Wooyun Legacy
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
This skill provides automated assistance for security agent tasks Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
$ npx skills add aAAaqwq/AGI-Super-Team --skill performing-security-code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team performing-security-code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-security-code-review .claude/skills/performing-security-code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "performing-security-code-review" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/performing-security-code-review into .claude/skills/performing-security-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-security-code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/performing-security-code-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aAAaqwq/AGI-Super-Team --skill performing-security-code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team performing-security-code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/performing-security-code-review .agents/skills/performing-security-code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "performing-security-code-review" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/performing-security-code-review into .agents/skills/performing-security-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-security-code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aAAaqwq/AGI-Super-Team --skill performing-security-code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team performing-security-code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/performing-security-code-review .cursor/skills/performing-security-code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "performing-security-code-review" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/performing-security-code-review into .cursor/skills/performing-security-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-security-code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aAAaqwq/AGI-Super-Team.git --path skills/performing-security-code-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aAAaqwq/AGI-Super-Team --skill performing-security-code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team performing-security-code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/performing-security-code-review .gemini/skills/performing-security-code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "performing-security-code-review" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/performing-security-code-review into .gemini/skills/performing-security-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-security-code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aAAaqwq/AGI-Super-Team performing-security-code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aAAaqwq/AGI-Super-Team --skill performing-security-code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/performing-security-code-review .github/skills/performing-security-code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "performing-security-code-review" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/performing-security-code-review into .github/skills/performing-security-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-security-code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aAAaqwq/AGI-Super-Team --skill performing-security-code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aAAaqwq/AGI-Super-Team performing-security-code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aAAaqwq/AGI-Super-Team.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/performing-security-code-review .opencode/skills/performing-security-code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "performing-security-code-review" agent skill from https://github.com/aAAaqwq/AGI-Super-Team/tree/main/skills/performing-security-code-review into .opencode/skills/performing-security-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "performing-security-code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
performing-security-code-reviewThis skill provides automated assistance for security agent tasks Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
Performing Security Code Review is an agent skill from aAAaqwq/AGI-Super-Team. This skill provides automated assistance for security agent tasks Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. it analyzes code for potential vulnerabilities like sql injection, xss, authentication flaws, and insecure dependencies. AI assistant uses this skill wh... Use when assessing security or running audits. Trigger with phrases like 'security scan', 'audit', or 'vulnerability'.
Its SKILL.md is about 920 tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/README.md`, `assets/example_code_secure.py` and `assets/example_code_vulnerable.py`).
It sits in Security, covering Web application vulnerabilities, Code review and Hooks and plugins. The repository describes itself as: An installable, cross-framework AI organization: C-suite agents, expert subagents, curated skills, independent review, and one-command setup across 18 AI client/runtime adapters. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 331ecd3. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditGrepGlobBash(cmd:*)From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Performing Security Code Review loads about 920 tokens when it runs, and up to ~1k if it reads all its reference files. Until then it costs about 122 tokens; SKILL.md has 392 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from aAAaqwq/AGI-Super-Team at commit 331ecd3, republished under its MIT licence (© aAAaqwq). 392 words, ~920 tokens.
.claude/skills/performing-security-code-review/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.This skill provides automated assistance for security agent tasks.
This skill empowers Claude to act as a security expert, identifying and explaining potential vulnerabilities within code. It leverages the security-agent plugin to provide detailed security analysis, helping developers improve the security posture of their applications.
This skill activates when you need to:
User request: "Please review this database query code for SQL injection vulnerabilities."
The skill will:
User request: "Can you check this project's dependencies for known security vulnerabilities?"
The skill will:
This skill integrates with Claude's code understanding capabilities and leverages the security-agent plugin to provide specialized security analysis. It can be used in conjunction with other code analysis tools to provide a comprehensive assessment of code quality and security.
The skill produces structured output relevant to the task.
© aAAaqwq, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 7 other files (scripts, references, assets) in skills/performing-security-code-review of aAAaqwq/AGI-Super-Team.
Open the folder on GitHubat commit 331ecd3
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in aAAaqwq/AGI-Super-Team, which our catalogue first saw on October 7, 2026.
Performing Security Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Performing Security Code Review this skillaAAaqwq/AGI-Super-Team | 105 | 1 repos | ~920 | Automated safety check: Pass | MIT | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Security Reviewgetsentry/skills | 1k | 4 repos | ~2.9k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Security Reviewdeadlock-mod-manager/deadlock-mod-manager | 473 | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Security Auditorpavel-molyanov/molyanov-ai-dev | 296 | — | ~566 | Automated safety check: Pass | MIT | |
| Security Reviewerforyourhealth111-pixel/Vibe-Skills | 3.6k | — | ~523 | Automated safety check: Pass | Apache-2.0 |
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
getsentry/skills
Security code review for vulnerabilities. An agent skill from getsentry/skills.
deadlock-mod-manager/deadlock-mod-manager
Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.
pavel-molyanov/molyanov-ai-dev
Analyzes changed security boundaries against applicable OWASP risks and project contracts.
foryourhealth111-pixel/Vibe-Skills
Dedicated security-audit route for OWASP-style risks, secret leaks, auth flaws, injection, unsafe input handling, SSRF/XSS, and sensitive-data exposure.
Hack23/cia
Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy
aAAaqwq/AGI-Super-Team
Create SEO-optimized marketing content with consistent brand voice.
aAAaqwq/AGI-Super-Team
Advanced financial calculator with future value tables, present value, discount calculations, markup pricing, and compound interest.
aAAaqwq/AGI-Super-Team
Create distinctive, production-grade static sites with React, Tailwind CSS, and shadcn/ui — no mockups needed.
aAAaqwq/AGI-Super-Team
Tool discovery and shell one-liner reference for sysadmin, DevOps, and security tasks.
aAAaqwq/AGI-Super-Team
Publish and manage content on 知识星球 (zsxq.com). An agent skill from aAAaqwq/AGI-Super-Team.
aAAaqwq/AGI-Super-Team
Robust URL-to-Markdown extraction for OpenClaw workflows. An agent skill from aAAaqwq/AGI-Super-Team.
Categories
This skill provides automated assistance for security agent tasks Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin. Performing Security Code Review is an agent skill from aAAaqwq/AGI-Super-Team. This skill provides automated assistance for security agent tasks Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.
Performing Security Code Review fits situations like: assessing security; with phrases like security scan.
Run `npx skills add aAAaqwq/AGI-Super-Team --skill performing-security-code-review -a claude-code`. Or copy the skill folder (skills/performing-security-code-review in aAAaqwq/AGI-Super-Team) into .claude/skills/performing-security-code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aAAaqwq/AGI-Super-Team --skill performing-security-code-review -a codex`. Or copy the skill folder (skills/performing-security-code-review in aAAaqwq/AGI-Super-Team) into .agents/skills/performing-security-code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aAAaqwq/AGI-Super-Team --skill performing-security-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-security-code-review, .gemini/skills/performing-security-code-review, .github/skills/performing-security-code-review and .opencode/skills/performing-security-code-review in your project.
Going by SKILL.md and its folder, Performing Security Code Review needs Python for the scripts in its folder. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Write, Edit, Grep, Glob, Bash(cmd:*).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Performing Security Code Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 920 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 103 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Performing Security Code Review: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Security Review (getsentry/skills, 1k stars), Security Review (deadlock-mod-manager/deadlock-mod-manager, 473 stars) and Security Auditor (pavel-molyanov/molyanov-ai-dev, 296 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aAAaqwq (a GitHub user) maintains it in aAAaqwq/AGI-Super-Team, which has 105 GitHub stars. The repository holds 161 skills in this directory. The repository was last updated on September 27, 2026.
Source: aAAaqwq/AGI-Super-Team on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.