wgpsecwgpsecOfficialยท117 Agent Skills Included

AboutSecurity

Structured penetration testing knowledge base with 200+ AI-executable attack methodologies

Provides 200+ step-by-step penetration testing skills covering web exploitation, network services, cloud, AI security, post-exploitation, and forensics. Eliminates guesswork during security assessments with ready-to-use attack decision trees, payload references, and 600+ documented CVE entries. Guides AI agents through full attack chains from reconnaissance to privilege escalation with strict behavioral rules per technique.
npx skills add wgpsec/AboutSecurity --all -g -y
Available:

Each AGENT.md gives the AI agent strict behavioral rules for a specific attack technique, including mandatory first steps, forbidden actions, preferred tools, and when to load detailed reference payloads.

All Skills in This Repository (117)

Pure Emerald Level Indicators
๐Ÿ“ฆ In Repo
wgpsecwgpsec

post-exploit-linux

Plan and execute Linux post-exploitation workflows from initial access through privilege escalation.

Official
Advanced
๐Ÿ“ฆ In Repo
wgpsecwgpsec

graphql-methodology

Identify GraphQL endpoints and test introspection, injection, and authorization bypass.

Official
Advanced
๐Ÿ“ฆ In Repo
wgpsecwgpsec

java-deserialization-methodology

Identify Java deserialization weaknesses by analyzing serialized payload markers and middleware exposure.

Official
Advanced
๐Ÿ“ฆ In Repo
wgpsecwgpsec

idor-methodology

Identifies and assesses XSS vulnerabilities in web applications and prescribes remediation steps.

Official
Advanced
๐Ÿ“ฆ In Repo
wgpsecwgpsec

nosql-injection

Identify NoSQL injection vulnerabilities in JSON-based application inputs.

Official
Advanced
๐Ÿ“ฆ In Repo
wgpsecwgpsec

business-logic-attack

Detect business logic vulnerabilities in e-commerce transactional flows.

Official
Advanced
๐Ÿ“ฆ In Repo
wgpsecwgpsec

information-disclosure-methodology

Detect and exploit web application information disclosure leaks to acquire credentials.

Official
Intermediate
๐Ÿ“ฆ In Repo
wgpsecwgpsec

oauth-sso-attack

Test OAuth 2.0 and OpenID Connect flows for redirect_uri, state, and token weaknesses.

Official
Advanced
๐Ÿ“ฆ In Repo
wgpsecwgpsec

api-fuzz

Automate API security testing with endpoint discovery and semantic fuzzing.

Official
Intermediate
๐Ÿ“ฆ In Repo
wgpsecwgpsec

jwt-attack-methodology

Decode JWT tokens and execute attacks like none-alg and weak-key brute force.

Official
Advanced
๐Ÿ“ฆ In Repo
wgpsecwgpsec

crypto-web-attack

Identify and analyze cryptographic weaknesses in web applications.

Official
Advanced
๐Ÿ“ฆ In Repo
wgpsecwgpsec

subdomain-takeover

Detect and validate subdomain takeover risks via CNAME, NS, and MX DNS signals.

Official
Advanced

Frequently Asked Questions

FAQPage Schema
How to install AboutSecurity?โ–ผ

Run `npx skills add wgpsec/AboutSecurity --all -g -y` in your terminal to install all security skills globally for your AI agent.

What is AboutSecurity used for?โ–ผ

It is a structured penetration testing knowledge base with 200+ AI-executable skills covering web exploits, network services, cloud attacks, post-exploitation, and digital forensics.

Can AI agents use AboutSecurity for automated pentesting?โ–ผ

Yes. Each skill contains decision trees, behavioral rules, and payload references designed for AI agents to execute full attack chains autonomously in Claude Code, Cursor, and similar tools.

Does AboutSecurity include vulnerability PoC data?โ–ผ

Yes. The Vuln directory contains 600+ structured vulnerability entries with affected versions and exploitation steps for middleware, web applications, and cloud platforms.

Do I need security experience to use AboutSecurity?โ–ผ

Basic security knowledge helps, but the skills are written as step-by-step methodologies that guide you or your AI agent through each attack phase with concrete commands.

Related Repositories in Software Engineering

View All in Software Engineeringโ†’