CLAUDE CODE MARKETPLACES
SkillsMarketplacesMCPDigestLearnAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Web & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web CrawlingAutomation & Workflows
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Learn
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by @mertduzgun

Independent project, not affiliated with Anthropic
  1. Skills
  2. /
  3. yaklang
  4. /
  5. hack-skills
  6. /
  7. Dependency Confusion

Dependency Confusion

Editor's Note

This teaches Claude how to identify and test dependency confusion vulnerabilities across npm, pip, Maven, RubyGems, and other package ecosystems. It walks through the core mechanic (attacker publishes a higher version of an internal package name on a public registry), shows recon commands to check if names are squattable, and provides PoC patterns using DNS callbacks instead of destructive payloads. The guidance is red-team focused but includes defensive controls like scoped packages and lockfile enforcement. Load this when you're auditing manifests for supply chain risk or running authorized exercises against build pipelines. It pairs well with the recon-for-sec skill for initial package enumeration.

Install

npx skills add https://github.com/yaklang/hack-skills --skill dependency-confusion
Votes
0
Installs900
GitHub Stars862
First SeenJun 3, 2026
View on GitHub

Comments

Login to comment