cxcscmu/apache-druid-javascript-rce-vulnerability-analysis
Understanding the CVE in Apache Druid 0.20.0 where authenticated attackers can execute arbitrary code via JavaScript payloads. The vulnerability exploits @JacksonInject with empty key "" to override JavaScriptConfig and enable JavaScript execution even when disabled. Use this skill to understand the attack vector and plan the fix.
npx skills add https://github.com/cxcscmu/SkillLearnBench --skill apache-druid-javascript-rce-vulnerability-analysis
Take cxcscmu/apache-druid-javascript-rce-vulnerability-analysis from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.