tanweaitanweaiCommunityยท1 Agent Skills Included

xianzhi-research

Expert vulnerability research and penetration testing methodology

Guides security research with a four-layer thinking framework distilled from 5,600+ real-world vulnerability articles. Covers web injection, deserialization, binary exploitation, domain penetration, code auditing, fuzzing, and reverse engineering. Eliminates guesswork when you are stuck on an exploit path, WAF bypass, or attack chain plan. Helps researchers and beginners analyze CVEs and audit code with expert-level reasoning.
npx skills add tanweai/xianzhi-research --all -g -y

All Skills in This Repository (1)

Pure Emerald Level Indicators

Frequently Asked Questions

FAQPage Schema
How to install xianzhi-research?โ–ผ

Run `npx skills add tanweai/xianzhi-research --all -g -y` in your terminal to install the skill globally.

What does the vuln-research skill do?โ–ผ

It gives your AI a structured security research methodology covering web injection, binary exploitation, domain penetration, fuzzing, and reverse engineering, so it reasons like an expert researcher instead of just listing facts.

Can it help when my exploit approach is stuck?โ–ผ

Yes. It applies a four-layer thinking model that shifts from attack surface mapping to defense reverse-engineering, helping you find bypasses such as WAF evasion or alternate attack chains.

Does it work with Claude Code?โ–ผ

Yes. It follows the standard SKILL.md format and can be invoked in Claude Code with commands like /vuln-research followed by your research question.

Is it suitable for security beginners?โ–ผ

Yes. It was built to transfer expert thinking patterns to newcomers, with topic modules and a CVE case index that guide analysis step by step.

Related Repositories in Software Engineering

View All in Software Engineeringโ†’