WooYun Legacy

A Claude Code plugin for business-logic vulnerabilities: testing methodology and references to real WooYun cases for authorized audit reports

Plugin

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Provides offensive business-logic testing methodology for payment and authorization systems
  • Ships real cases and attack patterns and is meant only for authorized testing
All reasons and checks

tanweai/wooyun-legacy

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add plugins/wooyun-legacy

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Run one by one in the Claude Code chat

/plugin marketplace add tanweai/wooyun-legacy
/plugin install wooyun-legacy@tanweai-security

Checked against the repository on Sep 24, 2026, commit d6a69e1.

Text for your agent

Install the plugin: /plugin marketplace add tanweai/wooyun-legacy, then /plugin install wooyun-legacy@tanweai-security. The plugin activates on its own for security tasks.

Other ways from the author
/plugin marketplace add tanweai/wooyun-legacy
/plugin install wooyun-legacy@tanweai-security

Lite install via the marketplace.

This is third-party code. Review the repository files before installing.

What it does

The plugin adds a knowledge base of business-logic vulnerabilities to Claude Code, distilled from WooYun public cases from 2010 to 2016. By the author's account it does not teach new attack techniques but backs the model's answers with references to real cases, frequency and severity statistics, and test prioritization. The material is split by area: amount tampering and payment flows, privilege escalation and bypass, IDOR and unauthorized access, password reset and weak credentials, logic flaws and race conditions, and code audit. It activates on explicit security requests and on implicit black-box scenarios. The author stresses the set is meant only for authorized testing, audit and education.

Who it is for. For security professionals and engineers running authorized testing, code audit and risk review.

Good fit when

  • You need methodology and priorities for an authorized business-logic test: payments, access control, password reset
  • You need to back a report with real case references and statistics
  • You need a code audit of an API for logic vulnerabilities together with the agent

Not a fit when

  • You have no written authorization to test the target
  • You need coverage of modern stacks: the data spans up to 2016

Example request

Draft an authorized test plan for this shop's payment logic and back it with real cases

Limitations

Licensed CC-BY-NC-SA-4.0, non-commercial use with attribution. The data spans 2010 to 2016, so modern stacks such as cloud services, GraphQL and Serverless are thinly covered. The set is intended only for authorized testing, and the legality of use is the user's responsibility. Source cases are mostly in Chinese, with an English README. The full case database is tens of megabytes and installs only in the full setup.

How to disable. Uninstall the plugin: claude plugin uninstall wooyun-legacy, then optionally remove the marketplace: claude plugin marketplace remove tanweai-security.

Security check

  • Provides offensive business-logic testing methodology for payment and authorization systems
  • Ships real cases and attack patterns and is meant only for authorized testing

README in short

The README describes a Claude Code plugin built on a large archive of WooYun public business-logic vulnerabilities. The plugin adds real company case references, quantitative statistics and test priorities to the model's answers, without claiming to teach new techniques. There are two install modes: a lite one via the marketplace and a full one via cloning the repository with the complete case database, examples and evaluation sets. Activation happens on explicit security keywords and on implicit black-box scenarios. A responsible-use section limits the tool to authorized testing and research.

FAQ

Does the plugin teach new attacks?

By the author's account, no. It adds real case references, statistics and priorities to methodology the model already knows, and is meant for authorized testing.

How current is the data?

The cases span 2010 to 2016. The author notes business-logic flaws are more stable than tech stacks, but modern stacks are thinly covered.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AIWooYun Legacy

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.