cxcscmu/skilllearnbench-jackson-inject-security
Fixing Jackson @JacksonInject bypass vulnerabilities where attackers use empty JSON keys to override injected values. Use this skill whenever reviewing or patching Java code that uses @JacksonInject for security-sensitive configuration injection, especially in Apache projects.
npx skills add https://github.com/cxcscmu/SkillLearnBench --skill jackson-inject-security
Take cxcscmu/skilllearnbench-jackson-inject-security from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.