Skip to content
Back to skills

Cwe

ASecurity

Exhaustively test a target against every applicable CWE.

  • 86 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 10, 2026
securitygoshellsqltestingapi

Works with

  • terminal
  • api

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 10, 2026

npx -y skills add 0dayInc/pwn --skill cwe --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cwe?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cwe
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/0dayinc-cwe/badge)](https://www.skillsdirectory.com/skills/0dayinc-cwe)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cwe
description: Exhaustively test a target against every applicable CWE.
license: MIT
allowed-tools: [pwn, terminal, extrospection]
metadata:
  bundled: true
  references:
    - https://cwe.mitre.org/
    - https://cwe.mitre.org/data/downloads.html
    - CWE List 4.20
---

# CWE exhaustive testing

Use when the ask names a CWE, OWASP/WSTG mapping to CWE, a CVE that
maps to CWE, SAST output with CWE IDs, or "test this app/binary/firmware
against CWE". Pair with `sast-code-scans` when source exists and
`web-application-penetration-testing` when the surface is HTTP.

## When to use

- "CWE-79", "test for SQLi", "map findings to CWE"
- CVE analysis that must name the underlying weakness
- Coverage pass: every CWE that applies to this stack

## Methodologies

| Catalog | Role |
|---|---|
| CWE List 4.20 | weakness IDs, views, categories — source of each reference |
| OWASP WSTG / ASVS | web mapping onto CWE IDs |
| NIST SP 800-115 | technical assessment techniques wrapping these tests |
| ATT&CK / CAPEC | attacker technique; still report the CWE |

## How to look up a CWE

Each CWE number is a file in this skill:

```text
references/CWE-<id>.md
```

Examples: `references/CWE-79.md`, `references/CWE-89.md`,
`references/CWE-787.md`. Open that file and follow its procedure
end-to-end. Do not improvise a one-line "XSS test" when the reference
exists. `references/INDEX.md` lists every ID.

## Exhaustive catalog procedure

1. Identify the target class (web, API, native, firmware, cloud, human).
2. Pick a CWE view (CWE-1000 Research Concepts, CWE-699 Software Development,
   CWE-1194 Hardware Design, CWE-1326 CWE Top 25, etc.) from `references/`.
3. For every **applicable** member, run `references/CWE-<id>.md`.
4. Record N/A with a reason when the platform does not exist.
5. Findings cite the member CWE, not only the view/category.
6. Re-read saved evidence before calling the CWE tested.

## Tooling

- Always: `skills_recall` this skill, then read the CWE reference file.
- HTTP: `PWN::Plugins::BurpSuite` or `TransparentBrowser`.
- Source: `PWN::SAST::Factory.start` / `pwn_sast`.
- Authz: `PWN::Bounty::LifecycleAuthzReplay`.
- Native: `PWN::Plugins::Assembly`, gdb via shell.
- Hardware: `PWN::Plugins::Serial`, BusPirate.

## Pitfalls

- Scanner output is inventory, not a test.
- Categories and views are groupings; they are not vulnerabilities.
- One payload on one parameter is not exhaustive for a Base CWE.
- Do not skip deprecated IDs without following the replacement.

## Verification

A CWE is done when its reference checklist is ticked and evidence
paths were re-read. The engagement is CWE-complete when every
applicable ID in the chosen view is tested or N/A.

## Catalog size (CWE 4.20)

- Weaknesses: 969
- Categories: 422
- Views: 59

Full table: `references/INDEX.md`.

Files in this skill

  • SKILL.md2.8 KB
  • references/CWE-1.md1.2 KB
  • references/CWE-10.md1.1 KB
  • references/CWE-100.md1.2 KB
  • references/CWE-1000.md1.6 KB
  • references/CWE-1001.md1.4 KB
  • references/CWE-1002.md1.4 KB
  • references/CWE-1003.md1.8 KB
  • references/CWE-1004.md4.2 KB
  • references/CWE-1005.md1.5 KB
  • references/CWE-1006.md1.7 KB
  • references/CWE-1007.md5.6 KB
  • references/CWE-1008.md1.5 KB
  • references/CWE-1009.md1.5 KB
  • references/CWE-101.md1.2 KB
  • references/CWE-1010.md1.6 KB
  • references/CWE-1011.md1.7 KB
  • references/CWE-1012.md1.6 KB
  • references/CWE-1013.md1.6 KB
  • references/CWE-1014.md1.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…