Wooyun Legacy
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking.
$ npx skills add fabricioctelles/skills --skill security-specialist -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install fabricioctelles/skills security-specialist --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/fabricioctelles/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-specialist .claude/skills/security-specialist && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "security-specialist" agent skill from https://github.com/fabricioctelles/skills/tree/main/skills/security-specialist into .claude/skills/security-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-specialist", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/fabricioctelles/skills/tree/main/skills/security-specialistType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add fabricioctelles/skills --skill security-specialist -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install fabricioctelles/skills security-specialist --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fabricioctelles/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/security-specialist .agents/skills/security-specialist && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "security-specialist" agent skill from https://github.com/fabricioctelles/skills/tree/main/skills/security-specialist into .agents/skills/security-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-specialist", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add fabricioctelles/skills --skill security-specialist -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install fabricioctelles/skills security-specialist --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fabricioctelles/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/security-specialist .cursor/skills/security-specialist && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "security-specialist" agent skill from https://github.com/fabricioctelles/skills/tree/main/skills/security-specialist into .cursor/skills/security-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-specialist", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/fabricioctelles/skills.git --path skills/security-specialist--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add fabricioctelles/skills --skill security-specialist -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install fabricioctelles/skills security-specialist --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fabricioctelles/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/security-specialist .gemini/skills/security-specialist && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "security-specialist" agent skill from https://github.com/fabricioctelles/skills/tree/main/skills/security-specialist into .gemini/skills/security-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-specialist", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install fabricioctelles/skills security-specialistInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add fabricioctelles/skills --skill security-specialist -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/fabricioctelles/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/security-specialist .github/skills/security-specialist && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "security-specialist" agent skill from https://github.com/fabricioctelles/skills/tree/main/skills/security-specialist into .github/skills/security-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-specialist", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add fabricioctelles/skills --skill security-specialist -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install fabricioctelles/skills security-specialist --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/fabricioctelles/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/security-specialist .opencode/skills/security-specialist && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "security-specialist" agent skill from https://github.com/fabricioctelles/skills/tree/main/skills/security-specialist into .opencode/skills/security-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "security-specialist", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
security-specialistRuns security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking.
Security Specialist is an agent skill from fabricioctelles/skills. Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking. Activate when the user says "security scan", "audit this repo", "review this PR for security", "threat model", "triage vulnerabilities", "fix this vuln", or "track findings".
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 25 other files, including scripts and reference files (for example `references/finding-format.md`, `references/report-format.md` and `references/report-schema.json`).
It sits in Security, covering Security review, Threat modeling and Bug bounty. The repository describes itself as: A collection of skills for AI agents (Kiro, Cursor, Windsurf, Claude Code, and others). Each skill is a reusable module that teaches the agent to perform complex tasks with… The licence is Apache-2.0.
10 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 242512d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 5 files in scripts/ (Python and JavaScript, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
nodepython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Security Specialist loads about 2.8k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 84 tokens; SKILL.md has 1,389 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from fabricioctelles/skills at commit 242512d, republished under its Apache-2.0 licence (© fabricioctelles). 1,389 words, ~2,830 tokens.
.claude/skills/security-specialist/SKILL.md (or your agent's skills folder). This skill also uses 22 other files; get the full folder from GitHub.You perform security work on source code. Not the hand-wavy kind — you dig into repos, trace data flows, find real bugs, and produce evidence.
Pick a workflow from the table below based on what the user needs. Then read the matching steering doc and follow it. Don't improvise the workflow order — it exists because skipping steps produces garbage findings.
Every finding must have a concrete attack scenario: who is the attacker, what do they do, and what do they get? "An attacker could theoretically..." is not a finding. "Send this request, get this result" is.
In Phase 1, identify what this application is and what comparable applications exist. Use comparables to calibrate — not to dismiss findings, but to focus effort. If the comparable has the same pattern and it's been exploited there, that's a STRONGER finding. If the comparable has the same pattern and nobody's exploited it in 20 years, understand why before reporting.
The agent that checks a finding is never the agent that found it. Hunting agents find; validation agents kill false positives. This separation is critical for report quality.
Severity = likelihood × impact, not deviation from a checklist. If you cannot describe the concrete damage an attacker achieves, the severity is probably lower than you think.
If Layer A prevents the attack, the absence of Layer B is a hardening suggestion, not a finding.
Testing shows a single run finds roughly half the total vulnerabilities across multiple runs. Each run explores different code paths. Prior runs inform where to dig deeper.
The scan scope depends on what the user provides:
| User provides | What runs |
|---|---|
| Path only | SAST (source code) → start dev server → DAST (localhost) |
| Path + URL | SAST (source code) → DAST (localhost) → DAST (production URL, requires confirmation) |
| URL only | DAST against the URL (confirm if not localhost) |
Always start with the least invasive layer and escalate. The three-layer correlation (source → dev → prod) produces the strongest evidence.
localhost, 127.0.0.1, 0.0.0.0, *.local, 192.168.*, 10.*, 172.16-31.* → no confirmation needed| What they want | Steering doc | Typical asks |
|---|---|---|
| Scan a whole repo | steering/full-scan.md | "scan this repo", "security audit", "find vulnerabilities" |
| Review a diff/PR | steering/diff-review.md | "review this PR", "check my changes", "security review this diff" |
| Pentest a live target | steering/pentest.md | "pentest this", "recon on target.com", "enumerate the app" |
| Hunt vulnerabilities | steering/hunting.md | "hunt for bugs", "attack classes", "run the wildcard agent" |
| Build a threat model | steering/threat-model.md | "threat model", "map attack surface", "identify trust boundaries" |
| Trace attack paths | steering/attack-paths.md | "how could this be exploited", "attack chain", "blast radius" |
| Discover new findings | steering/discovery.md | "look for issues in these files", "what's wrong here" |
| Triage findings | steering/triage.md | "prioritize these", "which ones matter", "assess severity" |
| Fix a vulnerability | steering/remediation.md | "fix this vuln", "patch it", "suggest a fix" |
| Track findings over time | steering/tracking.md | "track these findings", "export to GitHub issues", "update status" |
| Validate a fix | steering/validation.md | "verify this fix", "is it actually patched", "regression check" |
| Generate report | steering/reporting.md | "write the report", "summarize findings", "produce the final output" |
Utility scripts live in scripts/ relative to this skill:
python3 scripts/<name>.py [args] # Python utilities
node scripts/validate-findings.cjs <file> # Schema validator| Script | Purpose |
|---|---|
scan_db.py | SQLite CRUD: init scans, add/validate/triage findings, export |
rank_files.py | Score files by security relevance for discovery worklists |
pentest.py | Recon, enumeration, vuln scan wrapper (system tools + Python fallbacks) |
finalize.py | Seal scan: export JSON + HTML, compute integrity hashes |
validate-findings.cjs | Validate findings.json against report-schema.json (zero deps, Node.js) |
| File | What it governs | When to read |
|---|---|---|
references/report-format.md | HTML report template, CSS, structure, footer | Before generating security-report.html |
references/finding-format.md | Finding structure (simple + structured formats) | Before recording any finding |
references/severity-policy.md | Severity classification rules + CVE cross-ref protocol | Before assigning any severity |
references/scan-artifacts.md | Scan directory structure, file naming | Before initializing a scan |
references/report-schema.json | JSON schema for structured findings.json | Before writing Phase 5 output |
Report output is HTML (security-report.html) — self-contained dark-themed file with color-coded severities, collapsible evidence, and interactive severity filters. No external dependencies.
Erros que tornam auditorias de segurança inúteis:
Listar tudo que desvia do OWASP como finding. OWASP é checklist, não bug list. Toda aplicação real faz tradeoffs.
Rating defense-in-depth gaps como HIGH/CRITICAL. "Missing validateIdentifier onde o query builder já escapa identificadores" não é HIGH.
Ignorar o deployment model. Rate limiting no CDN layer é arquitetura válida. Nem toda app precisa rate limiting no application level.
Tratar designed behavior como bug. Entenda o trust model antes de auditar. Se o design diz admins are fully trusted, admin-does-admin-things não é finding.
Padding o report com LOWs para parecer thorough. Dez LOWs não fazem um report útil. Três MEDIUMs fazem.
"Potential" findings sem proof. Ou você pode explotar ou não pode. Se precisa das palavras "potencialmente" ou "teoricamente", não pesquisou o suficiente.
Ignorar o que o codebase faz bem. Se auth é sólido, diga. Constrói confiança nos findings que VOCÊ reporta e ajuda o time a priorizar.
Construir exploits de assumptions incorretas sobre parser/runtime. Os false positives mais convincentes vêm de reasoning "o parser vai interpretar isso como..." sem verificar. Se o exploit depende de parser behavior, cite a spec ou teste. Não assuma.
Pular business logic e creative attacks. As vulnerability classes padrão (SQLi, XSS, SSRF) são o que todo scanner checa. O valor de uma auditoria manual é encontrar o que scanners não podem: logic errors, state machine violations, chained attacks, implicit trust assumptions.
Desistir fácil demais. "O codebase usa parameterized queries portanto não tem SQL injection" é conclusão preguiçosa. Cheque CADA uso de sql.raw(). Cheque dynamic identifiers. Cheque search/FTS. Cheque se existe code path que bypassa o query builder. Insista.
These apply to every workflow. No exceptions.
references/ before generating structured output.node scripts/validate-findings.cjs before delivering findings.json.Before delivering security-report.html, verify ALL against references/report-format.md:
<title> with repo nameGenerated by security-specialist skill by github.com/fabricioctelles/skillsA CVE with CVSS 9.8 means nothing if the vulnerable code path is unreachable. Before classifying a dependency CVE, verify preconditions:
| Step | What to check | If absent → |
|---|---|---|
| 1 | Vulnerable function/module used directly? | Drop to LOW or INFO |
| 2 | Project uses the triggering feature? | Drop to LOW or INFO |
| 3 | Environmental conditions met? | Drop to LOW or INFO |
| 4 | DAST confirmed exploitability? | Flag as "not confirmed in production" |
A finding confirmed in localhost may not exist in production because infrastructure mitigates it. Always test both and document the delta.
Lack of input size validation on persisted fields is often missed. Real DoS vector — especially with SQLite where full disk kills the entire app.
Each run should explicitly target what prior runs missed. If prior runs found 5 injection bugs and 0 logic bugs, the next run should weight toward business logic, feature abuse, and wildcard agents.
© fabricioctelles, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 22 other files (scripts, references) in skills/security-specialist of fabricioctelles/skills.
Open the folder on GitHubat commit 242512d
Security Specialist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Security Specialist this skillfabricioctelles/skills | 106 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Security Audit Scannerruvnet/ruflo | 74k | 1 repos | ~823 | Automated safety check: Pass | MIT | |
| Flounderadshao/flounder | 518 | — | ~9.2k | Automated safety check: Pass | AGPL-3.0 | |
| Osint Methodologyelementalsouls/Claude-OSINT | 2.8k | — | ~8.7k | Automated safety check: Notes | MIT | |
| CSO Security Auditgarrytan/gstack | 136k | — | ~4.5k | Automated safety check: Pass | MIT |
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
adshao/flounder
Operates Flounder, an autonomous white-hat security auditor.
elementalsouls/Claude-OSINT
Comprehensive OSINT methodology for external red-team operations and authorized attack-surface assessments.
garrytan/gstack
Runs an evidence-first security audit of a codebase through gstack's trusted launcher, with static findings by default and isolated reproduction when enabled.
quillai-network/quillshield_skills
Token-efficient smart contract security auditing via Behavioral State Analysis (BSA).
fabricioctelles/skills
Produce a short motion-graphics video ad — a 15s Facebook/Instagram/TikTok spot — as a rendered MP4.
fabricioctelles/skills
Audit, score, and compare repositories containing portable Agent Plugins against the official Agent Plugins specification.
fabricioctelles/skills
Design well-structured agent loops with best-practice coaching and cross-model review gates before you run them.
fabricioctelles/skills
This skill should be used when the user needs to consume the Pier Cloud (Lighthouse) API for cloud cost management — including JWT authentication, listing contexts, workspaces, workspace groups, and…
fabricioctelles/skills
Automated iterative agent runner for spec-based development in Kiro.
fabricioctelles/skills
Evaluate any agent skill against a merged framework — Anthropic's Claude Code best practices plus Matt Pocock's writing-great-skills methodology — across 4 axes (Trigger, Structure, Steering…
Categories
Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking. Security Specialist is an agent skill from fabricioctelles/skills. Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking.
Security Specialist fits situations like: says security scan; audit this repo; review this PR for security; triage vulnerabilities.
Run `npx skills add fabricioctelles/skills --skill security-specialist -a claude-code`. Or copy the skill folder (skills/security-specialist in fabricioctelles/skills) into .claude/skills/security-specialist in your project. Claude Code loads it when a task matches its description.
Run `npx skills add fabricioctelles/skills --skill security-specialist -a codex`. Or copy the skill folder (skills/security-specialist in fabricioctelles/skills) into .agents/skills/security-specialist in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add fabricioctelles/skills --skill security-specialist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-specialist, .gemini/skills/security-specialist, .github/skills/security-specialist and .opencode/skills/security-specialist in your project.
Going by SKILL.md and its folder, Security Specialist needs Python and JavaScript for the scripts in its folder and the command-line tools its instructions call (node and python3). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Security Specialist is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 10k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Security Specialist: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Security Audit Scanner (ruvnet/ruflo, 74k stars), Flounder (adshao/flounder, 518 stars) and Osint Methodology (elementalsouls/Claude-OSINT, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
fabricioctelles (a GitHub user) maintains it in fabricioctelles/skills, which has 106 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 11, 2026.
Source: fabricioctelles/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.