Wooyun Legacy
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy
$ npx skills add Hack23/cia --skill secure-code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Hack23/cia secure-code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/secure-code-review .claude/skills/secure-code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "secure-code-review" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/secure-code-review into .claude/skills/secure-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Hack23/cia/tree/master/.github/skills/secure-code-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Hack23/cia --skill secure-code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Hack23/cia secure-code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/secure-code-review .agents/skills/secure-code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "secure-code-review" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/secure-code-review into .agents/skills/secure-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hack23/cia --skill secure-code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Hack23/cia secure-code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/secure-code-review .cursor/skills/secure-code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "secure-code-review" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/secure-code-review into .cursor/skills/secure-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Hack23/cia.git --path .github/skills/secure-code-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Hack23/cia --skill secure-code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Hack23/cia secure-code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/secure-code-review .gemini/skills/secure-code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "secure-code-review" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/secure-code-review into .gemini/skills/secure-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Hack23/cia secure-code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Hack23/cia --skill secure-code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/secure-code-review .github/skills/secure-code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "secure-code-review" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/secure-code-review into .github/skills/secure-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hack23/cia --skill secure-code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Hack23/cia secure-code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/secure-code-review .opencode/skills/secure-code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "secure-code-review" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/secure-code-review into .opencode/skills/secure-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secure-code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
secure-code-reviewConduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy
Secure Code Review is an agent skill from Hack23/cia. Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy
Its SKILL.md is about 5.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Security review, Web application vulnerabilities and Code review. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
mvnghFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comowasp.orgcwe.mitre.orgsans.orgiso.orgcsrc.nist.govcodeql.github.comsonarcloud.iofind-sec-bugs.github.iodocs.spring.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Secure Code Review loads about 5.8k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 1,025 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 1,025 words, ~5,798 tokens.
.claude/skills/secure-code-review/SKILL.md (or your agent's skills folder).This skill provides strategic guidance for conducting thorough security code reviews that identify vulnerabilities before they reach production. It implements defense-in-depth principles aligned with OWASP Top 10, SANS Top 25, and Hack23 ISMS Secure Development Policy.
Apply this skill when:
Do NOT use for:
START: Code Review Required
│
├─→ Does code handle user input?
│ ├─→ YES → Apply Input Validation Checklist
│ └─→ NO → Continue
│
├─→ Does code access database?
│ ├─→ YES → Apply SQL Injection Prevention
│ └─→ NO → Continue
│
├─→ Does code handle authentication/authorization?
│ ├─→ YES → Apply Authentication Security Checklist
│ └─→ NO → Continue
│
├─→ Does code process sensitive data?
│ ├─→ YES → Apply Data Protection Checklist
│ └─→ NO → Continue
│
├─→ Does code interact with external systems?
│ ├─→ YES → Apply API Security Checklist
│ └─→ NO → Continue
│
└─→ Run SAST tools (SonarCloud, CodeQL)
└─→ Document findings and mitigationWhat to Check:
Code Patterns:
✅ SECURE - Proper Authorization Check:
@Service
public class DocumentService {
@Autowired
private SecurityContext securityContext;
@PreAuthorize("hasRole('USER')")
public Document getDocument(Long documentId) {
Document doc = documentRepository.findById(documentId)
.orElseThrow(() -> new ResourceNotFoundException("Document not found"));
// Verify ownership before returning
if (!doc.getOwnerId().equals(getCurrentUserId())) {
throw new AccessDeniedException("Cannot access document owned by another user");
}
return doc;
}
}❌ INSECURE - Missing Authorization:
// BAD: No authorization check, anyone can access any document
@GetMapping("/documents/{id}")
public Document getDocument(@PathVariable Long id) {
return documentRepository.findById(id).orElse(null);
}What to Check:
Code Patterns:
✅ SECURE - Proper Password Hashing:
@Service
public class UserService {
@Autowired
private PasswordEncoder passwordEncoder; // BCryptPasswordEncoder
public void createUser(String username, String password) {
String hashedPassword = passwordEncoder.encode(password);
User user = new User(username, hashedPassword);
userRepository.save(user);
}
public boolean verifyPassword(String rawPassword, String hashedPassword) {
return passwordEncoder.matches(rawPassword, hashedPassword);
}
}❌ INSECURE - Plain Text Password:
// BAD: Storing passwords in plain text
public void createUser(String username, String password) {
User user = new User(username, password); // NEVER DO THIS
userRepository.save(user);
}What to Check:
Code Patterns:
✅ SECURE - Parameterized Query:
@Repository
public interface PoliticianRepository extends JpaRepository<Politician, Long> {
// JPA query with named parameter - safe from SQL injection
@Query("SELECT p FROM Politician p WHERE p.firstName = :firstName AND p.lastName = :lastName")
List<Politician> findByName(@Param("firstName") String firstName,
@Param("lastName") String lastName);
}
// Using JPA Criteria API - also safe
public List<Politician> searchPoliticians(String searchTerm) {
CriteriaBuilder cb = entityManager.getCriteriaBuilder();
CriteriaQuery<Politician> query = cb.createQuery(Politician.class);
Root<Politician> politician = query.from(Politician.class);
query.where(cb.like(politician.get("firstName"), "%" + searchTerm + "%"));
return entityManager.createQuery(query).getResultList();
}❌ INSECURE - SQL Injection Vulnerable:
// BAD: String concatenation in query
@Query(value = "SELECT * FROM politician WHERE first_name = '" + firstName + "'",
nativeQuery = true)
List<Politician> findByName(String firstName); // SQL INJECTION RISK!
// BAD: Direct JDBC with concatenation
public List<Politician> search(String name) {
String sql = "SELECT * FROM politician WHERE name = '" + name + "'";
return jdbcTemplate.query(sql, new PoliticianMapper()); // VULNERABLE!
}What to Check:
Secure Design Principles:
// Example: Rate limiting for login attempts
@Service
public class LoginService {
private static final int MAX_ATTEMPTS = 5;
private static final Duration LOCKOUT_DURATION = Duration.ofMinutes(15);
private final LoadingCache<String, Integer> loginAttempts = CacheBuilder.newBuilder()
.expireAfterWrite(LOCKOUT_DURATION)
.build(new CacheLoader<String, Integer>() {
public Integer load(String key) {
return 0;
}
});
public void login(String username, String password) {
// Check if account is locked
int attempts = loginAttempts.get(username);
if (attempts >= MAX_ATTEMPTS) {
throw new AccountLockedException(
"Account locked due to too many failed attempts. Try again in 15 minutes.");
}
// Attempt authentication
boolean authenticated = authenticate(username, password);
if (!authenticated) {
loginAttempts.put(username, attempts + 1);
throw new BadCredentialsException("Invalid credentials");
}
// Success - reset counter
loginAttempts.invalidate(username);
}
}What to Check:
Configuration Checklist:
✅ SECURE - Production Configuration:
# application-production.yml
spring:
profiles:
active: production
# Disable debug endpoints
boot:
admin:
client:
enabled: false
# Secure session management
session:
timeout: 30m
cookie:
secure: true
http-only: true
same-site: strict
# Hide implementation details
mvc:
throw-exception-if-no-handler-found: true
resources:
add-mappings: false
# Security headers
server:
error:
include-message: never
include-stacktrace: never
include-exception: false❌ INSECURE - Development Settings in Production:
# BAD: Debug enabled in production
spring:
profiles:
active: development
# Exposes sensitive endpoints
boot:
admin:
client:
enabled: true
# Leak stack traces
server:
error:
include-stacktrace: always
include-exception: trueWhat to Check:
Maven Security Check:
# Run OWASP Dependency Check before adding new dependencies
mvn org.owasp:dependency-check-maven:check
# Review the report
ls -la target/dependency-check-report.html
# Fail build on high severity vulnerabilities
mvn verify -Dowasp.failOnCVSS=7pom.xml Best Practices:
<!-- Use dependencyManagement to control versions -->
<dependencyManagement>
<dependencies>
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-framework-bom</artifactId>
<version>5.3.34</version>
<type>pom</type>
<scope>import</scope>
</dependency>
</dependencies>
</dependencyManagement>
<!-- Enable OWASP Dependency Check -->
<plugin>
<groupId>org.owasp</groupId>
<artifactId>dependency-check-maven</artifactId>
<version>9.0.7</version>
<configuration>
<failBuildOnCVSS>7</failBuildOnCVSS>
<suppressionFiles>
<suppressionFile>dependency-check-suppressions.xml</suppressionFile>
</suppressionFiles>
</configuration>
</plugin>What to Check:
Code Patterns:
✅ SECURE - Spring Security Configuration:
@Configuration
@EnableWebSecurity
public class SecurityConfig {
@Bean
public SecurityFilterChain filterChain(HttpSecurity http) throws Exception {
http
.authorizeHttpRequests(auth -> auth
.requestMatchers("/public/**").permitAll()
.requestMatchers("/admin/**").hasRole("ADMIN")
.anyRequest().authenticated()
)
.formLogin(form -> form
.loginPage("/login")
.failureHandler(authenticationFailureHandler())
.successHandler(authenticationSuccessHandler())
)
.logout(logout -> logout
.logoutSuccessUrl("/login?logout")
.invalidateHttpSession(true)
.deleteCookies("JSESSIONID")
)
.sessionManagement(session -> session
.sessionCreationPolicy(SessionCreationPolicy.IF_REQUIRED)
.maximumSessions(1)
.expiredUrl("/login?expired")
)
.csrf(csrf -> csrf.csrfTokenRepository(CookieCsrfTokenRepository.withHttpOnlyFalse()));
return http.build();
}
@Bean
public PasswordEncoder passwordEncoder() {
// BCrypt with strength 12
return new BCryptPasswordEncoder(12);
}
}What to Check:
Secure Deserialization:
// Use safe deserialization with explicit type validation
@Bean
public ObjectMapper objectMapper() {
ObjectMapper mapper = new ObjectMapper();
// Do NOT use activateDefaultTyping for untrusted input
// If polymorphism is required, use @JsonTypeInfo on specific DTOs
// with a strict allowlist-based PolymorphicTypeValidator
// Adjust serialization behavior if needed
mapper.disable(SerializationFeature.FAIL_ON_EMPTY_BEANS);
// Keep FAIL_ON_UNKNOWN_PROPERTIES enabled by default to catch unexpected/malicious fields
return mapper;
}What to Check:
Secure Logging Pattern:
@Component
public class SecurityAuditLogger {
private static final Logger auditLog = LoggerFactory.getLogger("SECURITY_AUDIT");
public void logAuthenticationSuccess(String username, String ipAddress) {
auditLog.info("Authentication successful - User: {}, IP: {}",
sanitizeForLog(username),
sanitizeForLog(ipAddress));
}
public void logAuthenticationFailure(String username, String ipAddress, String reason) {
auditLog.warn("Authentication failed - User: {}, IP: {}, Reason: {}",
sanitizeForLog(username),
sanitizeForLog(ipAddress),
reason);
}
public void logAccessDenied(String username, String resource) {
auditLog.warn("Access denied - User: {}, Resource: {}",
sanitizeForLog(username),
sanitizeForLog(resource));
}
// Prevent log injection
private String sanitizeForLog(String input) {
if (input == null) return "null";
return input.replaceAll("[\n\r\t]", "_");
}
}What to Check:
SSRF Prevention:
@Service
public class ExternalDataService {
private static final Set<String> ALLOWED_HOSTS = Set.of(
"api.riksdagen.se",
"api.worldbank.org",
"data.val.se"
);
public String fetchExternalData(String url) throws IOException {
URL parsedUrl;
try {
parsedUrl = new URL(url);
} catch (MalformedURLException e) {
throw new IllegalArgumentException("Invalid URL", e);
}
// Validate protocol
if (!parsedUrl.getProtocol().equals("https")) {
throw new IllegalArgumentException("Only HTTPS URLs allowed");
}
// Validate host against allowlist
if (!ALLOWED_HOSTS.contains(parsedUrl.getHost())) {
throw new IllegalArgumentException("Host not in allowlist: " + parsedUrl.getHost());
}
// Fetch data with timeout
HttpURLConnection conn = (HttpURLConnection) parsedUrl.openConnection();
conn.setConnectTimeout(5000);
conn.setReadTimeout(5000);
return IOUtils.toString(conn.getInputStream(), StandardCharsets.UTF_8);
}
}Ensure .github/workflows/codeql.yml includes:
name: "CodeQL Security Analysis"
on:
push:
branches: [ main, develop ]
pull_request:
branches: [ main ]
schedule:
- cron: '0 0 * * 0' # Weekly scan
jobs:
analyze:
name: Analyze
runs-on: ubuntu-latest
permissions:
actions: read
contents: read
security-events: write
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
with:
languages: java
queries: security-and-quality
- name: Build
run: mvn clean compile -DskipTests
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3Required quality gate thresholds:
Review these policies before code review:
Pre-Review Setup
# Checkout PR branch
gh pr checkout <PR-NUMBER>
# Run security scans
mvn clean verify
mvn org.owasp:dependency-check-maven:check
# Review CodeQL alerts
gh api /repos/Hack23/cia/code-scanning/alerts --jq '.[] | select(.state=="open")'Manual Code Review
Document Findings
## Security Review Findings
### Critical Issues
- [ ] SQL injection in `PoliticianController.search()` - line 45
### High Priority
- [ ] Missing authorization check in `DocumentService.getDocument()`
### Medium Priority
- [ ] Weak password validation in `UserRegistrationForm`
### Low Priority / Informational
- [ ] Consider adding rate limiting to login endpointRequest Changes or Approve
Before approving a PR, verify:
Secure Development Framework:
All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC
Track these KPIs to measure secure code review effectiveness:
© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/secure-code-review of Hack23/cia.
Open the folder on GitHubat commit 6a9797b
Secure Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Secure Code Review this skillHack23/cia | 239 | — | ~5.8k | Automated safety check: Pass | Apache-2.0 | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Trailmark Graph Evolutiontrailofbits/skills | 7.4k | — | ~3.4k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Security Reviewgetsentry/skills | 1k | 4 repos | ~2.9k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Cyber NeoHainrixz/cyber-neo | 281 | — | ~5.9k | Automated safety check: Warn | MIT | |
| Psalm Security Analysiscachethq/core | 230 | — | ~4.7k | Automated safety check: Pass | Custom licence |
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
getsentry/skills
Security code review for vulnerabilities. An agent skill from getsentry/skills.
Hainrixz/cyber-neo
Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.
cachethq/core
Runs and interprets Psalm security (taint) analysis on a Laravel project.
deadlock-mod-manager/deadlock-mod-manager
Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.
Hack23/cia
WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms
Hack23/cia
Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis
Hack23/cia
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
Hack23/cia
External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs
Hack23/cia
AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform
Hack23/cia
AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment
Categories
Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy. Secure Code Review is an agent skill from Hack23/cia.
Secure Code Review fits situations like: tasks that involve Security review; tasks that involve Web application vulnerabilities; tasks that involve Code review.
Run `npx skills add Hack23/cia --skill secure-code-review -a claude-code`. Or copy the skill folder (.github/skills/secure-code-review in Hack23/cia) into .claude/skills/secure-code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Hack23/cia --skill secure-code-review -a codex`. Or copy the skill folder (.github/skills/secure-code-review in Hack23/cia) into .agents/skills/secure-code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill secure-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secure-code-review, .gemini/skills/secure-code-review, .github/skills/secure-code-review and .opencode/skills/secure-code-review in your project.
Going by SKILL.md and its folder, Secure Code Review needs the command-line tools its instructions call (mvn and gh).
SKILL.md names 10 domains. As links in the text: github.com, owasp.org, cwe.mitre.org, sans.org, iso.org, csrc.nist.gov, codeql.github.com, sonarcloud.io, find-sec-bugs.github.io and docs.spring.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Secure Code Review is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.8k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Secure Code Review: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Trailmark Graph Evolution (trailofbits/skills, 7.4k stars), Security Review (getsentry/skills, 1k stars) and Cyber Neo (Hainrixz/cyber-neo, 281 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.
Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.