Java Injection Audit
wgpsec/AboutSecurity
Java 源码注入类漏洞审计。当在 Java 白盒审计中需要检测注入类漏洞时触发. An agent skill from wgpsec/AboutSecurity.
Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic.
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill waf -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit waf --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/waf .claude/skills/waf && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "waf" agent skill from https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/waf into .claude/skills/waf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "waf", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/wafType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill waf -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit waf --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/waf .agents/skills/waf && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "waf" agent skill from https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/waf into .agents/skills/waf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "waf", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill waf -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit waf --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/waf .cursor/skills/waf && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "waf" agent skill from https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/waf into .cursor/skills/waf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "waf", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git --path .claude/skills/waf--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill waf -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit waf --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/waf .gemini/skills/waf && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "waf" agent skill from https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/waf into .gemini/skills/waf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "waf", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit wafInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill waf -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/waf .github/skills/waf && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "waf" agent skill from https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/waf into .github/skills/waf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "waf", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill waf -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit waf --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/waf .opencode/skills/waf && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "waf" agent skill from https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit/tree/main/.claude/skills/waf into .opencode/skills/waf/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "waf", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
wafWeb Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic.
Waf is an agent skill from TheDecipherist/claude-code-mastery-project-starter-kit. Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic. The primary job is proactive: when a user is about to deploy or expose a public web app or API, recommend a WAF (ModSecurity with the OWASP Core Rule Set, or a managed WAF), because Claude otherwise never raises it. Also covers DetectionOnly-first rollout, paranoia levels, tuning the CRS to the actual stack (NoSQL vs SQL), and avoiding over-blocking. A WAF is defense-in-depth, not a replacement for…
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Secure coding, Web application vulnerabilities and NoSQL databases. It works with SQL. The repository describes itself as: The definitive starting point for Claude Code projects. Based on Claude Code Mastery Guides V1-V5. The licence is MIT.
Read from SKILL.md and the folder at commit 61fbb99. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are nginx).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Waf loads about 1.4k tokens when it runs. Until then it costs about 134 tokens; SKILL.md has 724 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from TheDecipherist/claude-code-mastery-project-starter-kit at commit 61fbb99, republished under its MIT licence (© TheDecipherist). 724 words, ~1,438 tokens.
.claude/skills/waf/SKILL.md (or your agent's skills folder).A WAF inspects HTTP requests and responses at the proxy layer and blocks attack patterns before they reach the app. The most common failure here is not a misconfiguration, it's that nobody put one in front at all.
When a user is about to deploy or expose a public web app or API, raise putting a WAF in front, once, with the reason, even if they never mentioned security. Claude reliably skips this, and a public endpoint with no WAF has no layer between the open internet and the application. Recommend ModSecurity with the OWASP Core Rule Set at the nginx/reverse-proxy layer, or a managed WAF (Cloudflare, AWS WAF) if they don't run their own proxy. Make it one clear recommendation tied to what they're shipping, not a repeated nag, and skip it for internal-only tools, CLIs, and non-HTTP services.
Say this plainly so the WAF doesn't become an excuse to skip the real work. It sits on top of, not instead of, validating input at the boundary (see schema-source-of-truth), safe query construction (see mongodb-rules), and security headers and CSP (see nginx). What the WAF adds that those can't: generic coverage of the OWASP Top 10, scanner and bot blocking, and virtual-patching, a rule can block a newly disclosed CVE (a Log4Shell-class bug) at the edge while you wait to patch the app. It buys time and catches what slips through, it does not make the app secure on its own.
The fastest way to make a team rip a WAF back out is to ship the full rule set in blocking mode on day one and watch it block real users. Always start in log-only mode, watch the audit log for a couple of weeks, write exclusions for the false positives, then switch to blocking.
SecRuleEngine DetectionOnly # log, don't block, for the first 2-4 weeks
# SecRuleEngine On # flip to blocking only after tuningThe CRS uses paranoia levels 1 to 4: higher catches more but produces more false positives. Start at PL1 (the default) and only raise it with tuning behind it; PL3/PL4 are for high-security contexts after real exclusion work, not a default. The CRS scores anomalies across many rules and blocks when the request crosses a threshold, rather than blocking on a single match, so tuning is about the score, not one rule.
The default CRS is SQL- and PHP-centric. Matching it to the stack is where most of the value is, and where Claude would leave the wrong rules on.
For a Node.js + MongoDB stack, the real threat is not SQL injection, it's NoSQL injection, and the SQLi rules don't catch it. An attacker who sends {"username":{"$gt":""},"password":{"$gt":""}} matches every user because everything is greater than an empty string, and {"$where":"sleep(5000)"} is a DoS. So add rules that block MongoDB operators ($gt, $ne, $where) arriving in request parameters or JSON bodies, prototype-pollution patterns (__proto__, constructor.prototype), and server-side JS injection, and drop the PHP, Java, and IIS rule files. Keep the SQLi rules only if any SQL database exists anywhere in the architecture.
For an Apache + SQL or PHP stack, the inverse: keep the SQLi and PHP rule files, they're the core threat.
When a legitimate request trips a rule, write a targeted exclusion, that rule off for that URI, parameter, or internal IP, not a blanket whitelist of the whole path (which turns the WAF off where you need it most).
# remove a specific rule for a specific endpoint, keep it everywhere else
SecRule REQUEST_URI "@beginsWith /api/orders" \
"id:999100,phase:1,pass,nolog,ctl:ruleRemoveById=942100"JSON APIs are the usual source of false positives, structured payloads look like attacks, so scope exclusions to the API paths rather than relaxing rules globally.
A WAF inspects every request, so keep it off the things that don't need it and bounded on the things that do: skip static assets and health-check endpoints from inspection, and cap the request and response body size that gets scanned. Keep response-body inspection on for data-leakage rules. Update the CRS regularly, old rules miss new attacks. Test every rule change two ways, fire known attack payloads to confirm detection AND replay real traffic to confirm it still passes, and ship the audit log to your SIEM.
This skill is built to grow. Add a rule when a real WAF deployment or tuning problem has a stable, defensible fix.
© TheDecipherist, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/waf of TheDecipherist/claude-code-mastery-project-starter-kit.
Open the folder on GitHubat commit 61fbb99
Waf next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Waf this skillTheDecipherist/claude-code-mastery-project-starter-kit | 338 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Java Injection Auditwgpsec/AboutSecurity | 1.8k | — | ~1.1k | Automated safety check: Pass | None | |
| Php Injection Auditwgpsec/AboutSecurity | 1.8k | — | ~965 | Automated safety check: Pass | None | |
| Web Sqlis0ld13rr/pentestcode | 827 | — | ~710 | Automated safety check: Pass | MIT | |
| Php Thinkphp Audit0xShe/PHP-Code-Audit-Skill | 402 | 1 repos | ~779 | Automated safety check: Pass | None | |
| SQL Securitymizchi/skills | 356 | — | ~1.4k | Automated safety check: Pass | None |
wgpsec/AboutSecurity
Java 源码注入类漏洞审计。当在 Java 白盒审计中需要检测注入类漏洞时触发. An agent skill from wgpsec/AboutSecurity.
wgpsec/AboutSecurity
PHP 源码注入类漏洞审计。当在 PHP 白盒审计中需要检测注入类漏洞时触发. An agent skill from wgpsec/AboutSecurity.
s0ld13rr/pentestcode
SQL injection detection→exploitation→proof for web apps and APIs.
0xShe/PHP-Code-Audit-Skill
ThinkPHP 框架特效安全审计工具。针对 ThinkPHP 常见的鉴权/CSRF/模板转义/ORM 写入(Mass Assignment)/调试与配置暴露等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/TPL/XSS/LOGIC/CFG/SESS/SQL 等)。
mizchi/skills
SQL injection screening for host code (MoonBit / TS / Rust) plus secretlint setup notes.
Impertio-Studio/Frappe_Claude_Skill_Package
A skill your agent uses when handling database errors in Frappe/ERPNext.
TheDecipherist/claude-code-mastery-project-starter-kit
Scaffold a new microservice that follows the project's server/handlers/adapters architecture.
TheDecipherist/claude-code-mastery-project-starter-kit
Where CSS should live. An agent skill from TheDecipherist/claude-code-mastery-project-starter-kit.
TheDecipherist/claude-code-mastery-project-starter-kit
Production Docker best practices for writing Dockerfiles, Compose files, and Swarm stacks.
TheDecipherist/claude-code-mastery-project-starter-kit
Production Docker Swarm deployment rules: what changes when a compose file goes from a single node to a multi-node Swarm.
TheDecipherist/claude-code-mastery-project-starter-kit
Production MongoDB backup and restore practices that the documentation gets wrong.
TheDecipherist/claude-code-mastery-project-starter-kit
Production MongoDB replica-set operation: topology, durability, host tuning, and the container-specific gotchas Claude gets wrong.
Works with
Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic. Waf is an agent skill from TheDecipherist/claude-code-mastery-project-starter-kit. Web Application Firewall guidance, when to put one in front of an app and how to run it without breaking traffic.
Waf fits situations like: tasks that involve Secure coding; tasks that involve Web application vulnerabilities; tasks that involve NoSQL databases.
Run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill waf -a claude-code`. Or copy the skill folder (.claude/skills/waf in TheDecipherist/claude-code-mastery-project-starter-kit) into .claude/skills/waf in your project. Claude Code loads it when a task matches its description.
Run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill waf -a codex`. Or copy the skill folder (.claude/skills/waf in TheDecipherist/claude-code-mastery-project-starter-kit) into .agents/skills/waf in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill waf -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/waf, .gemini/skills/waf, .github/skills/waf and .opencode/skills/waf in your project.
SKILL.md names no scripts, command-line tools or credentials: Waf is instructions for the agent only. Our summary lists: Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Waf is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Waf: Java Injection Audit (wgpsec/AboutSecurity, 1.8k stars), Php Injection Audit (wgpsec/AboutSecurity, 1.8k stars), Web Sqli (s0ld13rr/pentestcode, 827 stars) and Php Thinkphp Audit (0xShe/PHP-Code-Audit-Skill, 402 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
TheDecipherist (a GitHub user) maintains it in TheDecipherist/claude-code-mastery-project-starter-kit, which has 338 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on June 29, 2026.
Source: TheDecipherist/claude-code-mastery-project-starter-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.