wgpsec/AboutSecurity

Everything for pentest. | A penetration testing knowledge base that captures security methodologies in an AI Agent-executable format.

This repository also configures its own agents. See what AboutSecurity tells them →

1.7kStars on the repository
200Mods indexed here, across every type
7d agoLast push, which is what freshness is scored on
noneNo LICENSE: all rights reserved, so bodies are not copied

wgpsec/AboutSecurity

Skill Claude CodeCodex

A method for adding techniques that help an existing Loader avoid security detection, such as API obfuscation, string encryption, system calls, anti-debugging, and AMSI bypasses.

not rated 1.7k +7 7d ago A SkillSpector: pass 97 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A generator for combining storage, memory-allocation, copying, and execution components into C, C++, or Rust Shellcode Loaders. Shellcode is machine code designed to run inside another program or process.

not rated 1.7k +7 7d ago A SkillSpector: pass 81 tokens

sliver-c2

75

wgpsec/AboutSecurity

Skill Claude CodeCodex

An operating guide for Sliver, a command-and-control framework used to manage implants during red-team exercises and penetration tests. It covers several network protocols, two implant operating modes, proxies, and traffic tunnelling.

not rated 1.7k +7 7d ago D 86 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A method for testing the security of machine-learning infrastructure such as Jupyter, MLflow, Ray, Kubeflow, Gradio, Streamlit, and model-serving systems. These are tools for running notebooks, tracking models, managing ML workloads, or serving AI models.

not rated 1.7k +7 7d ago D 173 tokens

crypto-web-attack

77

wgpsec/AboutSecurity

Skill Claude CodeCodex

A method for testing weaknesses in cryptography used by web applications, including padding-oracle flaws, weak randomness, predictable tokens, and hash length-extension opportunities. It also covers attacks against CBC and ECB block-based encryption.

not rated 1.7k +7 7d ago A SkillSpector: pass 102 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to advanced HTTP request smuggling, a security flaw where different servers interpret one web request as two. It covers confirmed CL.TE, TE.CL, TE.TE, and HTTP/2 downgrade cases, along with ways they can be chained into attacks.

not rated 1.7k +7 7d ago A SkillSpector: warn 87 tokens

ot-ics-attack

79

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to assessing operational technology and industrial control systems such as SCADA, DCS, and PLC environments. These systems monitor and control physical processes and often use specialized network protocols.

not rated 1.7k +7 7d ago A SkillSpector: warn 81 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to testing race-condition vulnerabilities, where two or more requests arrive at nearly the same time and bypass checks that should happen in order.

not rated 1.7k +7 7d ago A SkillSpector: pass 70 tokens

supply-chain-attack

81

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to assessing attacks against the software supply chain: the packages, private repositories, build servers, and CI/CD pipelines used to create and deliver software.

not rated 1.7k +7 7d ago C 62 tokens

supply-chain-audit

82

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to auditing software dependencies, frameworks, package repositories, and CI/CD systems for supply-chain security problems. A CVE is a public identifier for a known software vulnerability.

not rated 1.7k +7 7d ago A SkillSpector: warn 132 tokens

401-403-bypass

83

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to testing web applications and APIs that reject requests with 401 or 403 responses. These codes usually mean authentication is required or access is forbidden.

not rated 1.7k +7 7d ago A SkillSpector: pass 122 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to identifying and testing image- and click-based CAPTCHA protections, which are checks intended to distinguish people from automated programs.

not rated 1.7k +7 7d ago A SkillSpector: pass 100 tokens

cookie-analysis

85

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to analyzing and forging session cookies used to identify logged-in users. It covers unsigned, signed, encrypted, and binary cookie formats and directs JWT cases to a separate method.

not rated 1.7k +7 7d ago A SkillSpector: pass 123 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to testing incorrect CORS settings. CORS, or Cross-Origin Resource Sharing, controls which websites a browser may contact on behalf of another website.

not rated 1.7k +7 7d ago A SkillSpector: pass 59 tokens

csrf-methodology

87

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to testing for cross-site request forgery, or CSRF, where a website is tricked into accepting a sensitive action from a user's logged-in browser.

not rated 1.7k +7 7d ago A SkillSpector: pass 62 tokens

idor-methodology

88

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to finding insecure direct object references (IDOR), where changing an identifier can expose another user's data or actions.

not rated 1.7k +7 7d ago A SkillSpector: warn 183 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to testing JSON Web Tokens (JWTs), the signed strings often used to keep users logged in to websites and APIs.

not rated 1.7k +7 7d ago A SkillSpector: warn 138 tokens

mobile-backend

90

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to security testing for the APIs used by mobile apps to communicate with their servers.

not rated 1.7k +7 7d ago A SkillSpector: pass 72 tokens

oauth-sso-attack

91

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to testing OAuth, single sign-on, and OpenID Connect login flows, which let users sign in through services such as Google or GitHub.

not rated 1.7k +7 7d ago A SkillSpector: pass 83 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to finding and exploiting weaknesses in compiled programs, such as memory corruption bugs.

not rated 1.7k +7 7d ago A SkillSpector: warn 125 tokens

dns-pentesting

95

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to assessing DNS, the system that maps domain names to network addresses.

not rated 1.7k +7 7d ago A SkillSpector: warn 111 tokens

wgpsec/AboutSecurity

Skill Claude CodeCodex

A guide to assessing Elasticsearch, a search and data-storage service, when it is exposed without proper access controls.

not rated 1.7k +7 7d ago A SkillSpector: warn 110 tokens

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: