Agent skill

Vulnerability Patterns

by revfactory in revfactory/harness-100

코드 취약점 패턴 데이터베이스. An agent skill from revfactory/harness-100.

Apache-2.0Auto-check passedSecurity

Install Vulnerability Patterns

skills CLI
$ npx skills add revfactory/harness-100 --skill vulnerability-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install revfactory/harness-100 vulnerability-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/revfactory/harness-100.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ko/21-code-reviewer/.claude/skills/vulnerability-patterns .claude/skills/vulnerability-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vulnerability-patterns
GitHub stars
1.3k
Token cost
~1.5k tokens
SKILL.md length
321 words
Files
1
Skills in repo
464
Repo updated
First seen
Licence
Apache-2.0

At a glance

코드 취약점 패턴 데이터베이스. An agent skill from revfactory/harness-100.

  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers 대상 에이전트, 취약점 분류 체계 (CWE Top 25), 언어별 취약 코드 패턴 and 시크릿/민감정보 패턴, plus 2 more sections
  • Reaches apache.org and xml.org

What it does

Vulnerability Patterns is an agent skill from revfactory/harness-100. 코드 취약점 패턴 데이터베이스. 언어별(Python/JS/Java/Go) 취약 코드 패턴, CWE 분류, 안전한 대안 코드, 심각도 판정 기준을 제공하는 security-analyst 확장 스킬. '취약점 패턴', 'CWE', 'SQL Injection', 'XSS', '보안 취약점', '안전한 코딩', '취약 코드' 등 보안 리뷰 시 사용한다. 단, 침투 테스트 수행이나 WAF 설정은 이 스킬의 범위가 아니다.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities. It works with Java and Python. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Web application vulnerabilities

Example prompts

  • “SQL Injection”
  • “/vulnerability-patterns”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 8e8d35c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python, javascript, java and go).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • apache.org
    • xml.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vulnerability Patterns loads about 1.5k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 321 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from revfactory/harness-100 at commit 8e8d35c, republished under its Apache-2.0 licence (© revfactory). 321 words, ~1,456 tokens.

Download SKILL.mdSave it as .claude/skills/vulnerability-patterns/SKILL.md (or your agent's skills folder).
name
vulnerability-patterns
description
코드 취약점 패턴 데이터베이스. 언어별(Python/JS/Java/Go) 취약 코드 패턴, CWE 분류, 안전한 대안 코드, 심각도 판정 기준을 제공하는 security-analyst 확장 스킬. '취약점 패턴', 'CWE', 'SQL Injection', 'XSS', '보안 취약점', '안전한 코딩', '취약 코드' 등 보안 리뷰 시 사용한다. 단, 침투 테스트 수행이나 WAF 설정은 이 스킬의 범위가 아니다.

Vulnerability Patterns — 코드 취약점 패턴 데이터베이스

security-analyst 에이전트가 보안 리뷰 시 활용하는 취약 코드 패턴, CWE 분류, 안전한 대안 레퍼런스.

대상 에이전트

security-analyst — 이 스킬의 취약점 패턴을 코드 보안 분석에 직접 적용한다.

취약점 분류 체계 (CWE Top 25)

최우선 검출 대상
CWE이름심각도빈도
CWE-79XSS (Cross-Site Scripting)High매우 높음
CWE-89SQL InjectionCritical높음
CWE-78OS Command InjectionCritical중간
CWE-22Path TraversalHigh중간
CWE-352CSRFHigh높음
CWE-798Hardcoded CredentialsCritical높음
CWE-862Missing AuthorizationCritical높음
CWE-306Missing AuthenticationCritical중간
CWE-502DeserializationCritical중간
CWE-918SSRFHigh중간

언어별 취약 코드 패턴

Python
SQL Injection (CWE-89)
python
# 취약
query = f"SELECT * FROM users WHERE name = '{user_input}'"
cursor.execute(query)

# 안전
cursor.execute("SELECT * FROM users WHERE name = %s", (user_input,))
# 또는 ORM 사용 (SQLAlchemy, Django ORM)
Command Injection (CWE-78)
python
# 취약
os.system(f"ping {user_input}")
subprocess.call(f"ls {user_input}", shell=True)

# 안전
subprocess.run(["ping", user_input], shell=False)
# shlex.quote()로 이스케이프 (부득이한 경우)
Path Traversal (CWE-22)
python
# 취약
file_path = os.path.join(BASE_DIR, user_input)
open(file_path).read()

# 안전
file_path = os.path.realpath(os.path.join(BASE_DIR, user_input))
if not file_path.startswith(os.path.realpath(BASE_DIR)):
    raise ValueError("Invalid path")
YAML Deserialization (CWE-502)
python
# 취약
data = yaml.load(user_input)  # 임의 코드 실행 가능

# 안전
data = yaml.safe_load(user_input)
JavaScript/TypeScript
XSS (CWE-79)
javascript
// 취약 (React)
<div dangerouslySetInnerHTML={{__html: userInput}} />

// 안전
<div>{userInput}</div>  // React 자동 이스케이프
// 필요 시 DOMPurify
import DOMPurify from 'dompurify';
<div dangerouslySetInnerHTML={{__html: DOMPurify.sanitize(userInput)}} />
Prototype Pollution (CWE-1321)
javascript
// 취약
function merge(target, source) {
  for (let key in source) {
    target[key] = source[key];  // __proto__ 오염 가능
  }
}

// 안전
function merge(target, source) {
  for (let key of Object.keys(source)) {
    if (key === '__proto__' || key === 'constructor') continue;
    target[key] = source[key];
  }
}
// 또는 Object.create(null) 사용
ReDoS (CWE-1333)
javascript
// 취약 (Catastrophic Backtracking)
const regex = /^(a+)+$/;
regex.test("aaaaaaaaaaaaaaaaaaaaaaaaaaaaab");  // 지수적 시간

// 안전: 비백트래킹 패턴 사용
const regex = /^a+$/;  // 중첩 반복 제거
eval/Function 실행 (CWE-95)
javascript
// 취약
eval(userInput);
new Function(userInput)();
setTimeout(userInput, 1000);

// 안전: eval 사용 금지, 대안 로직 사용
Java
SQL Injection (CWE-89)
java
// 취약
String query = "SELECT * FROM users WHERE id = " + userId;
Statement stmt = conn.createStatement();
stmt.executeQuery(query);

// 안전
PreparedStatement ps = conn.prepareStatement("SELECT * FROM users WHERE id = ?");
ps.setInt(1, userId);
ps.executeQuery();
XXE (CWE-611)
java
// 취약
DocumentBuilderFactory dbf = DocumentBuilderFactory.newInstance();
DocumentBuilder db = dbf.newDocumentBuilder();
db.parse(userInput);

// 안전
DocumentBuilderFactory dbf = DocumentBuilderFactory.newInstance();
dbf.setFeature("http://apache.org/xml/features/disallow-doctype-decl", true);
dbf.setFeature("http://xml.org/sax/features/external-general-entities", false);
Deserialization (CWE-502)
java
// 취약
ObjectInputStream ois = new ObjectInputStream(userInputStream);
Object obj = ois.readObject();  // 임의 코드 실행 가능

// 안전: JSON/XML 직렬화 사용 (Jackson, Gson)
// ObjectInputFilter 사용 (Java 9+)
Go
SQL Injection (CWE-89)
go
// 취약
query := fmt.Sprintf("SELECT * FROM users WHERE name = '%s'", userInput)
db.Query(query)

// 안전
db.Query("SELECT * FROM users WHERE name = $1", userInput)
SSRF (CWE-918)
go
// 취약
resp, err := http.Get(userProvidedURL)

// 안전: URL 화이트리스트 + 내부 IP 차단
parsedURL, _ := url.Parse(userProvidedURL)
if isInternalIP(parsedURL.Hostname()) {
    return errors.New("internal IP not allowed")
}

시크릿/민감정보 패턴

탐지 대상 패턴
유형정규식 패턴 (간략)심각도
AWS Access KeyAKIA[0-9A-Z]{16}Critical
AWS Secret Key[A-Za-z0-9/+=]{40} (AKIA와 함께)Critical
GitHub Tokengh[ps]_[A-Za-z0-9_]{36,}Critical
Google API KeyAIza[0-9A-Za-z_-]{35}High
Slack Tokenxox[baprs]-[0-9a-zA-Z-]+High
JWTeyJ[A-Za-z0-9_-]+\.eyJ[A-Za-z0-9_-]+High
Private Key`-----BEGIN (RSAEC
비밀번호 변수password\s*=\s*['"][^'"]+['"]Critical
DB Connection String`(mysqlpostgresql

심각도 판정 매트릭스

요소CriticalHighMediumLow
공격 용이성네트워크, 인증 불필요네트워크, 일부 조건로컬, 인증 필요물리적 접근
영향시스템 완전 장악데이터 유출서비스 저하정보 노출 (제한적)
데이터 범위전체 DB사용자 개인정보비민감 데이터공개 데이터
기밀성전면 노출부분 노출간접 노출미미

보안 리뷰 체크리스트

인증/인가
  • 모든 엔드포인트에 인증 확인
  • 객체 수준 인가 (자신의 데이터만 접근)
  • 관리자 기능 권한 분리
  • 비밀번호 해싱 (bcrypt/Argon2)
  • Rate Limiting 적용
입력 처리
  • 모든 입력 검증 (타입, 길이, 범위)
  • SQL 파라미터 바인딩 (ORM 또는 Prepared Statement)
  • HTML/JS 출력 이스케이핑
  • 파일 업로드 타입/크기 제한
  • URL/경로 입력 검증
데이터 보호
  • 민감 데이터 암호화 (저장/전송)
  • 로그에 민감 정보 미포함
  • 에러 응답에 내부 정보 미노출
  • HTTPS 강제
  • 보안 헤더 설정
의존성
  • 알려진 CVE 없는 버전
  • 불필요한 의존성 제거
  • 라이선스 호환성 확인

© revfactory, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in ko/21-code-reviewer/.claude/skills/vulnerability-patterns of revfactory/harness-100.

Open the folder on GitHubat commit 8e8d35c

Compare with similar skills

Vulnerability Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vulnerability Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vulnerability Patterns this skillrevfactory/harness-1001.3k—~1.5kAutomated safety check: PassApache-2.0
Taint Instrumentation AssistantArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: PassApache-2.0
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Insecure Deserialization PlaybookPentesterFlow/agent1.4k—~1.7kAutomated safety check: PassApache-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone

Similar skills

  • Taint Instrumentation Assistant

    ArabelaTso/Skills-4-SE

    Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

    253 GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization.

    1.4k GitHub stars~1.7k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    SecurityAuto-check: notes

More from revfactory/harness-100

All 464 skills in this repo
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • API Error Design Patterns

    revfactory/harness-100

    Reference for designing how an API reports failures: structured error codes, response shapes, client-friendly messages, an error catalog and retry or fallback advice.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Arg Parser Generator

    revfactory/harness-100

    Methodology for systematically designing and generating CLI tool argument parser structures.

    1.3k GitHub stars~1.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Audience Segmentation

    revfactory/harness-100

    Audience segmentation skill used by the analyst and curator agents.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Audio Storytelling

    revfactory/harness-100

    Audio storytelling skill used by the podcast scriptwriter and show note editor.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed

Works with

Categories

Questions about Vulnerability Patterns

What does Vulnerability Patterns do?

코드 취약점 패턴 데이터베이스. An agent skill from revfactory/harness-100. Vulnerability Patterns is an agent skill from revfactory/harness-100. 코드 취약점 패턴 데이터베이스.

When should I use Vulnerability Patterns?

Vulnerability Patterns fits situations like: tasks that involve Web application vulnerabilities.

How do I install Vulnerability Patterns in Claude Code?

Run `npx skills add revfactory/harness-100 --skill vulnerability-patterns -a claude-code`. Or copy the skill folder (ko/21-code-reviewer/.claude/skills/vulnerability-patterns in revfactory/harness-100) into .claude/skills/vulnerability-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Vulnerability Patterns in Codex?

Run `npx skills add revfactory/harness-100 --skill vulnerability-patterns -a codex`. Or copy the skill folder (ko/21-code-reviewer/.claude/skills/vulnerability-patterns in revfactory/harness-100) into .agents/skills/vulnerability-patterns in your project. Codex loads it when a task matches its description.

Can I use Vulnerability Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add revfactory/harness-100 --skill vulnerability-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vulnerability-patterns, .gemini/skills/vulnerability-patterns, .github/skills/vulnerability-patterns and .opencode/skills/vulnerability-patterns in your project.

What does Vulnerability Patterns need to run?

SKILL.md names no scripts, command-line tools or credentials: Vulnerability Patterns is instructions for the agent only. Our summary lists: Python 3.

Does Vulnerability Patterns access the network?

SKILL.md names 2 domains. In commands or code: apache.org and xml.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Vulnerability Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vulnerability Patterns use?

Vulnerability Patterns is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Vulnerability Patterns use?

About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Vulnerability Patterns?

Skills that share tags, products or a category with Vulnerability Patterns: Taint Instrumentation Assistant (ArabelaTso/Skills-4-SE, 253 stars), Security Review (github/awesome-copilot, 40k stars), Insecure Deserialization Playbook (PentesterFlow/agent, 1.4k stars) and Security Auditor (eigent-ai/eigent, 15k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vulnerability Patterns?

revfactory (a GitHub user) maintains it in revfactory/harness-100, which has 1,290 GitHub stars. The repository holds 464 skills in this directory. The repository was last updated on March 22, 2026.

Source: revfactory/harness-100 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.