Report · marked 26 Aug 2026
danielmiessler/SecLists
An agent is close to flying blind in this repository.
PHP · 73,079 stars · 6,272 files · branch master
Higher is better. Accent marks what is costing you most.
Fix these first
The full marking
Every deduction below names the file or setting it came from.
Instructions 3/27 F
Whether the repo tells an agent how to behave before it starts guessing.
Setup 0/14 F
Whether an agent can install the project and get it running without a human.
Verification loop 8/25 D
Whether an agent can check its own work. This is the category that most decides whether agent output is trustworthy.
Context economy 15/20 B+
Whether the repo fits in a context window, or fights it.
Here is your AGENTS.md
Drafted from what is actually in this repository: the install
command from your lockfile, the commands you already declare, your real directory layout. Anything
marked TODO needs a person. Save it at the root as AGENTS.md.
# AGENTS.md SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more. ## Setup ``` # TODO: the install command. No lockfile was found, so this could not be inferred. ``` ## Commands ``` # TODO: nothing declares a build or test command, so an agent has to guess. # This is the single most valuable section of this file. Fill it in. ``` ## Layout - `Web-Shells/` 37 source files - `Miscellaneous/` 5 source files - `Discovery/` 2 source files - `Payloads/` 2 source files - `Fuzzing/` 1 source file ## Conventions - Tests live alongside the code they cover, following `Fuzzing/extension-test.txt`. - CI defines what passing means. See `.github/workflows/readme-updater.yml`, and keep it green. - TODO: add the two or three conventions a newcomer always gets wrong here. ## Gotchas - No lockfile is committed, so an install here may not match what CI produced. --- Drafted by agentreadme.com from what is in this repository. Everything marked TODO needs a human. Check it in as AGENTS.md at the root.
Open the raw markdown
or
curl -o AGENTS.md agentreadme.com/draft/danielmiessler/SecLists.md
Show the mark
The badge re-checks daily, so it keeps up as the repository changes. Use mark again to force it now.
[](https://agentreadme.com/danielmiessler/SecLists)Other PHP repositories, marked
Think this mark is wrong?
Every deduction above names the file it came from, so this can be settled by looking. If a check missed something, that is a rule worth fixing.