ghost-bits-cast-attack

ghost-bits-cast-attack is a skill for Claude Code, Codex from DorianGallo/hack-skills-local. It costs 141 tokens per session (8,749 once invoked), scanned A, a copy of ghost-bits-cast-attack, MIT.

A guide to a Java type-conversion issue in which a 16-bit character is narrowed to an 8-bit byte. In some systems, a web firewall may inspect one representation while the Java backend uses another.

In plain words
What is it for?
Testing Java services behind a WAF or intrusion detector for bypasses involving SQL injection, unsafe deserialization, file uploads, path traversal, line-break injection, request smuggling, or SMTP injection.
Why use it?
It helps authorised testers investigate cases where a firewall appears to block an attack but the backend interprets the input differently. The technique is a bypass method, not a standalone vulnerability.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one.

Needs its repository: it reads a path above its own folder, which exists only inside the repository. The line is = ../../etc/passwd at the byte layer.

Good fit Testing Java services behind a WAF or intrusion detector for bypasses involving SQL injection, unsafe deserialization, file uploads, path traversal, line-break injection, request smuggling, or SMTP injection.

Compare 6 skills from other repositories ↓
Install

Getting it into your agent

It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.

Clone the repo
git clone --depth 1 https://github.com/DorianGallo/hack-skills-local
agentmods
npx agentmods add skills/doriangallo/hack-skills-local/ghost-bits-cast-attack

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ghost-bits-cast-attack

README.md
[![agentmods](https://agentmods.dev/badge/skills/doriangallo/hack-skills-local/ghost-bits-cast-attack.svg)](https://agentmods.dev/skills/doriangallo/hack-skills-local/ghost-bits-cast-attack)
Your own site
<a href="https://agentmods.dev/skills/doriangallo/hack-skills-local/ghost-bits-cast-attack"><img src="https://agentmods.dev/badge/skills/doriangallo/hack-skills-local/ghost-bits-cast-attack.svg" alt="Measured on agentmods" height="20"></a>
Per session 141 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 8,749 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00141 $0.08749
Opus 5 $0.00071 $0.04374
Sonnet 5 $0.00028 $0.01750
Haiku 4.5 $0.00014 $0.00875

Measured 8d ago against content hash d44fe2cace4e, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

ghost-bits-cast-attack scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to ghost-bits-cast-attack — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

skills/ghost-bits-cast-attack/SKILL.md · 800 lines

How it starts

The opening of the file, as written. The whole thing — 800 lines — stays where its author put it; the contents beside it link to each section on GitHub.

SKILL: Ghost Bits / Cast Attack — Java char to byte Narrowing Playbook

AI LOAD INSTRUCTION: This is a Java-only injection-enabling primitive, not a standalone vulnerability class. Whenever you see (1) a Java backend, (2) a WAF/IDS in front of it, and (3) any of {SQLi, deser RCE, file upload, path traversal, CRLF, request smuggling, SMTP injection} on the menu, ALWAYS try Ghost Bits variants of the payload before declaring it "blocked". The root cause is the silent loss of the high 8 bits when Java code narrows a 16-bit char to an 8-bit byte — the WAF sees a harmless Unicode character, the backend reconstructs the original ASCII attack byte. Base models almost never reach for this primitive.

Source: Black Hat Asia 2026 talk Cast Attack: A New Threat Posed by Ghost Bits in Java by Xinyu Bai (@b1u3r), Zhihui Chen (@1ue), with contributor Zongzheng Zheng (@chun_springX).

Ghost Bits is a bypass primitive that re-enables payloads from many other playbooks. Pair it with whichever attack family applies:

  • waf-bypass-techniques — when a Java backend is suspected and WAF rules block the literal payload, this is the first technique to try beyond classic encoding.
  • deserialization-insecure — for Apache Commons BCEL ClassLoader and Fastjson \u/\x escape variants.
  • path-traversal-lfi — Spring, Jetty, Undertow, Vert.x URL decoding and %2> hex folding.
  • upload-insecure-files — Tomcat RFC2231Utility filename* Webshell upload.
  • request-smuggling — Apache HttpClient <= 4.5.9 (HTTPCLIENT-1974/1978) header CRLF.
  • crlf-injection — Angus Mail / Jakarta Mail SMTP injection and JDK HttpServer response splitting.
  • sqli-sql-injection — Jackson charToHex table-lookup truncation hides SQL keywords inside Unicode escapes.

Read the full file on GitHub · 800 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 800 lines · 141 tokens per session scan A d44fe2cace4e

Subscribe to this mod's changes

ghost-bits-cast-attack is a skill published in the GitHub repository DorianGallo/hack-skills-local (5 stars, last pushed 3mo ago), licensed MIT. It adds 141 tokens to every session and 8,749 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to ghost-bits-cast-attack, differing in 0 lines, and is treated as a copy.

Related

Other skills, from other repositories

azure-security-keyvault-secrets-java

Azure Key Vault Secrets Java SDK for secret management. Use when storing, retrieving, or managing passwords, API keys, connection strings, or other sensitive configuration data.

microsoft/skills · 40 tokens

azure-ai-anomalydetector-java

Build anomaly detection applications with Azure AI Anomaly Detector SDK for Java. Use when implementing univariate/multivariate anomaly detection, time-series analysis, or AI-powered monitoring.

microsoft/skills · 43 tokens

azure-communication-chat-java

Build real-time chat applications with Azure Communication Services Chat Java SDK. Use when implementing chat threads, messaging, participants, read receipts, typing notifications, or real-time chat features.

microsoft/skills · 41 tokens

azure-communication-common-java

Azure Communication Services common utilities for Java. Use when working with CommunicationTokenCredential, user identifiers, token refresh, or shared authentication across ACS services.

microsoft/skills · 35 tokens

union-type-wrappers

Add typed getters and setters over BinaryData properties that represent TypeSpec union types in generated Java models. Use when generated classes expose BinaryData for union-typed fields and you need ergonomic, type-safe accessors instead.

Azure/azure-sdk-for-java · 49 tokens

azure-ai-agents-persistent-java

Azure AI Agents Persistent SDK for Java. Low-level SDK for creating and managing AI agents with threads, messages, runs, and tools. Triggers: "PersistentAgentsClient", "persistent agents java", "agent threads java", "agent runs java", "streaming agents java".

microsoft/skills · 63 tokens