Wooyun Legacy
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
A skill your agent uses when publishing, open-sourcing, exporting, sanitizing, or moving code, agent skills, prompts, templates, fixtures, datasets, workshop assets, or other artifacts from a…
$ npx skills add serejaris/personal-corp-os --skill safe-public-release -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install serejaris/personal-corp-os safe-public-release --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/serejaris/personal-corp-os.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/safe-public-release .claude/skills/safe-public-release && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "safe-public-release" agent skill from https://github.com/serejaris/personal-corp-os/tree/main/skills/safe-public-release into .claude/skills/safe-public-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "safe-public-release", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/serejaris/personal-corp-os/tree/main/skills/safe-public-releaseType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add serejaris/personal-corp-os --skill safe-public-release -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install serejaris/personal-corp-os safe-public-release --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/serejaris/personal-corp-os.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/safe-public-release .agents/skills/safe-public-release && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "safe-public-release" agent skill from https://github.com/serejaris/personal-corp-os/tree/main/skills/safe-public-release into .agents/skills/safe-public-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "safe-public-release", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add serejaris/personal-corp-os --skill safe-public-release -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install serejaris/personal-corp-os safe-public-release --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/serejaris/personal-corp-os.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/safe-public-release .cursor/skills/safe-public-release && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "safe-public-release" agent skill from https://github.com/serejaris/personal-corp-os/tree/main/skills/safe-public-release into .cursor/skills/safe-public-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "safe-public-release", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/serejaris/personal-corp-os.git --path skills/safe-public-release--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add serejaris/personal-corp-os --skill safe-public-release -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install serejaris/personal-corp-os safe-public-release --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/serejaris/personal-corp-os.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/safe-public-release .gemini/skills/safe-public-release && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "safe-public-release" agent skill from https://github.com/serejaris/personal-corp-os/tree/main/skills/safe-public-release into .gemini/skills/safe-public-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "safe-public-release", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install serejaris/personal-corp-os safe-public-releaseInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add serejaris/personal-corp-os --skill safe-public-release -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/serejaris/personal-corp-os.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/safe-public-release .github/skills/safe-public-release && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "safe-public-release" agent skill from https://github.com/serejaris/personal-corp-os/tree/main/skills/safe-public-release into .github/skills/safe-public-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "safe-public-release", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add serejaris/personal-corp-os --skill safe-public-release -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install serejaris/personal-corp-os safe-public-release --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/serejaris/personal-corp-os.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/safe-public-release .opencode/skills/safe-public-release && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "safe-public-release" agent skill from https://github.com/serejaris/personal-corp-os/tree/main/skills/safe-public-release into .opencode/skills/safe-public-release/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "safe-public-release", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
safe-public-releaseA skill your agent uses when publishing, open-sourcing, exporting, sanitizing, or moving code, agent skills, prompts, templates, fixtures, datasets, workshop assets, or other artifacts from a…
Safe Public Release is an agent skill from serejaris/personal-corp-os. Use when publishing, open-sourcing, exporting, sanitizing, or moving code, agent skills, prompts, templates, fixtures, datasets, workshop assets, or other artifacts from a private repository, vendor/runtime environment, or mixed working directory into a public repository or registry. Builds a provenance inventory, license/security review, explicit allowlist, clean staging package, approval dry run, and fresh public clone/install smoke. Triggers on "open source this", "publish these skills", "make this repo…
Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `README.md`, `README.ru.md` and `references/release-checklist.md`).
It sits in Security, covering Bug bounty and Security review. The repository describes itself as: Personal Corp OS — управление личной компанией через AI-агентов: задачи вне головы, отделы вместо памяти, недельное ретро. Открытые скиллы для Claude Code и Codex. The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 95e36c3. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
rggitgitleaksrsyncFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Safe Public Release loads about 3.4k tokens when it runs, and up to ~5k if it reads all its reference files. Until then it costs about 187 tokens; SKILL.md has 1,321 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- `.env*`, API keys, OAuth state, cookies, credentials;Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from serejaris/personal-corp-os at commit 95e36c3, republished under its MIT licence (© serejaris). 1,321 words, ~3,363 tokens.
.claude/skills/safe-public-release/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Turn a private, vendor-provided, runtime-generated, or mixed artifact into a public package without leaking secrets, private state, or material that cannot be redistributed.
One pipeline:
intent → owner issue tree → inventory → provenance → license → security/privacy → allowlist → clean package → approval → publish → fresh public verification → maintenance
The skill is allowlist-first. Never copy a whole runtime/private directory and hope denylist cleanup finds everything.
Publishing is an outward mutation. Before creating a public repository, changing visibility, pushing a release, or publishing to a registry:
PACKAGE-READY with no unresolved provenance/license/security blockers;A request to "prepare" or "review" a release authorizes read-only analysis and private/internal artifacts, not public publication.
corp-new; it requires a separate approval dry run.Resolve configuration from the user, project instructions, then defaults:
## Safe Public Release Config
- internal_owner_repo: owner/corp-opensource-or-project
- public_github_owner: owner
- staging_root: /tmp/safe-public-release
- allowed_public_licenses: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause
- secret_scanners: gitleaks, trufflehog
- approval_mode: explicit-before-publishDo not block preparation when optional scanners are unavailable. Record the limitation and keep the release blocked until equivalent manual and repository-native checks are completed. Never claim a scan ran when it did not.
Before extraction or packaging, find or create three scopes in the internal owner repo:
Separate unrelated work:
If the user has an issue-management skill such as manager, use it for the issue tree and cross-repo links.
Use exactly one current status:
DISCOVEREDINVENTORYPROVENANCE-CLEAREDLICENSE-CLEAREDSECURITY-CLEAREDPACKAGE-READYAPPROVEDPUBLISHEDVERIFIEDMAINTAINEDBLOCKED-PROVENANCEBLOCKED-LICENSEBLOCKED-SECURITYBLOCKED-OWNER-APPROVALNO-GO-VENDOR-PROTECTEDNO-GO-MIXED-PRIVATE-DATAEvery blocked status needs one concrete unblock_event: source found, written permission, license clarified, secret removed and rotated, scope reduced, or owner approval.
Record:
Do not create the public repository yet.
Create release-manifest.yaml using the bundled template.
For each candidate artifact record:
Visibility inside an application or runtime does not prove ownership or permission to redistribute.
| Class | Default decision |
|---|---|
| Owner-authored source | Candidate after license/security review |
| Third-party redistributable source | Candidate with preserved notices |
| Generated build artifact | Regenerate from allowlisted source |
| Runtime state, cache, queue, session | Exclude |
| Logs, transcripts, histories | Exclude or separate privacy review |
| Credentials, tokens, cookies, keys | Exclude; rotate if exposed |
| Customer, student, employee, user data | Exclude; aggregate only under a separate privacy owner |
| Vendor-protected or unknown source | Block |
| Mixed bundle | Split before review |
| Symlink, submodule, archive, binary | Inspect target/content and license before allowlist |
Every file in the future public tree must be reachable from an explicit allowlist entry.
For each candidate prove:
Unknown provenance → BLOCKED-PROVENANCE.
Do not publish a "cleaned up" artifact whose origin cannot be explained.
Check:
Attribution is not permission. A missing, custom, or unclear license means BLOCKED-LICENSE until the artifact is excluded or permission is obtained.
The skill does not provide legal advice. When license interpretation changes material risk, record the evidence and route the decision to the appropriate owner or counsel.
Exclude at minimum:
.env*, API keys, OAuth state, cookies, credentials;Run checks on the clean staging tree, not only the source directory:
find . -type l -print
find . -type f -size +10M -print
rg -n --hidden -S '(api[_-]?key|secret|token|password|BEGIN [A-Z ]*PRIVATE KEY|Authorization: Bearer)' .
rg -n --hidden -S '(/Users/|/home/|C:\\Users\\|private-|corp-|localhost:[0-9]{2,5})' .
git diff --checkWhen approved tools are available:
gitleaks detect --no-git --source .
trufflehog filesystem --no-update .A scanner passing does not replace manual review. A live secret finding stops the release: remove it, rotate it, document internally, rerun all relevant checks.
Never copy the whole source tree first.
allowlist.txt from the reviewed manifest.Example:
rm -rf "$STAGING_ROOT/package"
mkdir -p "$STAGING_ROOT/package"
rsync -a --files-from=allowlist.txt SOURCE_ROOT/ "$STAGING_ROOT/package/"
cd "$STAGING_ROOT/package"
find . -type f -print | sortOrphaning a SKILL.md from its references/scripts is a failed package, even when the main file is safe.
The package must contain or link to:
README.md;Do not claim compatibility that the public smoke test has not verified.
Use the bundled checklist. Show the user:
Release: <name>
Target: <public owner/repo or registry>
Allowed artifacts: <count and short list>
Blocked/excluded artifacts: <count and reasons>
Source licenses: <summary>
Security/privacy checks actually run: <commands and results>
Fresh-clone verification plan: <command>
Maintenance owner: <owner>
Open risks: <none or list>
Proposed outward action: create repo | change visibility | push | publish packageStop and request explicit approval. Continue only for the exact target and artifact set approved.
After approval:
refs owner/repo#N;If the public target is different from the approved dry run, stop and re-approve.
Test as an external user from a fresh directory:
workdir=$(mktemp -d)
git clone --depth 1 https://github.com/OWNER/REPO.git "$workdir/repo"
cd "$workdir/repo"Run the documented public command:
--help or bounded smoke;Repeat the relevant secret/private-path scans on the fresh clone. PUBLISHED becomes VERIFIED only after this passes.
Write a release evidence card in the internal owner issue:
release_status: VERIFIED
public_url: https://github.com/OWNER/REPO
source_version: ...
manifest: release-manifest.yaml
license_basis: ...
security_checks: ...
publication_commit: ...
fresh_clone_command: ...
fresh_clone_result: PASS
maintenance_owner: ...
next_review: YYYY-MM-DDAfter every release or blocked decision, add the new failure mode or rule to this skill or its references.
| Failure | Rule |
|---|---|
| Runtime folder copied wholesale | Allowlist-first clean staging |
| Attribution added, license still unknown | Attribution is not permission; block |
| Main skill copied without references/scripts | Release the complete functional bundle |
| Secret scan green, private path leaked | Manual classification plus private-path scan |
| Works in owner checkout, fails after clone | Fresh public-boundary smoke is mandatory |
| Evaluation mixed with redistribution | Separate issues and risk owners |
| Public repo created before inventory | No outward mutation before PACKAGE-READY and approval |
| Vendor asset visible in UI/runtime | Visibility does not imply redistribution rights |
| Release published with no owner | Maintenance owner and next review are required |
Report only verified facts:
Prepared: <artifact/release>
Status: <state>
Public action: published | not published
Target: <URL or planned target>
Allowed: <count>
Blocked/excluded: <count + reasons>
Checks run: <summary>
Fresh public verification: PASS | NOT RUN | FAILED
Owner issue: <reference>
Next gate: <one concrete action>© serejaris, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references) in skills/safe-public-release of serejaris/personal-corp-os.
Open the folder on GitHubat commit 95e36c3
Safe Public Release next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Safe Public Release this skillserejaris/personal-corp-os | 229 | — | ~3.4k | Automated safety check: Notes | MIT | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Flounderadshao/flounder | 518 | — | ~9.2k | Automated safety check: Pass | AGPL-3.0 | |
| Security Analysismicrosoft/haste | 107 | — | ~1k | Automated safety check: Pass | MIT | |
| Vulnerability Triage Brocardstrailofbits/skills | 7.5k | — | ~2.2k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Security Specialistfabricioctelles/skills | 106 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 |
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
adshao/flounder
Operates Flounder, an autonomous white-hat security auditor.
microsoft/haste
Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.
trailofbits/skills
Screens vulnerability reports, CVEs and automated findings against seven rules of thumb to accept, dismiss or ask for more information before any deep analysis.
fabricioctelles/skills
Runs security audits on codebases — full scans, diff reviews, threat models, vulnerability triage, remediation guidance, and finding tracking.
yaklang/hack-skills
Entry P0 primary router and operating doctrine for HackSkills.
serejaris/personal-corp-os
A skill your agent uses when the user is transitioning from a completed retro into a weekly plan, choosing weekly outcomes, scheduling a full ISO week, or asking for "план на неделю", "weekly…
serejaris/personal-corp-os
A skill your agent uses when creating, searching, updating, or managing GitHub issues via CLI.
serejaris/personal-corp-os
A skill your agent uses when auditing a product, business, or project ecosystem — analyzing data sources, decision loops, bottlenecks, and implementation contours.
serejaris/personal-corp-os
A skill your agent uses when operating, debugging, deploying, or monitoring a Telegram bot or Telegram-to-agent gateway.
serejaris/personal-corp-os
Audits the agent rules in the current folder (AGENTS.md, nested AGENTS.md files) and the skill descriptions the agent sees at start, then reports what to cut, move or rewrite and edits only after…
serejaris/personal-corp-os
Создаёт несколько вариантов дизайна 2D-поверхности (лендинг, герой, обложка, слайды): свой визуальный референс и автор на вариант, полный design.md с UTC/SHA-256 до кода, проверка в браузере…
Categories
A skill your agent uses when publishing, open-sourcing, exporting, sanitizing, or moving code, agent skills, prompts, templates, fixtures, datasets, workshop assets, or other artifacts from a…. Safe Public Release is an agent skill from serejaris/personal-corp-os. Use when publishing, open-sourcing, exporting, sanitizing, or moving code, agent skills, prompts, templates, fixtures, datasets, workshop assets, or other artifacts from a private repository, vendor/runtime environment, or mixed working directory into a public repository or registry.
Safe Public Release fits situations like: workshop assets; other artifacts from a private repository; vendor/runtime environment; mixed working directory into a public repository.
Run `npx skills add serejaris/personal-corp-os --skill safe-public-release -a claude-code`. Or copy the skill folder (skills/safe-public-release in serejaris/personal-corp-os) into .claude/skills/safe-public-release in your project. Claude Code loads it when a task matches its description.
Run `npx skills add serejaris/personal-corp-os --skill safe-public-release -a codex`. Or copy the skill folder (skills/safe-public-release in serejaris/personal-corp-os) into .agents/skills/safe-public-release in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add serejaris/personal-corp-os --skill safe-public-release -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/safe-public-release, .gemini/skills/safe-public-release, .github/skills/safe-public-release and .opencode/skills/safe-public-release in your project.
Going by SKILL.md and its folder, Safe Public Release needs the command-line tools its instructions call (rg, git, gitleaks and rsync).
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Safe Public Release is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Safe Public Release: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), Flounder (adshao/flounder, 518 stars), Security Analysis (microsoft/haste, 107 stars) and Vulnerability Triage Brocards (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
serejaris (a GitHub user) maintains it in serejaris/personal-corp-os, which has 229 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on October 7, 2026.
Source: serejaris/personal-corp-os on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.