# wgpsec/AboutSecurity: A Pentest Knowledge Base Shipped as Agent Skills

> AboutSecurity stores pentest methodology as SKILL.md files that Claude Code can load, plus dictionaries, payloads and 600+ vulnerability entries. It is a content repository, not a scanner, and the sync script is what makes it usable.

**wgpsec/AboutSecurity** — Everything for pentest. | 渗透测试知识库，以 AI Agent 可执行的格式沉淀安全方法论。

- Repository: https://github.com/wgpsec/AboutSecurity
- Stars: 1,770 · Forks: 244
- Language: Python
- License: not declared
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/wgpsec-aboutsecurity

## What AboutSecurity actually is, and who it is for

AboutSecurity is a knowledge base, not an executable. The README describes it as a penetration testing knowledge base that stores security methodologies in a format an AI Agent can execute, and the repository is organised into four content trees: skills/, Dic/, Payload/ and Vuln/. Nothing in the top-level layout suggests a scanner, a server-side component or a CLI beyond the scripts/ directory.

The audience is narrow and specific. You need an agent that consumes SKILL.md files (the README names Claude Code and describes the flat .claude/skills/<name>/SKILL.md layout it expects), and you need to be doing offensive work where a written methodology is the bottleneck rather than tooling. A consultant who already knows how to attack a Kubernetes cluster gains little; someone who needs the agent to recall the right sequence for a JWT confusion attack, or which dictionary to point at an SSH service, gains a lot. The skills/ tree covers recon, exploitation, lateral movement, post-exploitation, DFIR, malware analysis, mobile, hardware and CTF, so the intended user is closer to a generalist pentester or a red team member than to a narrow specialist.

## How the nested skills tree becomes agent-readable

The mechanism is a symlink flattening step. Skills live in nested categories such as skills/exploit/web-method/sql-injection/SKILL.md, but Claude Code only discovers skills in the flat structure .claude/skills/<name>/SKILL.md. The README states that the sync script creates symlinks for the nested-to-flat mapping, and that after syncing the agent automatically matches and loads relevant skills from conversation context with no manual specification.

That design has a consequence worth naming. The symlinks are the only binding between the repository and the agent, so the skills are never copied into the target project and never become stale copies. Adding or removing a skill directory changes what the agent sees only after you re-run the script, which the README explicitly tells you to do. The classification is also deliberate rather than decorative: the README draws a line between postexploit/ as the post-exploitation layer (what to do after access) and Vuln/ as the vulnerability data layer (affected versions, PoC code, exploitation steps per CVE), summarised as skills telling you what to do after you are in and Vuln telling you how to get in. If you are choosing where to look for something, that distinction is the fastest routing rule in the document.

## Installing it and syncing skills into a project

There is no package to install. You clone the repository and run the sync script against a target project. The README gives this as the first two steps:

```bash
# Clone the Repository
git clone https://github.com/wgpsec/AboutSecurity.git

# Sync Skills to Your Project
cd AboutSecurity
./scripts/sync-claude-skills.sh --target /path/to/your-project
```

The stated result is that .claude/skills/<skill-name>/ symlinks appear in the target project and Claude Code discovers and invokes them automatically. Omitting --target syncs into the AboutSecurity repo itself, which is what you want if you are driving an agent from inside the repository. Re-run the script after adding or removing skills, because the symlinks are not generated on the fly.

Dictionaries and payloads take a different route and are not synced at all. The README says to reference their paths in the conversation and let the agent read them through its Read and Glob tools:

```text
"Use the dictionaries under /path/to/AboutSecurity/Dic/auth/ to brute-force SSH"
"Load the payload list from /path/to/AboutSecurity/Payload/xss/ for fuzz testing"
```

There is also an MCP path. The README recommends deploying context1337, a separate repository, which turns AboutSecurity from a file tree into a queryable resource service:

```bash
git clone https://github.com/wgpsec/context1337.git
cd context1337
make run   # clone data + build index + start server
```

After that the README registers the service with Claude Code over HTTP on port 1337:

```bash
claude mcp add aboutsecurity --transport http http://localhost:1337/mcp
```

With that in place, natural-language queries such as searching for SQL injection resources or listing XSS payloads are answered from the index rather than by walking the filesystem.

## The content trees: skills, dictionaries, payloads, vulnerabilities

The skills/ tree is the largest surface. The README claims 200+ skill methodologies spanning recon to post-exploitation, with named subcategories including ai-security (prompt injection, model jailbreaking, prompt leaking, agent attack chains), cloud (Docker escape, Kubernetes attack chains, AWS IAM, Alibaba Cloud, Tencent Cloud, Serverless), code-audit (a PHP 8-skill system and a Java 8-skill system covering injection, file, serialization, auth, framework and exploit chains), lateral movement (AD domain attacks, NTLM relay, Kerberoasting, ACL abuse), and tool-delivery, which covers pushing tools such as fscan, frp, chisel, linpeas and mimikatz to compromised hosts across wget, curl, certutil, bitsadmin, PowerShell, python, nc, base64 and SMB, including no-egress scenarios and post-execution cleanup.

The other three trees are data rather than method. Dic/ holds usernames and passwords, device default credentials for government and enterprise appliances, DNS servers, excluded IP ranges, 19 types of service-specific brute-force dictionaries, and web dictionaries for directories, API parameters, middleware, upload bypass and webshells. Payload/ splits into sqli, xss, ssrf, xxe, lfi, rce, upload, cors, hpp, format, ssi, email, access-bypass and prompt-injection. Vuln/ is described as 600+ entries organised by product, with 394 middleware entries named and separate ai, cloud, network and web directories. Both Dic/ and Payload/ use lowercase hyphen-separated directory names and each directory carries a _meta.yaml file, which is the metadata contract an agent or script relies on when it enumerates them.

## Where AboutSecurity is the wrong tool

The most immediate limitation is that the repository does not tell you its licence. The licence field is unknown and the README does not state one. For a collection that includes payloads, PoCs and default-credential dictionaries, that is the single largest adoption risk, and it is a documentation gap rather than a legal conclusion you can draw from the repository listing alone.

The second limitation is the release history. The most recent release is v2 (f8x工具迁移) from 2021-01-21, and the two before it are v1.0.2 and v1.0.1 from January 2021. The README presents the skills tree as the current interface, so the tagged releases do not describe what the project is now; anyone treating a release tag as a stable snapshot will get something much smaller than the master branch.

Third, AboutSecurity is the wrong choice if your problem is discovery rather than recall. It contains no scanner and no exploitation engine, so it cannot find a vulnerable service for you. It also assumes an agent runtime: without Claude Code or an equivalent consumer of SKILL.md, the skills tree is a set of Markdown files you read manually, and the sync script has nothing to sync into. Finally, the README does not document rollback for the sync operation. If the symlinks land in the wrong project, the documented path forward is to re-run the script, not to undo it.

## How it differs from a scanner-and-exploit toolkit

The natural comparison is Metasploit, and the difference is in what each one stores. Metasploit ships modules: each module is code that performs an action against a target, and the framework's value is execution, session management and payload delivery. AboutSecurity ships prose. A SKILL.md file describes a methodology the agent should follow, and the agent supplies the execution by writing commands, calling tools or reading the dictionaries and payloads sitting next to it. That is why the two sit at different layers: you would point an agent using AboutSecurity at a host that Metasploit can also hit, but AboutSecurity contributes the sequence and the judgement, not the exploit code.

The second difference is extensibility. Adding a Metasploit module means writing Ruby against the framework's API. Adding an AboutSecurity skill means adding a directory with a SKILL.md and re-running the sync script, which the README frames as the whole workflow. The cost of that lower barrier is consistency: nothing in the README describes a schema, a validation step or a review gate for a new SKILL.md beyond the _meta.yaml convention used in Dic/ and Payload/. A large tree of individually authored methodology files will vary in depth, and the repository gives you no built-in way to measure that.

## Maintenance, upgrade cost and licence status

The repository is not archived, and the last push was on 2026-08-30, so the content tree is being touched recently even though the tagged releases stopped in 2021. Treat the two signals separately: the master branch is where current work lives, and the release list is a historical artefact of the earlier f8x tooling.

Upgrade cost is low by design. Because the sync step creates symlinks rather than copies, pulling new commits and re-running ./scripts/sync-claude-skills.sh --target /path/to/your-project is the whole update path, and the README already requires a re-run whenever skills are added or removed. The one thing to watch is that symlinks make the target project depend on the AboutSecurity checkout staying at the same path; move or delete the clone and the agent's skill directory points at nothing. Dictionaries and payloads have no update step at all, since they are read in place.

On licensing: the repository metadata does not identify a licence, and the README does not discuss one. The content mixes original methodology with PoC code and default-credential lists, and those categories often carry different provenance. Anyone planning to redistribute the tree, or to embed it in a commercial engagement deliverable, should establish the licence and the origin of the Vuln/ PoC entries from the repository itself before doing so. That is a question for the maintainers, not something this article can settle.

## Conclusion

Adopt AboutSecurity if you already run Claude Code or another agent that reads SKILL.md files and you want reconnaissance, exploitation and post-exploitation methodology in the same tree as your dictionaries and payloads. Do not adopt it if you want a tool that scans something on its own: there is no scanner here, and the README documents no licence, so verify the licence file and the sync-claude-skills.sh behaviour on a throwaway project before pointing it at client work.

## FAQ

### Does AboutSecurity include a scanner or exploitation tool?

No. The README describes it as a penetration testing knowledge base, and the repository layout is content trees (skills/, Dic/, Payload/, Vuln/) plus a scripts/ directory. The skills tell an agent what to do; the agent supplies the execution.

### How do I install AboutSecurity?

You clone the repository with git clone https://github.com/wgpsec/AboutSecurity.git and then run ./scripts/sync-claude-skills.sh --target /path/to/your-project to create .claude/skills/<skill-name>/ symlinks in the target project. Dictionaries and payloads need no syncing and are read directly by the agent.

### What is the difference between the postexploit/ skills and the Vuln/ directory in AboutSecurity?

The README states that postexploit/ is the post-exploitation layer covering privilege escalation, persistence, credential extraction and product-specific tactics, while Vuln/ is the vulnerability data layer holding affected versions, PoC code and exploitation steps per CVE. In the README's phrasing, skills tell you what to do after you are in and Vuln tells you how to get in.

### Does AboutSecurity work with tools other than Claude Code?

The README only documents the Claude Code skill layout (.claude/skills/<name>/SKILL.md) and an MCP route through the separate context1337 service. It does not describe support for other agent runtimes.

## Sources

- [Issues](https://github.com/wgpsec/AboutSecurity/issues)
- [README](https://github.com/wgpsec/AboutSecurity/blob/master/README.md)
- [Releases](https://github.com/wgpsec/AboutSecurity/releases)
- [wgpsec/AboutSecurity on GitHub](https://github.com/wgpsec/AboutSecurity)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/wgpsec-aboutsecurity
