Help us improve
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
Share bugs, ideas, or general feedback.
By califio
Audit PHP engine deserialization surfaces like unserialize, session decoders, WDDX, phar metadata, and custom handlers for use-after-free via back-references, type confusion, partial-object __destruct, heap overflows, and parse inconsistencies. Analyze PHP 5.4-5.6 sources with advisory verification and AI agents.
npx claudepluginhub califio/skills --plugin php-unserialize-auditA Claude Code plugin marketplace from Calif.io providing skills and slash commands for AI-assisted security research and code auditing.
Add the marketplace once:
/plugin marketplace add califio/skills
Then browse and install plugins:
/plugin menu
A Codex-native skill tree lives at .codex/skills/ (symlinked to the same content used by the Claude plugins). Install with:
git clone https://github.com/califio/skills.git ~/.codex/califio-skills
~/.codex/califio-skills/.codex/scripts/install-for-codex.sh
See .codex/INSTALL.md for details.
To test changes locally, from the parent directory of this repo:
/plugin marketplace add ./skills
| Plugin | Description |
|---|---|
| php-unserialize-audit | Audit PHP engine deserialization surface for UAF, type confusion, partial-object __destruct, signed-length heap overflow, and parse inconsistency |
New plugins are welcome. The repo follows the standard Claude Code plugin marketplace layout:
.claude-plugin/marketplace.json # marketplace index — add an entry here
plugins/<plugin-name>/
.claude-plugin/plugin.json # plugin metadata
skills/<skill-name>/SKILL.md # the skill (Claude auto-loads by description)
commands/<command-name>.md # slash command (optional)
agents/<agent-name>.md # subagents (optional)
A plugin can ship any combination of skills, commands, agents, and MCP servers. To add one:
plugins/<your-plugin>/ with the structure above..claude-plugin/marketplace.json.MIT © Calif.io
Share bugs, ideas, or general feedback.
Based on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
Advanced PHP programming skills for modern PHP and security patterns
Security audit patterns (OWASP Top 10, CWE Top 25 2025, CVSS v4.0) and GitHub project security checks for any project. Deep automated PHP/TYPO3 scanning with 80+ checkpoints, 19 reference guides, PreToolUse warnings. By Netresearch.
Specialized security review subagent
Perform security audit on codebase
Automatically reviews and fixes Claude Code skills through iterative refinement until they meet quality standards. Requires plugin-dev plugin.
Security research toolkit for discovering and remediating vulnerabilities
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge.
Sign in to claim