Wooyun Legacy
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
Entry P0 primary router and operating doctrine for HackSkills.
$ npx skills add yaklang/hack-skills --skill hack -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install yaklang/hack-skills hack --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hack .claude/skills/hack && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hack" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/hack into .claude/skills/hack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hack", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/yaklang/hack-skills/tree/main/skills/hackType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add yaklang/hack-skills --skill hack -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install yaklang/hack-skills hack --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/hack .agents/skills/hack && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hack" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/hack into .agents/skills/hack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hack", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yaklang/hack-skills --skill hack -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install yaklang/hack-skills hack --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/hack .cursor/skills/hack && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hack" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/hack into .cursor/skills/hack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hack", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/yaklang/hack-skills.git --path skills/hack--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add yaklang/hack-skills --skill hack -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install yaklang/hack-skills hack --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/hack .gemini/skills/hack && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hack" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/hack into .gemini/skills/hack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hack", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install yaklang/hack-skills hackInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add yaklang/hack-skills --skill hack -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/hack .github/skills/hack && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hack" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/hack into .github/skills/hack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hack", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yaklang/hack-skills --skill hack -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install yaklang/hack-skills hack --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/hack .opencode/skills/hack && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hack" agent skill from https://github.com/yaklang/hack-skills/tree/main/skills/hack into .opencode/skills/hack/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hack", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hackEntry P0 primary router and operating doctrine for HackSkills.
Hack is an agent skill from yaklang/hack-skills. Entry P0 primary router and operating doctrine for HackSkills. Use when the task involves web application testing, API security assessment, recon, vulnerability triage, exploit path planning, authorized pentest, code audit, source-leak mining, middleware audit, SOC triage, detection engineering, incident response, or choosing the right next category skill before any deep topic skill. Also use when the user mentions 安全工程师, 渗透测试, 红队, 蓝队, 代码审计, 源码泄露, SRC. Enforce impact-first testing, finish the current asset…
Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files (for example `BLUE_TEAM.md`, `CODE_AUDIT.md` and `EVIDENCE_REPORT.md`).
It sits in Security, covering Security operations, Penetration testing and Bug bounty. The repository describes itself as: Helping AI Agent become an awesome practical hacker! The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 6fbf0bc. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Hack loads about 4.7k tokens when it runs. Until then it costs about 155 tokens; SKILL.md has 2,073 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
| `.git` / `.svn` / `.env` / backups / public buckets | Source leak | [SOURCE_LEAK.md](./SOURCE_LEAK.md) |Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from yaklang/hack-skills at commit 6fbf0bc, republished under its MIT licence (© yaklang). 2,073 words, ~4,670 tokens.
.claude/skills/hack/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.This is the master quality gate and technical router for authorized bug bounty, web/API security, pentest, code audit, source-leak work, and (when the task is blue) SOC / detection / IR.
It does not replace specialized techniques. It makes the agent:
This file is a quality gate, not a capability ceiling. Surfaces not listed here stay in play if field evidence exists.
This file is not an exploit cookbook. Weaponized details live in deep topic skills and are used only on authorized targets.
Load on demand:
Complete in order. Stop if any item is missing:
assets/ (URLs, API inventory, script excerpts), evidence/ (requests, diffs, screenshots), reports/ (confirmed findings only).Do not expand onto unauthorized assets.
| User intent | Primary flow | Load |
|---|---|---|
| Pentest / red team / foothold / SRC | §§3–5 | RED_TEAM.md, TEST_MATRIX.md |
| Code audit / whitebox / find sinks | §3 R6 | CODE_AUDIT.md |
| Source leak / Git leak / secret leak | §3 R5 | SOURCE_LEAK.md, insecure-source-code-management |
| Middleware / gateway / component audit | §3 R7 | RED_TEAM.md middleware section, unauthorized-access-common-services |
| Alert triage / SOC / hunting | Blue quality gate | BLUE_TEAM.md |
| Detection rules | Blue B6 | BLUE_TEAM.md, template in EVIDENCE_REPORT.md |
| IR / forensics / containment | Blue B7 | BLUE_TEAM.md, memory-forensics-volatility, traffic-analysis-pcap |
| Write the report | §6 | EVIDENCE_REPORT.md |
When a task crosses red and blue, freeze evidence for the current phase before switching role.
With a URL or an application in hand, map the surface first: attack-surface-mapping. Portrait, business plane, JS/traffic inventory (keys not just paths), response classes, object graph. Do not scan into a blank portrait. Do not open with directory brute or payload spray.
| Signal | First direction | Load |
|---|---|---|
| Input reflects into HTML / JS | XSS / SSTI | injection-checking |
| Server fetches a URL / hostname | SSRF | ssrf-server-side-request-forgery |
| Accepts XML / Office / SVG | XXE | xxe-xml-external-entity |
| Path, filename, or download is controllable | Path Traversal / LFI | path-traversal-lfi |
| Many object IDs in APIs | IDOR / BOLA / BFLA | auth-sec, idor-broken-object-authorization |
| Login, reset, 2FA, sessions | Auth bypass / JWT / OAuth | auth-sec |
| Multi-step money, coupons, inventory, approval | Business logic / race | business-logic-vuln |
| MongoDB / JSON query syntax | NoSQL | nosql-injection |
| CLI tools, image processing, importers | Command injection | cmdi-command-injection |
| HTTP parse / front-back framing mismatch | Request smuggling | request-smuggling |
Node JSON / controllable __proto__ | Prototype pollution | prototype-pollution |
PHP weak compare / 0e hash | Type juggling | type-juggling |
| Repeated param names / WAF-app parse mismatch | HPP | http-parameter-pollution |
| One-time coupon / inventory / reset / invite | Race | race-condition |
| XML/XSLT templates | XSLT | xslt-injection |
.git / .svn / .env / backups / public buckets | Source leak | SOURCE_LEAK.md |
| CSV/Excel export | CSV formula | csv-formula-injection |
| WebSocket upgrade | WebSocket | websocket-security |
| Internal package names | Dependency confusion | dependency-confusion |
| Business API returns 401/403 | Path / method / header bypass | 401-403-bypass-techniques |
| Public middleware admin / default ports | Default creds, debug, version defects | unauthorized-access-common-services |
| Chat assistant with command tools | Does the tool actually execute | llm-prompt-injection |
| File upload / preview / convert | Upload chain — do not stop at store+download | upload-insecure-files |
| GraphQL / OAuth JWT / gateway | Matching specialty; tick done or write N/A | api-sec, jwt-oauth-token-attacks |
Opening one check class does not mean firing only that one shot. Walk the rest of the matrix.
Full pass/fail rules: TEST_MATRIX.md. Default order:
id / userId / tenantId / fileKey / openid / ciphertext PK)Do not stop on a half-chain. Upload that stores, OTP that sends, or a copied secret string is not done. Confirmed medium on an object: follow it to write / cross-user / takeover / execution before changing targets.
A full "please log in" with no business fields is not an injection surface. Empty list, error, and timeout are not "please log in".
Finish the current asset cluster before expanding.
Shortest path to influential control first. Each candidate: can the attacker harm a real user or system now? The report narrative is the attack chain; CVSS is an appendix. Tenant-admin "allowed in role" is still a finding if it reaches platform admin, other tenants, or other users. Rank findings with the impact ladder in RED_TEAM.md; layer 7 (pure compliance) is appendix-only.
Do not stop at ".git exposed" or "repo is public". SOURCE_LEAK.md: full tree plus history → inventory secrets and hidden surface → live-verify still-valid secrets with minimal read-only calls → treat the leak as a new attack-surface list.
CODE_AUDIT.md. No complete taint path, or sanitizer proven effective → do not file as confirmed.
Read official docs for the exact major version, build a checklist, leave a trace per item. A middleware conclusion with no comparison table is unfinished.
Success is shorter dwell time, not close-rate. Details: BLUE_TEAM.md.
If the full repository is present, prefer these together. Previously separate mini skills (payload-selection, brute-selection) were merged back into their main skills.
Points baseline models miss that hit often in real bounty work:
alg, kid, JWKS, key source — do not blindly spray.Default three layers by audience:
Use templates in EVIDENCE_REPORT.md. Medium and above: write to disk immediately. Severe: notify the authorized contact immediately.
Two gates before a finding is "confirmed":
.git or a secret string as mere info-leak; code audit that lists dangerous function names without source→sink.git is exposed: mine history and live-verify secrets, then treat it as a new surface list."Recommended skill name: hack
Search keywords: HackSkills, HACKING SKILLS, bug bounty, security engineer ops
© yaklang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files in skills/hack of yaklang/hack-skills.
Open the folder on GitHubat commit 6fbf0bc
Hack next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hack this skillyaklang/hack-skills | 2.4k | — | ~4.7k | Automated safety check: Notes | MIT | |
| Wooyun Legacytanweai/wooyun-legacy | 1.8k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| 007sickn33/agentic-awesome-skills | 47k | 2 repos | ~410 | Automated safety check: Pass | MIT | |
| Implementing Continuous Security Validation With Basmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| Find Cybersecurity Firmjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~3.7k | Automated safety check: Notes | MIT | |
| Strix Code Vulnerability Scanusestrix/strix | 67k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 |
tanweai/wooyun-legacy
WooYun business logic vulnerability methodology — 22,132 real cases across 6 domains (authentication bypass, authorization bypass, payment tampering, information disclosure, logic flaws…
sickn33/agentic-awesome-skills
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
mukul975/Anthropic-Cybersecurity-Skills
Deploys Breach and Attack Simulation (BAS) platforms such as SafeBreach, AttackIQ, Picus, Cymulate, Pentera, or SCYTHE to continuously validate endpoint, network, email-gateway, SIEM, and…
jeremylongshore/tons-of-skills-marketplace
A skill your agent uses whenever the user wants to find, shortlist, vet, or enrich US cybersecurity firms — pen-testing/red team, security audits, vCISO, SOC 2 readiness, incident response, managed…
usestrix/strix
Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
yaklang/hack-skills
Anti-debugging detection and bypass playbook. An agent skill from yaklang/hack-skills.
yaklang/hack-skills
API authentication and JWT abuse playbook. An agent skill from yaklang/hack-skills.
yaklang/hack-skills
API authorization and BOLA testing playbook. An agent skill from yaklang/hack-skills.
yaklang/hack-skills
API reconnaissance and documentation review playbook. An agent skill from yaklang/hack-skills.
yaklang/hack-skills
Draw a testable attack surface from one authorized target URL or one application.
yaklang/hack-skills
Classical cipher analysis playbook. An agent skill from yaklang/hack-skills.
Categories
Entry P0 primary router and operating doctrine for HackSkills. Hack is an agent skill from yaklang/hack-skills. Entry P0 primary router and operating doctrine for HackSkills.
Hack fits situations like: the task involves web application testing; API security assessment; vulnerability triage; exploit path planning.
Run `npx skills add yaklang/hack-skills --skill hack -a claude-code`. Or copy the skill folder (skills/hack in yaklang/hack-skills) into .claude/skills/hack in your project. Claude Code loads it when a task matches its description.
Run `npx skills add yaklang/hack-skills --skill hack -a codex`. Or copy the skill folder (skills/hack in yaklang/hack-skills) into .agents/skills/hack in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaklang/hack-skills --skill hack -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hack, .gemini/skills/hack, .github/skills/hack and .opencode/skills/hack in your project.
SKILL.md names no scripts, command-line tools or credentials: Hack is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Hack is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Hack: Wooyun Legacy (tanweai/wooyun-legacy, 1.8k stars), 007 (sickn33/agentic-awesome-skills, 47k stars), Implementing Continuous Security Validation With Bas (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Find Cybersecurity Firm (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
yaklang (a GitHub organization) maintains it in yaklang/hack-skills, which has 2,394 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on September 13, 2026.
Source: yaklang/hack-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.