CLAUDE CODE MARKETPLACES
SkillsMarketplacesMCPDigestLearnAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Web & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web CrawlingAutomation & Workflows
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Learn
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by @mertduzgun

Independent project, not affiliated with Anthropic
  1. Skills
  2. /
  3. yaklang
  4. /
  5. hack-skills
  6. /
  7. Csp Bypass Advanced

Csp Bypass Advanced

Editor's Note

When you hit an XSS vector but CSP is blocking execution, this walks you through the actual bypass techniques that work. It covers the directive hierarchy (and the critical ones like base-uri that don't fall back to default-src), nonce reuse and leakage, abusing whitelisted CDNs like jsdelivr or googleapis for JSONP callbacks, strict-dynamic propagation via script gadgets, and framework-specific template injection when Angular or Vue are allowed. The base-uri omission is especially common in the wild and often overlooked. Also handles the meta tag versus header CSP differences and exfiltration channels when script execution stays blocked but you still need to get data out.

Install

npx skills add https://github.com/yaklang/hack-skills --skill csp-bypass-advanced
Votes
0
Installs882
GitHub Stars862
First SeenJun 3, 2026
View on GitHub

Comments

Login to comment