hack-skills: A Three-Layer Security Knowledge Base Built for AI Agents
Helping AI Agent become an awesome practical hacker!
At a glance
- What is it?
- A structured repository of 102 deep security skills across 14 domains, organized with a master entry and six category entries so AI agents can route into specific penetration testing and CTF playbooks on demand.
- Who is it for?
- hack-skills is useful for security engineers who deploy AI agents in authorized penetration testing, CTF competition work, or bug bounty research and want a structured, auditable knowledge base rather than a flat payload dump. The three-layer hierarchy makes it practical to start an agent at the master entry and drill down only when a specific technique is needed, which reduces context window consumption.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 17 days ago.
- What is it written in?
- Mainly CSS, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 28, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What the Repository Is For and Who It Targets
hack-skills is not a raw payload list. It is a distillation layer designed for AI agents that need to navigate security knowledge during an engagement. The distinction matters: an agent given a flat list of 50,000 payloads cannot efficiently decide what to do next, while an agent given a routable hierarchy of documented techniques can select, load, and apply skills as needed.
The project targets three audiences: security engineers running authorized penetration tests who want an agent assistant; CTF competitors who need quick access to technique references for web, binary, crypto, or reverse engineering challenges; and bug bounty researchers building automated recon and testing workflows.
The 14 security domains covered are: web security, API security, authentication and authorization, OS privilege escalation (Linux, Windows, macOS), Active Directory attacks, mobile security, binary exploitation (Pwn), reverse engineering, cryptography attacks, blockchain and smart contract security, AI/ML and LLM security, network protocols and pivoting, and digital forensics.
The README is clear about scope: all material is for bug bounty, penetration testing, CTF competitions, and authorized security research. It is not an exploit kit or a tool for unauthorized access.
Three-Layer Skill Hierarchy: Master, Category, and Deep Topic
The repository organizes skills at three levels, and the design principle is explicit: expose only what an agent loader needs to see at the top, and defer depth until it is needed.
The master entry is a single skill called hack, stored at skills/hack/SKILL.md. It provides global routing, an operating doctrine, a test sequencing framework, and instructions for switching between categories. An agent should load this first when facing a new target with an unknown attack surface.
The six category entries route by attack surface family. Examples include recon-for-sec, api-sec, and auth-sec. These compress what techniques exist in a domain into a stable index that an agent can scan without loading individual technique files.
The 102 deep topic skills each live in their own directory at skills/{semantic-identifier}/SKILL.md. They contain complete attack playbooks and execution details. The recommended pattern is to load a category entry first, then load deep topics on demand. Examples of deep topic skills include xss-cross-site-scripting and sqli-sql-injection.
The README notes that the current branch has converged on this standard directory structure, suggesting earlier versions had inconsistent layouts.
Installing and Loading the Master Entry
The preferred installation uses the npx skills command:
npx skills add yaklang/hack-skillsFor tooling that supports loading a single SKILL.md by URL, the master entry is available directly:
https://raw.githubusercontent.com/yaklang/hack-skills/main/skills/hack/SKILL.mdThe frontmatter name for the master entry is hack. Once installed, the recommended sequence is to start at the master entry, navigate to a category entry that matches the target's attack surface, and then load deep topic skills on demand as specific techniques are needed.
The repository is also published as a static web UI at skills.hackbenchmark.com. The site provides fuzzy search, a category sidebar, tier filtering (P0/P1/P2), and copy-paste install commands. It is a fully client-side build with no backend or tracking.
An encrypted ZIP of all skill markdown files is available for air-gapped environments where internet access is not possible during an engagement. The public password for the ZIP is hack-skills, as documented in the README. The ZIP uses AES-256 encryption.
How the Knowledge Was Distilled from Public Sources
The project names its source materials explicitly. The primary inputs are PayloadsAllTheThings (64 vulnerability categories), PentesterSpecialDict (OS-specific payload dictionaries and middleware fingerprinting data), Dictionary-Of-Pentesting (bug bounty bypass techniques and cloud metadata endpoints), Hello-CTF (PHP/Python/Java CTF web challenges), ctf-wiki (Pwn, Crypto, Reverse Engineering, Forensics), and hacktricks (a penetration testing encyclopedia covering privilege escalation, Active Directory, containers, mobile, and AI security).
The README states the distillation principles explicitly: no direct copying of large dictionaries or full payload lists; prioritize routable, composable, and auditable skills; use small stable samples, taxonomies, and cross-references. The goal is agent stability in real scenarios rather than exhaustive coverage.
The README also notes that public security research papers and CVE advisories were used as methodology sources for attack pattern matrices and decision trees.
The project is a distillation layer. It does not expose every minor payload as a separate entry and does not replicate upstream content wholesale. This design makes it easier to audit for accuracy and to update when techniques evolve.
Scope Boundaries and Cases Where It Falls Short
The repository is a static knowledge base, not a live tool. It does not execute code, scan targets, or interact with running systems. An AI agent that loads hack-skills still needs a separate tool layer for actual test execution: scanners, exploit frameworks, and traffic analysis tools must be configured and managed outside this repository.
The 102 deep topic skills cover a broad surface area, but depth varies by domain. Web security and Active Directory attacks are likely the most developed sections given their prominence in the source materials. Less common domains like civil digital forensics or specialized mobile security topics may have thinner coverage.
The project has no GitHub releases, and the last push was on 2026-09-13. The README does not specify a versioning scheme for individual skills, so there is no way to track when a specific technique file was last reviewed against current CVE data or tool syntax changes.
Skills are written in English and Chinese; the README has both language versions. For non-English-speaking teams, the main README content is accessible, but individual skill files may vary in language.
How hack-skills Differs from PayloadsAllTheThings
PayloadsAllTheThings is a well-known GitHub repository with 64 vulnerability categories containing raw payload lists, bypass techniques, and exploit chains. It is organized by vulnerability type and is primarily intended for human researchers who will manually select and adapt payloads during testing.
hack-skills takes a different approach: it distills the same source material into routable, semantically labeled skills designed for AI agent consumption. The master entry provides an operating doctrine, the category entries provide topic routing, and the deep topic skills provide structured playbooks rather than raw payload lists.
For a human researcher quickly looking up XXE payload variants, PayloadsAllTheThings is faster. For an AI agent that needs to navigate a full engagement workflow, select techniques based on discovered attack surface, and reason about test sequencing, hack-skills provides a structure that flat payload files do not.
License and Maintenance
The repository uses the MIT license, which permits reuse, modification, and commercial use without restriction.
The last push to the main branch was on 2026-09-13. The repository has no GitHub releases, meaning there is no formal versioning or release changelog. The README describes the current branch as having converged to a standard directory structure, but does not document a roadmap or contribution guide for adding new skills.
The website at skills.hackbenchmark.com is maintained alongside the repository. Changes to skill files are reflected in the website on each push to main, according to the deploy workflow.
Editorial conclusion
hack-skills is useful for security engineers who deploy AI agents in authorized penetration testing, CTF competition work, or bug bounty research and want a structured, auditable knowledge base rather than a flat payload dump. The three-layer hierarchy makes it practical to start an agent at the master entry and drill down only when a specific technique is needed, which reduces context window consumption. The MIT license permits reuse without restriction. Teams using this for automated scanning against systems they do not own are not the intended audience; the README explicitly scopes the project to authorized testing and educational research. The last push was on 2026-09-13.
Frequently asked questions
How do AI agents load and use hack-skills?
The recommended method is npx skills add yaklang/hack-skills. After installation, an agent should start at the master entry (skill name: hack), navigate to the relevant category entry for the target's attack surface, and load deep topic skills on demand as specific techniques are needed.
What security domains does hack-skills cover?
The repository covers 14 domains: web security, API security, authentication and authorization, OS privilege escalation for Linux/Windows/macOS, Active Directory attacks, mobile security, binary exploitation, reverse engineering, cryptography attacks, blockchain and smart contract security, AI/ML and LLM security, network protocols and pivoting, and digital forensics.
Can hack-skills be used offline without internet access?
Yes. An encrypted ZIP of all skill markdown files is available for air-gapped environments. The README documents the public password as hack-skills. The static website requires internet access, but the downloaded ZIP contains all content locally.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/yaklang-hack-skills)