CLAUDE CODE MARKETPLACES
SkillsMarketplacesMCPDigestLearnJobsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Web & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web CrawlingAutomation & Workflows
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Learn
  • Feedback
  • Privacy Policy
  • Jobs
  • Advertise

Built for the Claude Code community with Claude Code by @mertduzgun

Independent project, not affiliated with Anthropic
  1. Skills
  2. /
  3. yaklang
  4. /
  5. hack-skills
  6. /
  7. Ssrf Server Side Request Forgery

Ssrf Server Side Request Forgery

Editor's Note

This is a comprehensive SSRF exploitation playbook that goes well beyond the basic 169.254.169.254 trick most models already know. It covers cloud metadata endpoint extraction across AWS, GCP, Azure, and Alibaba, IP filter bypass using octal, hex, and IPv6-mapped formats, and protocol abuse via gopher, dict, and file schemes to hit Redis, Elasticsearch, and local filesystems. The real value is in the chaining techniques, like SSRF to internal Redis to crontab RCE, and the URL parser differential tricks that exploit how Python urllib versus Java URL versus PHP parse_url handle the same malformed input differently. Load this when you're testing anything that fetches URLs, renders PDFs from HTML, or configures webhooks, and you need the full bypass arsenal instead of just the AWS metadata basics.

Install

npx skills add https://github.com/yaklang/hack-skills --skill ssrf-server-side-request-forgery
Votes
0
Installs539
GitHub Stars636
Categories
Frontend DevelopmentBackend & APIsTesting & QAGit & Pull RequestsCode Review & QualityData Science & MLAutomation & WorkflowsPythonCloud & InfrastructureJava & JVMOffice & DocumentsPHP & Laravel
First SeenMay 16, 2026
View on GitHub

Comments

Login to comment

Related Frontend Development Skills

View all →
frontend-design

anthropics/skills

10
418.1k
135.1k
Distinctive, production-grade frontend interfaces that reject generic AI aesthetics.
vercel-react-best-practices

vercel-labs/agent-skills

5
402.7k
26.6k
3
React and Next.js performance optimization guide with 64 prioritized rules across 8 categories.
remotion-best-practices

remotion-dev/skills

0
312.3k
3.2k
Domain-specific knowledge base for building videos with Remotion and React.
vercel-composition-patterns

vercel-labs/agent-skills

0
175.4k
26.6k
React composition patterns for scaling components and avoiding boolean prop proliferation.
ui-ux-pro-max

nextlevelbuilder/ui-ux-pro-max-skill

4
167k
79k
Comprehensive design intelligence for web and mobile UI/UX across 10 technology stacks.
shadcn

shadcn/ui

0
143.8k
114.5k
Complete shadcn/ui component management for adding, searching, fixing, styling, and composing UI.