ghost-bits-cast-attack

ghost-bits-cast-attack is a skill for Claude Code, Codex from ShulkwiSEC/bb-huge. It costs 141 tokens per session (8,749 once invoked), scanned A, a copy of ghost-bits-cast-attack, MIT.

A Java security-testing guide for finding attacks that exploit the conversion of Unicode characters into bytes. It focuses on cases where a web application firewall sees one value but the Java backend interprets another.

In plain words
What is it for?
Use it when assessing Java services behind a WAF for SQL injection, unsafe deserialization, file-upload, path-traversal, CRLF, request-smuggling, or SMTP-injection risks.
Why use it?
It helps test whether filtering can be bypassed when a Java service changes character data into a narrower byte format.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/shulkwisec/bb-huge/ghost-bits-cast-attack
Any agent
npx skills add ShulkwiSEC/bb-huge --skill ghost-bits-cast-attack
Clone the repo
git clone --depth 1 https://github.com/ShulkwiSEC/bb-huge

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ghost-bits-cast-attack

README.md
[![agentmods](https://agentmods.dev/badge/skills/shulkwisec/bb-huge/ghost-bits-cast-attack.svg)](https://agentmods.dev/skills/shulkwisec/bb-huge/ghost-bits-cast-attack)
Your own site
<a href="https://agentmods.dev/skills/shulkwisec/bb-huge/ghost-bits-cast-attack"><img src="https://agentmods.dev/badge/skills/shulkwisec/bb-huge/ghost-bits-cast-attack.svg" alt="Measured on agentmods" height="20"></a>
Per session 141 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 8,749 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00141 $0.08749
Opus 5 $0.00071 $0.04374
Sonnet 5 $0.00028 $0.01750
Haiku 4.5 $0.00014 $0.00875

Measured yesterday against content hash d44fe2cace4e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

ghost-bits-cast-attack scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to ghost-bits-cast-attack — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

skills/curated/ghost-bits-cast-attack/SKILL.md · 800 lines

How it starts

The opening of the file, as written. The whole thing — 800 lines — stays where its author put it; the contents beside it link to each section on GitHub.

SKILL: Ghost Bits / Cast Attack — Java char to byte Narrowing Playbook

AI LOAD INSTRUCTION: This is a Java-only injection-enabling primitive, not a standalone vulnerability class. Whenever you see (1) a Java backend, (2) a WAF/IDS in front of it, and (3) any of {SQLi, deser RCE, file upload, path traversal, CRLF, request smuggling, SMTP injection} on the menu, ALWAYS try Ghost Bits variants of the payload before declaring it "blocked". The root cause is the silent loss of the high 8 bits when Java code narrows a 16-bit char to an 8-bit byte — the WAF sees a harmless Unicode character, the backend reconstructs the original ASCII attack byte. Base models almost never reach for this primitive.

Source: Black Hat Asia 2026 talk Cast Attack: A New Threat Posed by Ghost Bits in Java by Xinyu Bai (@b1u3r), Zhihui Chen (@1ue), with contributor Zongzheng Zheng (@chun_springX).

Ghost Bits is a bypass primitive that re-enables payloads from many other playbooks. Pair it with whichever attack family applies:

  • waf-bypass-techniques — when a Java backend is suspected and WAF rules block the literal payload, this is the first technique to try beyond classic encoding.
  • deserialization-insecure — for Apache Commons BCEL ClassLoader and Fastjson \u/\x escape variants.
  • path-traversal-lfi — Spring, Jetty, Undertow, Vert.x URL decoding and %2> hex folding.
  • upload-insecure-files — Tomcat RFC2231Utility filename* Webshell upload.
  • request-smuggling — Apache HttpClient <= 4.5.9 (HTTPCLIENT-1974/1978) header CRLF.
  • crlf-injection — Angus Mail / Jakarta Mail SMTP injection and JDK HttpServer response splitting.
  • sqli-sql-injection — Jackson charToHex table-lookup truncation hides SQL keywords inside Unicode escapes.

Read the full file on GitHub · 800 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 800 lines · 141 tokens per session scan A d44fe2cace4e

Subscribe to this mod's changes

ghost-bits-cast-attack is a skill published in the GitHub repository ShulkwiSEC/bb-huge (22 stars, last pushed 1mo ago), licensed MIT. It adds 141 tokens to every session and 8,749 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to ghost-bits-cast-attack, differing in 0 lines, and is treated as a copy.

Related

Other skills, from other repositories

bugcrowd-reporting

Bugcrowd-specific reporting tactics complementing report-writing: VRT category search-and-fallback strategy when no exact match exists, manual severity override when VRT defaults underrate impact, severity-request paragraph as first body section, OOS-clause rebuttal templates (rate limiting on auth-flow endpoints…

elementalsouls/Claude-BugHunter · 171 tokens

skill-context-detection

Auto-detect work context (Dev vs Knowledge) — use to tailor workflows based on current task type.

nyldn/claude-octopus · 25 tokens

skill-copilot-provider

GitHub Copilot CLI as optional zero-cost provider via copilot -p programmatic mode.

nyldn/claude-octopus · 24 tokens

race

Race condition / TOCTOU playbook — limit overrun (one-time codes used twice, gift cards spent twice), single-packet attack (last-byte sync) to force parallel processing, and state-confusion races (file upload + read, order before payment). Use when timing-sensitive logic could be abused — one-time codes, coupons/gift…

PentesterFlow/agent · 82 tokens

skill-security-framing

URL validation and content sanitization for untrusted sources — use when handling external input safely.

nyldn/claude-octopus · 22 tokens

my-skill

One line on what this playbook does, then a "Use when ..." clause so the agent knows when to load it (e.g. "Use when the target exposes X / you see Y in requests"). Max 1024 chars. This description is the ONLY thing the model sees until it loads the skill — make the trigger conditions explicit, since there is no…

PentesterFlow/agent · 84 tokens