wgpsec

60 mods across 3 repositories, 2.4k stars between them.

wgpsec/AboutSecurity

Skill Claude CodeCodex

Use this skill whenever the user asks to add, absorb, migrate, port, update, merge, compare, or extract security knowledge into the AboutSecurity repository from any external resource such as InternalAllTheThings, blog posts, tools, docs, PRs, screenshots, notes, or URLs. This skill SOPs the full workflow: first…

1.7k 1mo ago A 0 tokens

agent-security

02

wgpsec/AboutSecurity

Skill Claude CodeCodex

A methodology for testing the security of AI-agent systems that call tools, work with other agents, or make decisions autonomously. It covers ten risks from the OWASP Agentic AI Security Top 10, including prompt hijacking, excessive tool use, permission problems, and unsafe code execution.

1.7k 1mo ago A 95 tokens

ai-data-security

03

wgpsec/AboutSecurity

Skill Claude CodeCodex

A security-testing method for AI systems that examines data leaks, training-data exposure, and the integrity of retrieval-augmented generation (RAG) or vector databases. A vector database stores data in a form AI systems use to find related information.

1.7k 1mo ago A 109 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A methodology for testing identity and permission security in AI systems, including agent authentication, roles, sessions, and MCP or API credentials. It covers attacks such as role escape, unauthorized actions, identity forgery, session hijacking, and credential misuse.

1.7k 1mo ago A 113 tokens

cot-injection

05

wgpsec/AboutSecurity

Skill Claude CodeCodex

A security-testing method for attacks on an AI agent's intermediate reasoning in multi-step systems. Chain-of-Thought (CoT) means the reasoning steps an AI uses to reach an answer, while ReAct combines reasoning with actions.

1.7k 1mo ago A 118 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A security-testing method for systems that combine traditional websites with AI or large language model components. It maps attacks that move from the website into the AI system, and from the AI system back into the website.

1.7k 1mo ago A 138 tokens

mcp-security

07

wgpsec/AboutSecurity

Skill Claude CodeCodex

A security-testing method for MCP, or Model Context Protocol, integrations that let AI agents call external tools. It examines tool descriptions, schemas, instructions, tokens, and interactions between multiple MCP servers.

1.7k 1mo ago A 115 tokens

prompt-injection

08

wgpsec/AboutSecurity

Skill Claude CodeCodex

A security-testing method for indirect prompt injection, where instructions hidden in webpages, documents, emails, databases, or API responses influence an AI system. It also covers attacks on connected tools, retrieved data, and information handling.

1.7k 1mo ago A 78 tokens

prompt-jailbreak

09

wgpsec/AboutSecurity

Skill Claude CodeCodex

A security-testing method for breaking or bypassing the instructions that control AI chatbots and agents. It covers techniques such as role-playing, code and language changes, context-window pressure, and attempts to replace system instructions.

1.7k 1mo ago C 73 tokens

prompt-leak

10

wgpsec/AboutSecurity

Skill Claude CodeCodex

A security-testing skill for finding system instructions, settings, tools, and stored information inside applications built with large language models.

1.7k 1mo ago A 63 tokens

aliyun-pentesting

11

wgpsec/AboutSecurity

Skill Claude CodeCodex

A methodology for security testing of systems hosted on Alibaba Cloud. Alibaba Cloud services include platforms for servers, storage, databases, containers, and access control.

1.7k 1mo ago E 141 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A method for analysing AWS access policies, including IAM policies, resource policies, Lambda code, and CloudFormation templates. AWS is Amazon’s cloud platform; IAM controls who can access its resources.

1.7k 1mo ago C 101 tokens

aws-iam-privesc

13

wgpsec/AboutSecurity

Skill Claude CodeCodex

A methodology for finding privilege-escalation paths in AWS Identity and Access Management (IAM), the system that controls access to AWS resources.

1.7k 1mo ago F 104 tokens

aws-pentesting

14

wgpsec/AboutSecurity

Skill Claude CodeCodex

A general method guide for security testing of Amazon Web Services, a cloud platform that hosts storage, servers, functions, databases, and other services.

1.7k 1mo ago C 116 tokens

aws-post-exploit

15

wgpsec/AboutSecurity

Skill Claude CodeCodex

An AWS post-compromise security skill for situations where someone already has high-level access to Amazon Web Services accounts or specific services.

1.7k 1mo ago C 110 tokens

azure-ad-attack

16

wgpsec/AboutSecurity

Skill Claude CodeCodex

A methodology for attacking Microsoft Azure AD, now called Microsoft Entra ID, and related Microsoft 365 cloud identity systems. It covers ways attackers may obtain access, steal tokens, abuse application identities, and bypass some access controls.

1.7k 1mo ago A 76 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A methodology for moving from a compromised Azure or Entra ID cloud account into an on-premises Active Directory network. Active Directory is commonly used to manage users and computers inside an organization.

1.7k 1mo ago A 160 tokens

azure-pentesting

18

wgpsec/AboutSecurity

Skill Claude CodeCodex

A methodology for assessing the security of Microsoft Azure and Microsoft 365 cloud environments, including Entra ID, Microsoft's identity service.

1.7k 1mo ago C 113 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A security-testing methodology for CI/CD pipelines—the automated systems that build, test, and deploy software—and their connected code repositories and cloud environments.

1.7k 1mo ago E 146 tokens

cloud-aksk-exploit

20

wgpsec/AboutSecurity

Skill Claude CodeCodex

A playbook for using leaked cloud access keys and secret keys after they have been found in places such as environment files, Git history, or server-side request forgery (SSRF).

1.7k 1mo ago A 173 tokens

cloud-iam-audit

21

wgpsec/AboutSecurity

Skill Claude CodeCodex

A playbook for auditing cloud IAM, the system that controls which identities can perform which actions. It covers AWS, Azure, GCP, and Tencent Cloud.

1.7k 1mo ago A 128 tokens

cloud-metadata

22

wgpsec/AboutSecurity

Skill Claude CodeCodex

A playbook for using cloud instance metadata, a local service that can reveal information and temporary credentials about a running cloud machine.

1.7k 1mo ago C 113 tokens

docker-pentesting

23

wgpsec/AboutSecurity

Skill Claude CodeCodex

A playbook for testing Docker, a platform that runs applications in isolated containers. It covers the Docker daemon, registries, images, build outputs, and container escape risks.

1.7k 1mo ago C 142 tokens

gcp-exploit

24

wgpsec/AboutSecurity

Skill Claude CodeCodex

A playbook for attacking Google Cloud Platform (GCP) environments, including service accounts, instance metadata, storage buckets, and Kubernetes Engine (GKE).

1.7k 1mo ago C 60 tokens