CAT
/Skills
SkillsMCPMarketplacesDigestToolsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Sales & MarketingWeb & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web Crawling
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Cross AI Tools

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Tools
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by @mertduzgun

Independent project, not affiliated with Anthropic

yaklang/hack-skills

102 skills·91.8k total installs·GitHub
npx -y skills add yaklang/hack-skills --agent claude-code
hack1ksqli-sql-injection993xss-cross-site-scripting986code-obfuscation-deobfuscation979ssrf-server-side-request-forgery974api-sec964api-recon-and-docs963recon-and-methodology956api-auth-and-jwt-abuse955android-pentesting-tricks950recon-for-sec949websocket-security949business-logic-vulnerabilities945jwt-oauth-token-attacks944authbypass-authentication-flaws943auth-sec942injection-checking941idor-broken-object-authorization939waf-bypass-techniques937api-authorization-and-bola933401-403-bypass-techniques931csrf-cross-site-request-forgery927oauth-oidc-misconfiguration927business-logic-vuln924cors-cross-origin-misconfiguration924path-traversal-lfi922traffic-analysis-pcap921xxe-xml-external-entity919heap-exploitation917race-condition917cmdi-command-injection914open-redirect914ssti-server-side-template-injection914crlf-injection913deserialization-insecure913file-access-vuln913graphql-and-hidden-parameters913http-parameter-pollution911insecure-source-code-management911request-smuggling911web-cache-deception910csv-formula-injection907format-string-exploitation907jndi-injection907saml-sso-assertion-attacks906kubernetes-pentesting904clickjacking903expression-language-injection903prototype-pollution903dependency-confusion900kernel-exploitation900type-juggling900xslt-injection900llm-prompt-injection899binary-protection-bypass892ios-pentesting-tricks891http-host-header-attacks890active-directory-acl-abuse888browser-exploitation-v8888subdomain-takeover884active-directory-certificate-services883active-directory-kerberos-attacks883arbitrary-write-to-rce882csp-bypass-advanced882http2-specific-attacks881memory-forensics-volatility880symbolic-execution-tools880vm-and-bytecode-reverse880windows-av-evasion880hash-attack-techniques879stack-overflow-and-rop879anti-debugging-techniques878dangling-markup-injection878classical-cipher-analysis875upload-insecure-files875email-header-injection874windows-privilege-escalation874ai-ml-security873mobile-ssl-pinning-bypass873dns-rebinding-attacks872linux-lateral-movement872linux-privilege-escalation872network-protocol-attacks871smart-contract-vulnerabilities871tunneling-and-pivoting871prototype-pollution-advanced870container-escape-techniques869defi-attack-patterns868linux-security-bypass868steganography-techniques868nosql-injection867symmetric-cipher-attacks866lattice-crypto-attacks864windows-lateral-movement864rsa-attack-techniques863sandbox-escape-techniques862ntlm-relay-coercion855unauthorized-access-common-services855macos-process-injection850macos-security-bypass849reverse-shell-techniques835ghost-bits-cast-attack617