CLAUDE CODE MARKETPLACES
SkillsMarketplacesMCPDigestLearnAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Web & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web CrawlingAutomation & Workflows
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Learn
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by @mertduzgun

Independent project, not affiliated with Anthropic
  1. Skills
  2. /
  3. yaklang
  4. /
  5. hack-skills
  6. /
  7. Prototype Pollution

Prototype Pollution

Editor's Note

This gives Claude the full offensive playbook for finding and exploiting prototype pollution in JavaScript applications. It covers both `__proto__` and `constructor.prototype` injection paths, quick probes for client and server contexts, and concrete black-box detection signals like polluting Express `parameterLimit` or `json spaces` settings. The gadget table walks through real RCE chains in EJS and child_process scenarios. Load this when you're merging untrusted input into objects, auditing query parsers or deep assign logic, or hunting for post-pollution sinks that turn property injection into command execution. The decision tree and tool list make it practical for both initial recon and chaining to full exploits.

Install

npx skills add https://github.com/yaklang/hack-skills --skill prototype-pollution
Votes
0
Installs903
GitHub Stars862
First SeenJun 3, 2026
View on GitHub

Comments

Login to comment