wooyun

Provides WooYun vulnerability case data and statistics for business logic security testing.

Updated Jul 20, 2026
One-click install
npx skills add https://github.com/lsongdev/skills --skill wooyun-lsongdev
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: wooyun
Source: https://github.com/lsongdev/skills/tree/main/wooyun
Command: npx skills add https://github.com/lsongdev/skills --skill wooyun-lsongdev

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Security testers often lack real-world evidence and quantitative backing when prioritizing business logic vulnerability tests or writing reports for clients. This Skill supplies 22,132 historical WooYun (2010-2016) vulnerability cases with statistics and priority ordering to ground testing decisions in real data. ## Core Features & Use Cases - Case-Backed Testing Guidance: References real company vulnerability cases across 6 domains and 33 categories including auth bypass, IDOR, payment tampering, and information disclosure. - Quantitative Statistics: Provides high-severity ratios (e.g., 88% for password reset flaws) and data-driven test priority ordering. - Layered Knowledge Base: Loads methodology matrices, technical manuals, and categorized case indexes on demand. - Use Case: When auditing a SaaS application for IDOR and privilege escalation, use this Skill to retrieve relevant real-world cases, common vulnerable parameters, and attack pattern distributions to plan and justify your test cases. ## Quick Start Ask the agent to use the wooyun skill to plan an IDOR and privilege escalation test for your SaaS application with real case references.

Frequently Asked Questions about wooyun

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I prioritize business logic vulnerability tests with real case data?▼

Use the WooYun case statistics to rank test targets by historical severity ratios, such as password reset flaws at 88% high-severity. The skill provides data-driven priority ordering across 33 vulnerability categories to focus testing effort.

What vulnerability categories does the WooYun dataset cover?▼

The dataset covers 6 domains and 33 categories: authentication bypass, IDOR and privilege escalation, financial security like payment tampering, information disclosure, logic flaws including race conditions, and misconfiguration.

Can I use WooYun cases for security reports to Chinese enterprises?▼

Yes, the cases come from real Chinese companies including government OA systems, telecom operators, and banks. They provide evidence-backed references that make security reports more persuasive for local clients.

Does this skill teach penetration testing techniques?▼

No, it does not replace pentest technique training. It augments existing security testing skills with real case references, quantitative statistics, and attack pattern distributions from historical data.

What are the limitations of the WooYun vulnerability data?▼

The data covers 2010-2016, so cloud-native, GraphQL, and Serverless scenarios have limited coverage. However, business logic attack patterns remain relatively stable over time, so the cases still hold reference value.