secknowledge-skill
Web and AI security testing knowledge and payloads
All Skills in This Repository (1)
Pure Emerald Level IndicatorsFrequently Asked Questions
FAQPage SchemaHow to install secknowledge-skill?โผ
Run `npx skills add Pa55w0rd/secknowledge-skill --all -g -y` in your terminal to install it globally for your AI coding assistant.
What does secknowledge-skill do?โผ
It gives your AI assistant a structured security testing knowledge base covering web vulnerabilities like SQL injection and XSS, plus AI risks like prompt injection, jailbreaks, and sandbox escape.
Can it help test LLM and AI agent security?โผ
Yes. It covers 173 GAARM AI risks across five domains, including prompt injection, MCP poisoning, RAG poisoning, agent misuse, and container escape, mapped to OWASP LLM and Agentic AI Top 10.
Does it include real attack payloads?โผ
Yes. Each reference file contains battle-tested payloads and WAF bypass techniques drawn from 88,636 real WooYun vulnerability cases, with strict rules against inventing unverified payloads.
Do I need security experience to use it?โผ
No. Describe your target in plain language and the skill routes the request to the right testing methodology, though it only outputs exploitation steps for authorized tests or CTF scenarios.
Related Repositories in Software Engineering
View All in Software Engineeringโopenclaw
Run a personal AI assistant across your devices and chat apps
superpowers
Gives coding agents a disciplined workflow from idea to merged code
react
AI agent skills for building, testing, and porting React core