CLAUDE CODE MARKETPLACES
SkillsMarketplacesMCPDigestLearnAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Web & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web CrawlingAutomation & Workflows
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Learn
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by @mertduzgun

Independent project, not affiliated with Anthropic
  1. Skills
  2. /
  3. yaklang
  4. /
  5. hack-skills
  6. /
  7. Upload Insecure Files

Upload Insecure Files

Editor's Note

When you need to test file upload endpoints beyond just "does it accept .php," this is the playbook. It walks through the four trust boundaries of accept, store, process, and serve, which is the right mental model because bugs usually hide in a different stage than where you uploaded. You get validation bypass patterns (double extensions, polyglots, magic byte tricks), processing chain attacks (ImageMagick, FFmpeg, zip slip), and the authorization gaps that live in direct object URLs and cross-tenant paths. It routes you to companion skills for XXE in SVG imports, path traversal in archive extraction, and XSS in filename reflection. Honest take: if you're only checking upload success without testing retrieval and background processing, you're missing the actual impact.

Install

npx skills add https://github.com/yaklang/hack-skills --skill upload-insecure-files
Votes
0
Installs875
GitHub Stars862
First SeenJun 3, 2026
View on GitHub

Comments

Login to comment