wooyun-legacy
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of Markdown files providing methodology and checklists for penetration testing. It does not contain any executable scripts (Python, JavaScript, shell, etc.) or binary files.
- [COMMAND_EXECUTION]: The documentation contains examples of command injection payloads and reverse shell strings (e.g., in
references/unauthorized-access.md). These are identified as educational content for security testing purposes and are not executed by the skill itself. - [SAFE]: The contents are derived from the WooYun vulnerability database and are intended for authorized security audits and education. No malicious behaviors such as data exfiltration, credential theft, or unauthorized network access were detected.
Audit Metadata