agent skill from https://github.com/utkusen/sast-skills/tree/main/sast-files/.agents/skills/sast-businesslogic into .cursor/skills/sast-businesslogic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sast-businesslogic", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add utkusen/sast-skills --skill sast-businesslogic -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "sast-businesslogic" agent skill from https://github.com/utkusen/sast-skills/tree/main/sast-files/.agents/skills/sast-businesslogic into .gemini/skills/sast-businesslogic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sast-businesslogic", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add utkusen/sast-skills --skill sast-businesslogic -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "sast-businesslogic" agent skill from https://github.com/utkusen/sast-skills/tree/main/sast-files/.agents/skills/sast-businesslogic into .github/skills/sast-businesslogic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sast-businesslogic", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add utkusen/sast-skills --skill sast-businesslogic -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "sast-businesslogic" agent skill from https://github.com/utkusen/sast-skills/tree/main/sast-files/.agents/skills/sast-businesslogic into .opencode/skills/sast-businesslogic/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sast-businesslogic", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
sast-businesslogic
GitHub stars
1.3k
Token cost
~5.3k tokens
SKILL.md length
2,596 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
MIT
At a glance
Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel…
Works in 12 steps: Price & Payment Manipulation → Quantity & Numeric Limit Violations → Workflow & Multi-Step Process Bypass → …
Asked to find business logic
SKILL.md covers What are Business Logic…, Business Logic Attack Categories, Execution and Important Reminders
Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
What it does
Sast Businesslogic is an agent skill from utkusen/sast-skills. Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel subagents, 3 scenarios each), and merge (consolidate batch results). Covers price manipulation, workflow bypass, limit violations, race conditions, reward abuse, etc. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/businesslogic-results.md. Use when asked to find business logic, logic flaws, or…
Its SKILL.md is about 5.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Static analysis and SAST, Async programming and Threat modeling. The repository describes itself as: Collection of agent skills to find vulnerabilities inside your web/mobile apps. The licence is MIT.
When your agent uses it
Asked to find business logic
Abuse-of-function bugs
Example prompts
“/sast-businesslogic”
Workflow steps
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit db52227. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Sast Businesslogic loads about 5.3k tokens when it runs. Until then it costs about 140 tokens; SKILL.md has 2,596 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~140
When it runs· the whole SKILL.md, loaded when a task matches
~5.3k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/sast-businesslogic/SKILL.md (or your agent's skills folder).
name
sast-businesslogic
description
Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel subagents, 3 scenarios each), and merge (consolidate batch results). Covers price manipulation, workflow bypass, limit violations, race conditions, reward abuse, etc. Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/businesslogic-results.md. Use when asked to find business logic, logic flaws, or abuse-of-function bugs.
Business Logic Vulnerability Detection
You are performing a focused security assessment to find business logic vulnerabilities in a codebase. This skill uses a three-phase approach with subagents: threat modeling (understand the domain and generate attack scenarios), batched verify (check whether scenarios are exploitable in parallel batches of 3), and merge (consolidate batch results).
Prerequisites: sast/architecture.md must exist. Run the analysis skill first if it doesn't.
What are Business Logic Vulnerabilities
Business logic vulnerabilities arise when an application's intended workflow, rules, or constraints can be manipulated to produce unintended outcomes — without exploiting technical flaws like injection or memory corruption. The attacker operates within the application's own features but uses them in ways the developers did not anticipate.
The core pattern: the application accepts input that is syntactically valid and passes authentication/authorization, but violates a business rule that was never enforced in code.
What Business Logic Vulnerabilities ARE
Submitting a negative quantity to a purchase endpoint, receiving a credit instead of a charge
Applying the same one-time discount coupon multiple times in parallel requests
Skipping the payment step in a multi-step checkout by replaying a later step's request
Posting a rating of 9999 to a movie rating endpoint that should cap ratings at 5
Transferring a negative amount to move money from the recipient to the sender
Redeeming a referral bonus by referring yourself with a second account
Re-using a single-use reset token or voucher that was never invalidated
Purchasing an item that is out of stock due to a race condition between inventory check and reservation
Accessing a premium subscription feature after downgrading to a free plan
Winning an auction by retracting a high bid after others have been eliminated
What Business Logic Vulnerabilities are NOT
Do not flag these as business logic issues:
SQL injection, XSS, RCE, XXE, SSRF, SSTI: These are injection/technical flaws — separate skills cover them
Missing authentication: Endpoint requires no login at all → that's "Unauthenticated Access"
IDOR: Accessing another user's resource by changing an ID → that's a separate access-control class
Brute-force / rate limiting: Generic rate-limit bypass on login → that's not a business logic flaw unless it enables specific business rule circumvention
Business Logic Attack Categories
Use these categories to guide threat modeling. Not all categories apply to every application — identify which ones are relevant based on the architecture summary.
1. Price & Payment Manipulation
Negative prices or zero prices on purchase endpoints
Arbitrary price override in request body (mass assignment of price field)
Currency or unit confusion (e.g., cents vs. dollars)
Floating-point precision abuse in monetary arithmetic
Applying discounts that reduce total below zero
2. Quantity & Numeric Limit Violations
Negative quantities (ordering −5 items to receive a credit)
Quantities exceeding per-user or per-order limits
Integer overflow/underflow in quantity or balance calculations
Out-of-range values for bounded fields (ratings, scores, percentages)
3. Workflow & Multi-Step Process Bypass
Skipping mandatory steps in a sequential process (payment, email verification, ID check)
Replaying a completion token from a previous successful flow to bypass steps
Direct-access to a later-stage endpoint without completing earlier stages
Submitting a terminal state transition without going through intermediate states (state machine violations)
4. Coupon, Discount & Voucher Abuse
Applying the same coupon multiple times (single-use not enforced)
Stacking discounts that were not intended to be combined
Using an expired coupon or voucher
Generating or guessing valid coupon codes
5. Race Conditions & Concurrency Abuse
Double-spending: sending two concurrent purchase requests to consume a balance once
Launch a subagent with the following instructions:
Goal: Analyze the codebase to understand its business domain and generate a concrete, prioritized list of business logic attack scenarios specific to this application. Write results to sast/businesslogic-threats.md.
Context: You will be given the project's architecture summary. Use it to understand what the application does, what features it has, and what business rules it is supposed to enforce. Focus entirely on understanding the domain — do not verify vulnerabilities yet.
Step 1 — Identify the business domain and features:
Read sast/architecture.md and then explore the codebase to answer:
What does this application do? (e-commerce, marketplace, SaaS, social platform, fintech, gaming, booking, etc.)
What financial or transactional features exist? (payments, subscriptions, credits, tokens, wallets, invoices, refunds)
What quantitative limits or rules exist? (ratings, scores, quantities, usage limits, quotas)
What multi-step workflows exist? (checkout, onboarding, KYC, booking, auctions)
What promotional or reward features exist? (coupons, referrals, loyalty points, bonuses, vouchers)
What role or tier distinctions exist? (free vs. paid, user vs. premium, trial vs. full)
What inventory or capacity constraints exist? (stock, seats, slots, bandwidth)
For each relevant business domain area found, generate specific attack scenarios. Each scenario must be:
Specific to this codebase — name the actual endpoint, model, or feature involved
Actionable — describe exactly what an attacker would send/do
Grounded — reference the code or data model that makes this scenario plausible
Use the attack categories below as a checklist. Only include categories that are relevant to this application:
Price/payment manipulation: Can a user send an arbitrary price in the request? Is price trusted from client?
Quantity/value out of range: Can a user send negative quantities, zero, or values exceeding defined limits?
Workflow bypass: Can a user skip a mandatory step in a multi-step process?
Coupon/discount abuse: Can a coupon be used multiple times or after expiration?
Race conditions: Are there check-then-act patterns on shared resources (inventory, balance, coupon usage)?
Refund abuse: Can a refund be requested after the product is consumed?
Reward/referral abuse: Can referral or signup bonuses be farmed?
Entitlement bypass: Are premium features checked at access time or only at subscription time?
Transfer/balance logic: Can negative transfers or self-transfers be made?
Time/date logic: Are time-limited offers enforced server-side?
Inventory logic: Is stock validated atomically before reservation?
Output format — write to sast/businesslogic-threats.md:
markdown
# Business Logic Threat Model: [Project Name]
## Application Domain
[2–3 sentence summary of what the application does and its key business features]
## Business Features Identified
- [Feature 1]: [brief description, relevant models/endpoints]
- [Feature 2]: ...
## Attack Scenarios
### 1. [Short title, e.g. "Negative quantity purchase for credit"]
- **Category**: [e.g. Quantity & Numeric Limit Violations]
- **Target**: [Endpoint or feature, e.g. `POST /api/orders`]
- **Description**: [What an attacker would do and what outcome they expect]
- **Relevant code**: [File and line range where the relevant logic lives]
- **Business rule that should be enforced**: [What the application is supposed to do]
- **Risk level**: [High / Medium / Low]
### 2. ...
[Use sequential numbering ### 3., ### 4., ... for every scenario — required for batching in Phase 2.]
## Categories Not Applicable
[List any categories from the checklist that are not relevant to this application and why]
Show full SKILL.md (1,177 more words)Show less
Phase 2: Verify — Check Whether Scenarios Are Exploitable (Batched)
After Phase 1 completes, read sast/businesslogic-threats.md and split the attack scenarios into batches of up to 3 scenarios each. Launch one subagent per batch in parallel. Each subagent verifies only its assigned scenarios and writes results to its own batch file.
Batching procedure (you, the orchestrator, do this — not a subagent):
Read sast/businesslogic-threats.md and count the numbered scenario sections (### 1., ### 2., etc.).
Divide them into batches of up to 3. For example, 8 scenarios → 3 batches (1–3, 4–6, 7–8).
For each batch, extract the full text of those scenario sections from the threats file.
Launch all batch subagents in parallel, passing each one only its assigned scenarios.
Each subagent writes to sast/businesslogic-batch-N.md where N is the 1-based batch number.
Give each batch subagent the following instructions (substitute the batch-specific values):
Goal: For each assigned attack scenario, determine whether the business rule is properly enforced in code or whether the attack is exploitable. Our goal is to find business logic vulnerabilities. Write results to sast/businesslogic-batch-[N].md.
Your assigned scenarios (from the threat modeling phase):
[Paste the full text of the assigned scenario sections here, preserving the original numbering]
Context: You will be given the project's architecture summary. Use it to understand validation patterns, ORM usage, and where business rules are typically enforced. Trace the code paths referenced in each scenario.
What business logic flaws are NOT — do not flag these here:
SQL injection, XSS, RCE, XXE, SSRF, SSTI: separate skills
Missing authentication: Unauthenticated Access
IDOR: another access-control class
Generic brute-force unless it clearly circumvents a business rule
For each scenario, perform the following checks:
1. Is the business rule enforced server-side?
Is the constraint validated in the backend handler, service layer, or ORM/database?
Or is it only validated client-side (frontend form validation, JavaScript min/max attributes)?
Client-side-only validation = exploitable.
2. Is the validation complete and covers all edge cases?
Does it check for negative values where applicable?
Does it check upper bounds, not just lower bounds?
Does it handle concurrent requests (is the check atomic, or is there a TOCTOU window)?
Does it re-validate at the point of use, not just at an earlier step?
3. For workflow bypass scenarios:
Does each step verify that previous required steps were completed?
Are step completion flags stored server-side (not just in a cookie or session that can be replayed)?
Can a terminal endpoint be called directly without going through earlier steps?
4. For coupon/voucher scenarios:
Is the coupon marked as used atomically with the transaction (in the same DB transaction)?
Is concurrent redemption protected (SELECT FOR UPDATE, optimistic locking, atomic compare-and-swap)?
Is the expiry date checked server-side at redemption time?
5. For race condition scenarios:
Is stock/balance check and decrement done atomically (in a single DB transaction or with row-level locking)?
Is there any idempotency key or deduplication logic to prevent duplicate concurrent requests?
6. For entitlement/subscription scenarios:
Is the user's current plan/tier checked at the point of feature access?
Or is it cached at login/session start and never re-evaluated?
7. For transfer/balance scenarios:
Is there a server-side check that the transfer amount is positive?
Is there a server-side check that the sender has sufficient balance?
Are these checks done within a database transaction to prevent race conditions?
Classification:
Exploitable: The business rule is absent, bypassable, or only enforced client-side.
Likely Exploitable: The rule exists but has gaps (race condition window, missing edge case, bypassable condition).
Not Exploitable: Proper server-side enforcement exists and covers edge cases.
Needs Manual Review: Cannot determine with confidence (complex logic, external service dependency, etc.).
Output format — write to sast/businesslogic-batch-[N].md:
markdown
# Business Logic Batch [N] Results
## Findings
### [EXPLOITABLE] Scenario title
- **Category**: [Attack category]
- **File**: `path/to/file.ext` (lines X-Y)
- **Endpoint**: `METHOD /path`
- **Business Rule Violated**: [What rule the application should enforce]
- **Issue**: [Clear description of what validation is missing or broken]
- **Impact**: [What an attacker can achieve — free goods, financial loss, unfair advantage, etc.]
- **Proof**: [Show the code path demonstrating the missing enforcement]
- **Remediation**: [Specific fix for this scenario]
- **Dynamic Test**:
[Step-by-step instructions or curl commands to confirm the finding on the live app.
Include exact HTTP method, endpoint, headers, and request body.
Describe what response or side effect confirms the vulnerability.]
### [LIKELY EXPLOITABLE] Scenario title
- **Category**: [Attack category]
- **File**: `path/to/file.ext` (lines X-Y)
- **Endpoint**: `METHOD /path`
- **Business Rule Violated**: [What rule should be enforced]
- **Issue**: [What enforcement gap or race condition exists]
- **Concern**: [Why this is likely exploitable despite partial enforcement]
- **Proof**: [Show the code path with the weak/partial check]
- **Remediation**: [Specific fix]
- **Dynamic Test**:
[Step-by-step instructions or curl commands, e.g. two concurrent requests, to confirm.]
### [NOT EXPLOITABLE] Scenario title
- **Category**: [Attack category]
- **File**: `path/to/file.ext` (lines X-Y)
- **Business Rule**: [What the application is supposed to enforce]
- **Protection**: [How it is enforced — server-side validation, DB constraint, atomic transaction, etc.]
### [NEEDS MANUAL REVIEW] Scenario title
- **Category**: [Attack category]
- **File**: `path/to/file.ext` (lines X-Y)
- **Uncertainty**: [Why automated analysis couldn't determine the status]
- **Suggestion**: [What to examine manually or test dynamically]
Phase 3: Merge — Consolidate Batch Results
After all Phase 2 batch subagents complete, read every sast/businesslogic-batch-*.md file and merge them into a single sast/businesslogic-results.md. You (the orchestrator) do this directly — no subagent needed.
Merge procedure:
Read all sast/businesslogic-batch-1.md, sast/businesslogic-batch-2.md, ... files.
Collect all findings from each batch file and combine them into one list, preserving the original classification and all detail fields.
Count totals across all batches for the executive summary.
Write the merged report to sast/businesslogic-results.md using this format:
markdown
# Business Logic Analysis Results: [Project Name]
## Executive Summary
- Scenarios analyzed: [total across all batches]
- Exploitable: [N]
- Likely Exploitable: [N]
- Not Exploitable: [N]
- Needs Manual Review: [N]
## Findings
[All findings from all batches, grouped by classification:
EXPLOITABLE first, then LIKELY EXPLOITABLE, then NEEDS MANUAL REVIEW, then NOT EXPLOITABLE.
Preserve every field from the batch results exactly as written.]
After writing sast/businesslogic-results.md, delete all intermediate batch files (sast/businesslogic-batch-*.md).
Important Reminders
Read sast/architecture.md and pass its content to all subagents as context.
Phase 2 must run after Phase 1 completes — it depends on the threat model output.
Phase 3 must run after all Phase 2 batches complete — it depends on all batch outputs.
Batch size is 3 scenarios per subagent. If there are 1–3 scenarios total, use a single subagent. If there are 10, use 4 subagents (3+3+3+1).
Launch all batch subagents in parallel — do not run them sequentially.
Each batch subagent receives only its assigned scenarios' text from the threats file, not the entire threats file. This keeps each subagent's context small and focused.
Focus strictly on business logic flaws — do not flag injection bugs, auth bypass, or IDOR issues here.
Threat modeling in Phase 1 should be application-specific: generic scenarios not grounded in the actual codebase are not useful.
Server-side validation is the only valid protection. Client-side validation, frontend form constraints, and API documentation that says "must be positive" are not security controls.
Race conditions on financial operations are high-severity even if they appear to require exact timing — automated tools (Turbo Intruder, concurrent curl) make them trivial to exploit.
When in doubt, classify as "Needs Manual Review" rather than "Not Exploitable". False negatives in a security assessment are worse than false positives.
Pay attention to ORM and database-level constraints (CHECK constraints, unique indexes, transactions with locking) — these can provide enforcement that is not visible in application code alone.
Clean up intermediate files: delete sast/businesslogic-threats.md and all sast/businesslogic-batch-*.md files after the final sast/businesslogic-results.md is written.
Sast Businesslogic next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Runs full Trailmark structural analysis by building a graph, running preanalysis(), and reporting hotspots, taint, blast radius, privilege boundaries, attack surface, and version-gated Trailmark…
A skill your agent uses when writing, reviewing, testing, or shipping Go code and HTTP services: idioms, %w error wrapping, goroutine/context/errgroup concurrency, net/http 1.22 routing, log/slog…
Detect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon (confirm GraphQL usage and find unsafe operation document assembly sites), batched verify (trace user input…
Detect Insecure Direct Object Reference (IDOR) vulnerabilities in a codebase using a three-phase approach: recon (find candidates), batched verify (check authorization in parallel subagents, 3…
Detect insecure file upload vulnerabilities in a codebase using a three-phase approach: discovery (find all upload sites), batched verify (check extension bypass and related issues in parallel…
Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel…. Sast Businesslogic is an agent skill from utkusen/sast-skills. Detect business logic vulnerabilities in a codebase using a three-phase approach: threat modeling (domain analysis and attack scenarios), batched verify (check exploitable gaps in parallel subagents, 3 scenarios each), and merge (consolidate batch results).
When should I use Sast Businesslogic?
Sast Businesslogic fits situations like: asked to find business logic; abuse-of-function bugs.
How do I install Sast Businesslogic in Claude Code?
Run `npx skills add utkusen/sast-skills --skill sast-businesslogic -a claude-code`. Or copy the skill folder (sast-files/.agents/skills/sast-businesslogic in utkusen/sast-skills) into .claude/skills/sast-businesslogic in your project. Claude Code loads it when a task matches its description.
How do I install Sast Businesslogic in Codex?
Run `npx skills add utkusen/sast-skills --skill sast-businesslogic -a codex`. Or copy the skill folder (sast-files/.agents/skills/sast-businesslogic in utkusen/sast-skills) into .agents/skills/sast-businesslogic in your project. Codex loads it when a task matches its description.
Can I use Sast Businesslogic in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add utkusen/sast-skills --skill sast-businesslogic -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sast-businesslogic, .gemini/skills/sast-businesslogic, .github/skills/sast-businesslogic and .opencode/skills/sast-businesslogic in your project.
What does Sast Businesslogic need to run?
SKILL.md names no scripts, command-line tools or credentials: Sast Businesslogic is instructions for the agent only.
Does Sast Businesslogic access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Sast Businesslogic safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Sast Businesslogic use?
Sast Businesslogic is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Sast Businesslogic use?
About 5.3k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Sast Businesslogic?
Skills that share tags, products or a category with Sast Businesslogic: Hunter (codexstar69/bug-hunter, 520 stars), Trailmark Structural (trailofbits/skills, 7.5k stars), Discover Attack Surface (seqra/opentaint, 163 stars) and Audit Integrity (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Sast Businesslogic?
utkusen (a GitHub user) maintains it in utkusen/sast-skills, which has 1,331 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on April 8, 2026.
Source: utkusen/sast-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.