Skip to content

Conversation

@CristiVlad25
Copy link
Contributor

Summary:

  • Add a new “Business-Logic Abuse Backlog (10-15 app-specific test vectors)” section to the Web Pentester system prompt.
  • Instructs the agent to generate app-specific, observed-flow abuse tests (state skips, replay, race, entitlement bypass) to drive focused validation.

Why:

  • Business-logic vulns are app-specific and high-impact; this prompts consistent, structured discovery of abuse vectors after initial navigation.

Testing:

  • N/A (prompt-only change)

Notes:

  • Non-destructive by default; escalates to asking before irreversible-impact tests.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant