AboutSecurity
Structured penetration testing knowledge base with 200+ AI-executable attack methodologies
All Skills in This Repository (117)
Pure Emerald Level Indicatorspost-exploit-linux
Plan and execute Linux post-exploitation workflows from initial access through privilege escalation.
graphql-methodology
Identify GraphQL endpoints and test introspection, injection, and authorization bypass.
java-deserialization-methodology
Identify Java deserialization weaknesses by analyzing serialized payload markers and middleware exposure.
idor-methodology
Identifies and assesses XSS vulnerabilities in web applications and prescribes remediation steps.
nosql-injection
Identify NoSQL injection vulnerabilities in JSON-based application inputs.
business-logic-attack
Detect business logic vulnerabilities in e-commerce transactional flows.
information-disclosure-methodology
Detect and exploit web application information disclosure leaks to acquire credentials.
oauth-sso-attack
Test OAuth 2.0 and OpenID Connect flows for redirect_uri, state, and token weaknesses.
api-fuzz
Automate API security testing with endpoint discovery and semantic fuzzing.
jwt-attack-methodology
Decode JWT tokens and execute attacks like none-alg and weak-key brute force.
crypto-web-attack
Identify and analyze cryptographic weaknesses in web applications.
subdomain-takeover
Detect and validate subdomain takeover risks via CNAME, NS, and MX DNS signals.
Frequently Asked Questions
FAQPage SchemaHow to install AboutSecurity?โผ
Run `npx skills add wgpsec/AboutSecurity --all -g -y` in your terminal to install all security skills globally for your AI agent.
What is AboutSecurity used for?โผ
It is a structured penetration testing knowledge base with 200+ AI-executable skills covering web exploits, network services, cloud attacks, post-exploitation, and digital forensics.
Can AI agents use AboutSecurity for automated pentesting?โผ
Yes. Each skill contains decision trees, behavioral rules, and payload references designed for AI agents to execute full attack chains autonomously in Claude Code, Cursor, and similar tools.
Does AboutSecurity include vulnerability PoC data?โผ
Yes. The Vuln directory contains 600+ structured vulnerability entries with affected versions and exploitation steps for middleware, web applications, and cloud platforms.
Do I need security experience to use AboutSecurity?โผ
Basic security knowledge helps, but the skills are written as step-by-step methodologies that guide you or your AI agent through each attack phase with concrete commands.
Related Repositories in Software Engineering
View All in Software Engineeringโopenclaw
Run a personal AI assistant across your devices and chat apps
superpowers
Gives coding agents a disciplined workflow from idea to merged code
react
AI agent skills for building, testing, and porting React core