Agent skill

Vulnerability Patterns

by revfactory in revfactory/harness-100

Code vulnerability pattern database. An agent skill from revfactory/harness-100.

Apache-2.0Auto-check passedSecurity

Install Vulnerability Patterns

skills CLI
$ npx skills add revfactory/harness-100 --skill vulnerability-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install revfactory/harness-100 vulnerability-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/revfactory/harness-100.git skills-src && mkdir -p .claude/skills && cp -r skills-src/en/21-code-reviewer/.claude/skills/vulnerability-patterns .claude/skills/vulnerability-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vulnerability-patterns
GitHub stars
1.3k
Token cost
~1.5k tokens
SKILL.md length
223 words
Files
1
Skills in repo
464
Repo updated
First seen
Licence
Apache-2.0

At a glance

Code vulnerability pattern database. An agent skill from revfactory/harness-100.

  • Performing security reviews involving vulnerability patterns
  • SKILL.md covers Target Agent, Vulnerability Classification…, Language-Specific Vulnerable… and Severity Assessment Criteria
  • Reaches apache.org and xml.org
  • Security vulnerabilities

What it does

Vulnerability Patterns is an agent skill from revfactory/harness-100. Code vulnerability pattern database. An extension skill for security-analyst that provides language-specific (Python/JS/Java/Go) vulnerable code patterns, CWE classification, safe alternative code, and severity assessment criteria. Use when performing security reviews involving 'vulnerability patterns', 'CWE', 'SQL Injection', 'XSS', 'security vulnerabilities', 'secure coding', 'vulnerable code', etc. Note: penetration testing execution and WAF configuration are outside the scope of this skill.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities and Security review. It works with Java and Python. The licence is Apache-2.0.

When your agent uses it

  • Performing security reviews involving vulnerability patterns
  • Security vulnerabilities
  • Vulnerable code

Example prompts

  • “vulnerability patterns”
  • “SQL Injection”
  • “security vulnerabilities”
  • “/vulnerability-patterns”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 8e8d35c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python, javascript, java and go).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • apache.org
    • xml.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vulnerability Patterns loads about 1.5k tokens when it runs. Until then it costs about 131 tokens; SKILL.md has 223 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~131
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from revfactory/harness-100 at commit 8e8d35c, republished under its Apache-2.0 licence (© revfactory). 223 words, ~1,527 tokens.

Download SKILL.mdSave it as .claude/skills/vulnerability-patterns/SKILL.md (or your agent's skills folder).
name
vulnerability-patterns
description
Code vulnerability pattern database. An extension skill for security-analyst that provides language-specific (Python/JS/Java/Go) vulnerable code patterns, CWE classification, safe alternative code, and severity assessment criteria. Use when performing security reviews involving 'vulnerability patterns', 'CWE', 'SQL Injection', 'XSS', 'security vulnerabilities', 'secure coding', 'vulnerable code', etc. Note: penetration testing execution and WAF configuration are outside the scope of this skill.

Vulnerability Patterns — Code Vulnerability Pattern Database

A reference of vulnerable code patterns, CWE classification, and safe alternatives used by the security-analyst agent during security reviews.

Target Agent

security-analyst — Directly applies the vulnerability patterns from this skill to code security analysis.

Vulnerability Classification System (CWE Top 25)

Priority Detection Targets
CWENameSeverityFrequency
CWE-79XSS (Cross-Site Scripting)HighVery high
CWE-89SQL InjectionCriticalHigh
CWE-78OS Command InjectionCriticalMedium
CWE-22Path TraversalHighMedium
CWE-352CSRFHighHigh
CWE-798Hardcoded CredentialsCriticalHigh
CWE-862Missing AuthorizationCriticalHigh
CWE-306Missing AuthenticationCriticalMedium
CWE-502DeserializationCriticalMedium
CWE-918SSRFHighMedium

Language-Specific Vulnerable Code Patterns

Python
SQL Injection (CWE-89)
python
# Vulnerable
query = f"SELECT * FROM users WHERE name = '{user_input}'"
cursor.execute(query)

# Safe
cursor.execute("SELECT * FROM users WHERE name = %s", (user_input,))
# Or use ORM (SQLAlchemy, Django ORM)
Command Injection (CWE-78)
python
# Vulnerable
os.system(f"ping {user_input}")
subprocess.call(f"ls {user_input}", shell=True)

# Safe
subprocess.run(["ping", user_input], shell=False)
# shlex.quote() for escaping (if unavoidable)
Path Traversal (CWE-22)
python
# Vulnerable
file_path = os.path.join(BASE_DIR, user_input)
open(file_path).read()

# Safe
file_path = os.path.realpath(os.path.join(BASE_DIR, user_input))
if not file_path.startswith(os.path.realpath(BASE_DIR)):
    raise ValueError("Invalid path")
YAML Deserialization (CWE-502)
python
# Vulnerable
data = yaml.load(user_input)  # Arbitrary code execution possible

# Safe
data = yaml.safe_load(user_input)
JavaScript/TypeScript
XSS (CWE-79)
javascript
// Vulnerable (React)
<div dangerouslySetInnerHTML={{__html: userInput}} />

// Safe
<div>{userInput}</div>  // React auto-escapes
// When needed, use DOMPurify
import DOMPurify from 'dompurify';
<div dangerouslySetInnerHTML={{__html: DOMPurify.sanitize(userInput)}} />
Prototype Pollution (CWE-1321)
javascript
// Vulnerable
function merge(target, source) {
  for (let key in source) {
    target[key] = source[key];  // __proto__ pollution possible
  }
}

// Safe
function merge(target, source) {
  for (let key of Object.keys(source)) {
    if (key === '__proto__' || key === 'constructor') continue;
    target[key] = source[key];
  }
}
// Or use Object.create(null)
ReDoS (CWE-1333)
javascript
// Vulnerable (Catastrophic Backtracking)
const regex = /^(a+)+$/;
regex.test("aaaaaaaaaaaaaaaaaaaaaaaaaaaaab");  // Exponential time

// Safe: Use non-backtracking patterns
const regex = /^a+$/;  // Remove nested repetition
eval/Function Execution (CWE-95)
javascript
// Vulnerable
eval(userInput);
new Function(userInput)();
setTimeout(userInput, 1000);

// Safe: Never use eval; use alternative logic
Java
SQL Injection (CWE-89)
java
// Vulnerable
String query = "SELECT * FROM users WHERE id = " + userId;
Statement stmt = conn.createStatement();
stmt.executeQuery(query);

// Safe
PreparedStatement ps = conn.prepareStatement("SELECT * FROM users WHERE id = ?");
ps.setInt(1, userId);
ps.executeQuery();
XXE (CWE-611)
java
// Vulnerable
DocumentBuilderFactory dbf = DocumentBuilderFactory.newInstance();
DocumentBuilder db = dbf.newDocumentBuilder();
db.parse(userInput);

// Safe
DocumentBuilderFactory dbf = DocumentBuilderFactory.newInstance();
dbf.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
dbf.setFeature("http://xml.org/sax/features/external-general-entities", false);
Deserialization (CWE-502)
java
// Vulnerable
ObjectInputStream ois = new ObjectInputStream(userInputStream);
Object obj = ois.readObject();  // Arbitrary code execution possible

// Safe: Use JSON/XML serialization (Jackson, Gson)
// Use ObjectInputFilter (Java 9+)
Go
SQL Injection (CWE-89)
go
// Vulnerable
query := fmt.Sprintf("SELECT * FROM users WHERE name = '%s'", userInput)
db.Query(query)

// Safe
db.Query("SELECT * FROM users WHERE name = $1", userInput)
Path Traversal (CWE-22)
go
// Vulnerable
http.ServeFile(w, r, filepath.Join(baseDir, r.URL.Path))

// Safe
cleanPath := filepath.Clean(r.URL.Path)
fullPath := filepath.Join(baseDir, cleanPath)
if !strings.HasPrefix(fullPath, baseDir) {
    http.Error(w, "Forbidden", 403)
    return
}

Severity Assessment Criteria

CVSS v3.1-Based Assessment
FactorWeightCriteria
Attack VectorHighNetwork (remote) > Local
Attack ComplexityHighLow complexity > High complexity
Privileges RequiredMediumNone > Low > High
User InteractionMediumNone > Required
Impact (CIA)HighEach confidentiality/integrity/availability
Practical Exploitability Assessment
FactorHigh RiskLow Risk
Input sourceExternal user inputInternal config
Data sensitivityPII, credentialsPublic data
AuthenticationUnauthenticatedAdmin only
Exploit complexitySimple string injectionMulti-step chain
Existing defensesNoneWAF, input validation present

© revfactory, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in en/21-code-reviewer/.claude/skills/vulnerability-patterns of revfactory/harness-100.

Open the folder on GitHubat commit 8e8d35c

Compare with similar skills

Vulnerability Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vulnerability Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vulnerability Patterns this skillrevfactory/harness-1001.3k—~1.5kAutomated safety check: PassApache-2.0
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Cyber NeoHainrixz/cyber-neo281—~5.9kAutomated safety check: WarnMIT

Similar skills

  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    281 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Security Review

    getsentry/warden

    Official

    Finds exploitable application security vulnerabilities in code changes.

    414 GitHub stars~1.8k tokensUpdated 6 days ago
    SecurityAuto-check passed

More from revfactory/harness-100

All 464 skills in this repo
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • API Error Design Patterns

    revfactory/harness-100

    Reference for designing how an API reports failures: structured error codes, response shapes, client-friendly messages, an error catalog and retry or fallback advice.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Arg Parser Generator

    revfactory/harness-100

    Methodology for systematically designing and generating CLI tool argument parser structures.

    1.3k GitHub stars~1.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Audience Segmentation

    revfactory/harness-100

    Audience segmentation skill used by the analyst and curator agents.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Audio Storytelling

    revfactory/harness-100

    Audio storytelling skill used by the podcast scriptwriter and show note editor.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed

Works with

Categories

Questions about Vulnerability Patterns

What does Vulnerability Patterns do?

Code vulnerability pattern database. An agent skill from revfactory/harness-100. Vulnerability Patterns is an agent skill from revfactory/harness-100. Code vulnerability pattern database.

When should I use Vulnerability Patterns?

Vulnerability Patterns fits situations like: performing security reviews involving vulnerability patterns; security vulnerabilities; vulnerable code.

How do I install Vulnerability Patterns in Claude Code?

Run `npx skills add revfactory/harness-100 --skill vulnerability-patterns -a claude-code`. Or copy the skill folder (en/21-code-reviewer/.claude/skills/vulnerability-patterns in revfactory/harness-100) into .claude/skills/vulnerability-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Vulnerability Patterns in Codex?

Run `npx skills add revfactory/harness-100 --skill vulnerability-patterns -a codex`. Or copy the skill folder (en/21-code-reviewer/.claude/skills/vulnerability-patterns in revfactory/harness-100) into .agents/skills/vulnerability-patterns in your project. Codex loads it when a task matches its description.

Can I use Vulnerability Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add revfactory/harness-100 --skill vulnerability-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulnerability-patterns, .gemini/skills/vulnerability-patterns, .github/skills/vulnerability-patterns and .opencode/skills/vulnerability-patterns in your project.

What does Vulnerability Patterns need to run?

SKILL.md names no scripts, command-line tools or credentials: Vulnerability Patterns is instructions for the agent only. Our summary lists: Python 3.

Does Vulnerability Patterns access the network?

SKILL.md names 2 domains. In commands or code: apache.org and xml.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Vulnerability Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vulnerability Patterns use?

Vulnerability Patterns is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vulnerability Patterns use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vulnerability Patterns?

Skills that share tags, products or a category with Vulnerability Patterns: Security Review (github/awesome-copilot, 40k stars), Security Auditor (eigent-ai/eigent, 15k stars), Code Audit (3stoneBrother/code-audit, 893 stars) and CodeQL Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vulnerability Patterns?

revfactory (a GitHub user) maintains it in revfactory/harness-100, which has 1,290 GitHub stars. The repository holds 464 skills in this directory. The repository was last updated on March 22, 2026.

Source: revfactory/harness-100 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.