wooyun-legacy

Analyze web application vulnerabilities using real-world case data.

Updated Mar 1, 2026
One-click install
npx skills add https://github.com/cpfcoaching/glowing-palm-tree --skill wooyun-legacy-cpfcoaching
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: wooyun-legacy
Source: https://github.com/cpfcoaching/glowing-palm-tree/tree/main/.agent/skills/wooyun-legacy
Command: npx skills add https://github.com/cpfcoaching/glowing-palm-tree --skill wooyun-legacy-cpfcoaching

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a methodology for web vulnerability testing, leveraging real-world data and patterns, helping users identify and mitigate potential security flaws.

Core Features & Use Cases

  • Real-world Patterns: Utilizes data from 88,636 real-world vulnerability cases.
  • Comprehensive Coverage: Covers a wide range of vulnerabilities like SQL Injection, XSS, command execution, and information disclosure.
  • Customization: Allows users to specify allowed tools and customize testing criteria.
  • Use Case: Ideal for penetration testing, security audits, and vulnerability research in web applications.

Quick Start

Use the wooyun-legacy skill to identify SQL Injection vulnerabilities in the target web application.

Frequently Asked Questions about wooyun-legacy

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I identify SQL Injection vulnerabilities during web security testing?

To identify SQL Injection vulnerabilities during web security testing, analyze input validation and data flow using a methodology derived from real-world cases. This approach detects security flaws by evaluating how user inputs interact with backend queries.

What is the best way to find XSS and command execution flaws in web applications?

The best way to find XSS and command execution flaws is to apply a vulnerability testing methodology based on 88,636 real-world cases. This process examines output encoding and data flow to accurately pinpoint potential security weaknesses.

Can I customize testing criteria for penetration testing and security audits?

Yes, you can customize testing criteria for penetration testing and security audits by specifying allowed tools. This flexibility ensures the vulnerability testing methodology adapts to your specific web application security requirements.

How does analyzing input validation and output encoding help with vulnerability research?

Analyzing input validation and output encoding helps vulnerability research by mapping data flow to uncover security flaws. This methodology leverages real-world patterns to identify vulnerabilities like SQL Injection and cross-site scripting.

Does this web vulnerability testing methodology cover information disclosure?

Yes, this web vulnerability testing methodology covers information disclosure along with SQL Injection, XSS, and command execution. It utilizes comprehensive real-world case data to identify a wide range of web application security flaws.