Agent skill

Vuln Research

by tanweai in tanweai/xianzhi-research

安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.

No licenceAuto-check passedSecurity

Install Vuln Research

skills CLI
$ npx skills add tanweai/xianzhi-research --skill vuln-research -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tanweai/xianzhi-research vuln-research --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
vuln-research
GitHub stars
185
Token cost
~847 tokens
SKILL.md length
138 words
Files
11 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
None found

At a glance

安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research.

  • Works in 6 steps: 假设-验证循环 → 边界条件思维 → 防御反推 → …
  • Tasks that involve Capture the flag
  • SKILL.md covers 核心元思考模型, 快速导航, 元思考原则 and 使用指南, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Vuln Research is an agent skill from tanweai/xianzhi-research. 安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架。 Use this skill when: - 进行漏洞挖掘和安全研究时,需要系统化的思考框架 - 分析特定类型漏洞(Web注入、反序列化、二进制、域渗透等)的攻击路径 - 需要了解绕过防护措施(WAF、EDR、沙箱)的思维模式 - 进行代码审计需要Source-Sink分析方法论 - 红队攻防需要完整攻击链规划 - CTF竞赛需要快速解题思路 - 逆向分析恶意软件需要方法论指导 Triggers: 漏洞挖掘、安全研究、渗透测试、代码审计、红队攻防、CTF、逆向分析、 WAF绕过、免杀、提权、横向移动、域渗透、反序列化、二进制安全、Fuzzing

Its SKILL.md is about 850 tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including reference files (for example `README.md`, `references/binary-exploitation.md` and `references/case-index.md`).

It sits in Security, covering Capture the flag and Fuzzing.

When your agent uses it

  • Tasks that involve Capture the flag
  • Tasks that involve Fuzzing

Example prompts

  • “/vuln-research”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. 假设-验证循环
  2. 边界条件思维
  3. 防御反推
  4. 链式思维
  5. 版本敏感
  6. 语义差异

What it can do on your machine

Read from SKILL.md and the folder at commit 5be2798. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Vuln Research loads about 847 tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 84 tokens; SKILL.md has 138 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~847
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 138 words (~847 tokens).

name
vuln-research

Read the full SKILL.md on GitHub

Files

SKILL.md and 10 other files (references) in the repository root of tanweai/xianzhi-research.

  • SKILL.md
  • README.md
  • references/binary-exploitation.md
  • references/case-index.md
  • references/domain-pentest.md
  • references/fuzzing.md
  • references/privilege-bypass.md
  • references/rce-persistence.md
  • references/redteam-ctf.md
  • references/reverse-engineering.md
  • references/web-injection.md

Open the folder on GitHubat commit 5be2798

Compare with similar skills

Vuln Research next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Vuln Research compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Vuln Research this skilltanweai/xianzhi-research185—~847Automated safety check: PassNone
Adaptive Web FuzzingEncod3d-Sec/TORCH329—~1.3kAutomated safety check: PassMIT
Fizzpashov/skills1.2k2 repos~11kAutomated safety check: PassMIT
Reverse Flowlingbol088-spec/reverse-flow-skill940—~2.4kAutomated safety check: PassMIT
Ctf Osintljagiello/ctf-skills3.4k1 repos~2.3kAutomated safety check: NotesMIT
Fizz Syncpashov/skills1.2k2 repos~3.9kAutomated safety check: PassMIT

Similar skills

  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Fizz

    pashov/skills

    Generate Echidna/Medusa-compatible Solidity fuzz suites from Foundry or Hardhat projects.

    1.2k GitHub starsUsed in 2 repos~11k tokens
    SecurityAuto-check passed
  • Reverse Flow

    lingbol088-spec/reverse-flow-skill

    Guided reverse engineering workflow for binaries, firmware, mobile apps, scripts, document samples, protocol captures, and unknown artifacts.

    940 GitHub stars~2.4k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Ctf Osint

    ljagiello/ctf-skills

    Provides open source intelligence techniques for CTF challenges.

    3.4k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Fizz Sync

    pashov/skills

    Reconcile an existing Fizz harness with a changed source tree.

    1.2k GitHub starsUsed in 2 repos~3.9k tokens
    SecurityAuto-check passed
  • Research Fuzzer

    ARA-Labs/Agent-Native-Research-Artifact

    Treat an open-ended investigation the way a fuzzer treats a program.

    691 GitHub stars~2.4k tokensUpdated 3 days ago
    SecurityAuto-check passed

Categories

Questions about Vuln Research

What does Vuln Research do?

安全研究元思考方法论 - 从先知社区5600+篇安全文档中提炼的漏洞挖掘方法论框架. An agent skill from tanweai/xianzhi-research. Vuln Research is an agent skill from tanweai/xianzhi-research.

When should I use Vuln Research?

Vuln Research fits situations like: tasks that involve Capture the flag; tasks that involve Fuzzing.

How do I install Vuln Research in Claude Code?

Run `npx skills add tanweai/xianzhi-research --skill vuln-research -a claude-code`. Or copy the skill folder (the tanweai/xianzhi-research repository) into .claude/skills/vuln-research in your project. Claude Code loads it when a task matches its description.

How do I install Vuln Research in Codex?

Run `npx skills add tanweai/xianzhi-research --skill vuln-research -a codex`. Or copy the skill folder (the tanweai/xianzhi-research repository) into .agents/skills/vuln-research in your project. Codex loads it when a task matches its description.

Can I use Vuln Research in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tanweai/xianzhi-research --skill vuln-research -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/vuln-research, .gemini/skills/vuln-research, .github/skills/vuln-research and .opencode/skills/vuln-research in your project.

What does Vuln Research need to run?

SKILL.md names no scripts, command-line tools or credentials: Vuln Research is instructions for the agent only.

Does Vuln Research access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Vuln Research safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Vuln Research use?

No licence was found for Vuln Research or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Vuln Research use?

About 847 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 14k tokens, read only when the agent opens those files.

What are the alternatives to Vuln Research?

Skills that share tags, products or a category with Vuln Research: Adaptive Web Fuzzing (Encod3d-Sec/TORCH, 329 stars), Fizz (pashov/skills, 1.2k stars), Reverse Flow (lingbol088-spec/reverse-flow-skill, 940 stars) and Ctf Osint (ljagiello/ctf-skills, 3.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Vuln Research?

tanweai (a GitHub user) maintains it in tanweai/xianzhi-research, which has 185 GitHub stars. The repository was last updated on January 29, 2026.

Source: tanweai/xianzhi-research on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.