attack-patterns-reference
Use when classifying a verified web or WordPress behavior and selecting a related validation skill.
Install / Use
npx skills add uphiago/recon-skills --skill attack-patterns-referenceInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Tags
Our assessment of attack-patterns-reference
attack-patterns-reference scores 79/100 on our quality scale, 801st of 971 Security skills we index.
Its SKILL.md is 5.6 KB long, well organised into 10 sections and no code examples: a solid amount of guidance for an agent.
With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 29 days ago, so attack-patterns-reference is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
attack-patterns-reference compared with similar skills
All 4 of these similar skills score higher than attack-patterns-reference; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| attack-patterns-reference (this skill)by uphiago | 79 | 1.3k | 29d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 8d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 8d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 9d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 9d ago | SKILL.md |
Frequently asked questions
- How do I install attack-patterns-reference?
- Run
npx skills add uphiago/recon-skills --skill attack-patterns-reference. The install tabs above show the steps for each supported agent. - Which AI agents does attack-patterns-reference work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is attack-patterns-reference safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is attack-patterns-reference still maintained?
- The repository was last updated 29 days ago, so attack-patterns-reference is actively maintained.
Skill content
View source on GitHubname: attack-patterns-reference description: Use when classifying a verified web or WordPress behavior and selecting a related validation skill. version: 1.2.0 license: MIT platforms: [linux] compatibility: N/A (reference catalog) tags: [meta, reference, patterns, validation] category: meta related_skills:
- cors-credential-wordpress
- cross-attack-chains
- error-log-mining
- js-secrets-extraction
- phpinfo-to-rce
- port-service-discovery
- source-leak-hunt
- staging-subdomain-hunt
- wordpress-plugin-hunt
- wp-mass-recon
- xmlrpc-exploitation
Attack Patterns Reference
This catalog maps observed web and WordPress behavior to the skill that owns its validation. Pattern IDs are navigation labels. They do not establish exploitability, severity, prevalence, or a confirmed attack path.
When to Use
- A recon result needs to be classified before focused testing.
- Several verified behaviors may form a candidate attack path.
- A WordPress, CORS, XML-RPC, source-leak, or exposed-service signal needs an owning validation procedure.
Do not use the catalog as a scanner finding list or a substitute for the verification section of the owning skill.
Prerequisites
- An authorized target and current scope constraints.
- Captured evidence for the observation being classified.
- The tools and identities required by the selected follow-up skill.
How to Run
- Match the observed behavior to the closest pattern.
- Open the owning skill listed in the table.
- Check its prerequisites and side effects.
- Run the smallest validation and negative control that can falsify the hypothesis.
- Record the result as observed, inferred, confirmed, or not tested.
Procedure
General Web Patterns
| Pattern | Initial signal | Owning skill |
|---|---|---|
| WordPress user exposure | REST or author route returns user metadata | wp-mass-recon |
| Credentialed CORS | Untrusted origin reflected with credentials | cors-credential-wordpress |
| XML-RPC methods | Protocol-valid system.listMethods response | xmlrpc-exploitation |
| XML-RPC SSRF | pingback.ping reaches a controlled callback | xmlrpc-exploitation |
| Public registration | Registration is enabled | wp-mass-recon |
| Plugin surface | REST namespace, asset, or version marker | wordpress-plugin-hunt |
| Staging difference | Non-production host has weaker controls | staging-subdomain-hunt |
| Exposed error log | Response contains real application errors | error-log-mining |
| PHPInfo exposure | PHP configuration page is reachable | phpinfo-to-rce |
| Source or backup leak | Response contains repository, configuration, or database content | source-leak-hunt |
| JavaScript secret candidate | Bundle contains a credential-shaped value | js-secrets-extraction |
| Public service | Non-HTTP or administrative service is internet reachable | port-service-discovery |
See references/p-patterns.md for the extended
pattern notes.
CORS Variants
| Variant | Initial signal | Required validation |
|---|---|---|
| Origin reflection with credentials | Untrusted origin plus ACAC: true | Credentialed browser reads non-public data |
| Null-origin trust | ACAO: null plus ACAC: true | Sandboxed browser reads non-public data |
| Wildcard without credentials | ACAO: * | Determine whether the response is already public |
| Credentialed preflight | OPTIONS accepts origin, method, and headers | Actual request succeeds and browser exposes response |
| Auth-route CORS | CORS headers appear on a protected route | Approved session returns readable protected data |
| Plugin-specific CORS | Only one plugin namespace accepts the origin | Response contains protected data or performs an authorized test action |
| Environment-specific CORS | Staging and production policies differ | Demonstrate impact in the authorized environment |
| Third-party allowlist | One external service origin is trusted | Establish control of that origin and protected-data access |
Candidate Attack Paths
These are composition templates, not confirmed findings:
| Path | Preconditions that must be verified | |---|---| | CORS to protected-data read | Approved session, untrusted origin, browser-readable non-public response | | XML-RPC SSRF to cloud metadata | Controlled callback, reachable metadata service, usable secondary impact | | Open registration to upload | Approved synthetic account, upload-capable role, executable file path | | Exposed log to account access | Current credential material, approved identity, valid authentication control | | Staging exposure to production impact | Shared trust boundary, reusable secret or deployment path, explicit scope |
Use cross-attack-chains only after every prerequisite is independently
verified.
Pitfalls
- Historical frequency is not evidence about the current target.
- A product name, version, status code, or header does not prove impact.
- A catch-all route can make sensitive paths appear reachable.
- Public client identifiers and intentionally public APIs are not automatically credentials or authorization failures.
- Pattern prerequisites change across product and plugin versions.
- An attack path inherits the uncertainty of its weakest step.
Verification
- Match every pattern to captured request and response evidence.
- Run a negative control that distinguishes the result from public or generic behavior.
- Use a browser for CORS impact; headers alone are insufficient.
- Use a controlled callback for blind SSRF; a protocol status alone is insufficient.
- Use exact component and prerequisite checks before associating a CVE.
- Report only the impact reproduced within scope.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
