secknowledge

Consolidate web and AI security knowledge into structured references for threat modeling and testing workflows.

Updated Aug 27, 2026
One-click install
npx skills add https://github.com/0X6C7879/aegissec --skill secknowledge
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: secknowledge
Source: https://github.com/0X6C7879/aegissec/tree/main/skills/secknowledge
Command: npx skills add https://github.com/0X6C7879/aegissec --skill secknowledge

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

SecKnowledge consolidates WooYun's vulnerability catalog, GAARM risk matrix, and OWASP-aligned testing methodologies into a single, accessible knowledge base to accelerate comprehensive web and AI security testing and defense planning.

Core Features & Use Cases

  • Cross-domain threat coverage for Web apps, AI/LLMs, and hybrid deployments.
  • Centered references across references/ GAARM risk indices, testing methodology, and payload libraries for practical testing workflows.
  • Structured guidance for attack surface mapping, risk indexing, remediation suggestions, and cross-layer defense strategies.

Quick Start

Load the quick-reference card and open the references folder to perform a cross-domain security assessment.

Frequently Asked Questions about secknowledge

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map attack surfaces for AI and web applications?

Attack surface mapping for AI and web applications is supported by consolidated threat modeling methodologies and structured references for cross-layer environments. It provides practical workflows to discover threats across hybrid deployments.

What is the GAARM risk matrix for AI security?

The GAARM risk matrix is a structured framework for AI security risk indexing. It helps categorize and assess threats specific to LLM deployments, supporting cross-domain defense planning and remediation strategies.

How do I test for prompt injection vulnerabilities in LLMs?

Testing for prompt injection vulnerabilities involves applying cross-domain payload guidance and structured testing methodologies. The knowledge base provides practical workflows for discovering and validating these specific AI security threats.

Does this knowledge base include Wooyun vulnerability catalogs?

The Wooyun vulnerability catalog is consolidated within the knowledge base to accelerate web security testing. It provides real-world vulnerability references aligned with OWASP testing methodologies for attack surface analysis.

Can I use this for OWASP-aligned web security testing workflows?

OWASP-aligned testing methodologies are integrated to support web security testing workflows. The system provides structured guidance for risk indexing, payload deployment, and remediation planning across web applications.

What is the best way to plan cross-layer defense strategies?

Planning cross-layer defense strategies requires consolidating web and AI security knowledge into unified threat modeling. The system applies structured methodologies across hybrid deployments to support comprehensive remediation planning.