CLAUDE CODE MARKETPLACES
SkillsMarketplacesMCPDigestLearnJobsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Web & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web CrawlingAutomation & Workflows
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Learn
  • Feedback
  • Privacy Policy
  • Jobs
  • Advertise

Built for the Claude Code community with Claude Code by @mertduzgun

Independent project, not affiliated with Anthropic
  1. Skills
  2. /
  3. yaklang
  4. /
  5. hack-skills
  6. /
  7. Deserialization Insecure

Deserialization Insecure

Editor's Note

When you're staring at a `rememberMe` cookie that starts with `rO0AB` or a POST body with `O:8:"ClassName"`, this is the playbook you load. It walks through traffic fingerprinting for Java, PHP, and Python deserialization, then covers the actual exploit chains: ysoserial for Java gadgets (CommonsCollections, Spring, the whole roster), PHPGGC for PHP magic methods, Shiro rememberMe with hardcoded keys, WebLogic T3, and Phar wrapper tricks. The URLDNS probe for safe confirmation is smart. The gadget chain version matrix saves you from trial and error hell. It knows the JDK 8u191 cutoff where remote class loading dies and you pivot to serialized gadgets over LDAP. This is the difference between finding `readObject()` and actually popping a shell.

Install

npx skills add https://github.com/yaklang/hack-skills --skill deserialization-insecure
Votes
0
Installs501
GitHub Stars636
Categories
Git & Pull RequestsDocumentationRelease ManagementDebuggingPythonMarketing & SEOJava & JVMCLI & TerminalPHP & Laravel
First SeenMay 16, 2026
View on GitHub

Comments

Login to comment

Related Git & Pull Requests Skills

View all →
azure-diagnostics

microsoft/azure-skills

0
320.3k
964
Systematic diagnosis and remediation for Azure production issues using AppLens, Monitor, and resource health.
azure-messaging

microsoft/azure-skills

0
309.6k
964
Diagnose and resolve Azure Event Hubs and Service Bus SDK issues with structured troubleshooting workflows.
azure-hosted-copilot-sdk

microsoft/azure-skills

0
293.1k
964
Build and deploy GitHub Copilot SDK applications to Azure with flexible model configuration.
github-actions-docs

xixu-me/skills

0
140.1k
53
github actions docs
azure-ai

microsoft/github-copilot-for-azure

0
103.7k
160
azure-cost-optimization

microsoft/github-copilot-for-azure

0
103.2k
160