* Fix unauthenticated command injection (RCE) in Studio server
The `--studio` server (cli-tool/src/sandbox-server.js) bound to 0.0.0.0
with wildcard CORS and no authentication, and passed request-body fields
into spawn(..., { shell: true }). Because shell:true makes Node join the
argv array into a single `sh -c` string, the fields were parsed by the
shell, allowing OS command injection (RCE) via POST /api/execute (prompt)
and POST /api/install-agent (agentName), reachable from the LAN or a
malicious web page (wildcard CORS).
- Remove shell:true from all three spawns so arguments stay discrete argv
entries; shell metacharacters can no longer inject commands.
- Validate agentName against ^[A-Za-z0-9._/-]+$ before use.
- Bind the server to 127.0.0.1 only (removes the LAN vector).
- Restrict CORS to the local UI origin and reject cross-origin requests
(removes the drive-by browser vector).
Fixes GHSA-79wm-x847-7cvg.
Co-Authored-By: Claude Opus <noreply@anthropic.com>
* security: Windows-safe spawns + release bump on top of GHSA-79wm-x847-7cvg fix
Builds on @spartan8806's fix (advisory-fix-1). Adds the two pieces that fix
lacked:
- Resolve npx/claude via their .cmd shims on Windows (NPX_CMD/CLAUDE_CMD).
Without shell:true, bare spawn('npx'/'claude') fails with ENOENT on win32,
which would break agent install/local execution. This keeps the security fix
cross-platform.
- Bump version to 1.29.4 (root + cli-tool package.json) and add the 1.29.4
Security entry to CHANGELOG for the patched release.
Refs GHSA-79wm-x847-7cvg.
---------
Co-authored-by: spartan8806 <spartan8806@users.noreply.github.com>
Co-authored-by: Claude Opus <noreply@anthropic.com>
Co-authored-by: Dani <dan.avila7@gmail.com>
Sponsored by Bright Data
Bright Data proudly supports this project.
Connect Claude Code to live web data — try their Skills and MCPs for web search, scraping, and structured data feeds.
# Install the Bright Data Skills + MCP for Claude Code
npx claude-code-templates@latest --skill web-data/search,web-data/scrape,web-data/data-feeds,web-data/bright-data-mcp,web-data/bright-data-best-practices,development/brightdata-local-search --mcp web-data/brightdata --yes
Claude Code Templates (aitmpl.com)
Ready-to-use configurations for Anthropic's Claude Code. A comprehensive collection of AI agents, custom commands, settings, hooks, external integrations (MCPs), and project templates to enhance your development workflow.
Browse & Install Components and Templates
Browse All Templates - Interactive web interface to explore and install 100+ agents, commands, settings, hooks, and MCPs.
🚀 Quick Installation
# Install a complete development stack
npx claude-code-templates@latest --agent development-team/frontend-developer --command testing/generate-tests --mcp development/github-integration --yes
# Browse and install interactively
npx claude-code-templates@latest
# Install specific components
npx claude-code-templates@latest --agent development-tools/code-reviewer --yes
npx claude-code-templates@latest --command performance/optimize-bundle --yes
npx claude-code-templates@latest --setting performance/mcp-timeouts --yes
npx claude-code-templates@latest --hook git/pre-commit-validation --yes
npx claude-code-templates@latest --mcp database/postgresql-integration --yes
What You Get
| Component | Description | Examples |
|---|---|---|
| 🤖 Agents | AI specialists for specific domains | Security auditor, React performance optimizer, database architect |
| ⚡ Commands | Custom slash commands | /generate-tests, /optimize-bundle, /check-security |
| 🔌 MCPs | External service integrations | GitHub, PostgreSQL, Stripe, AWS, OpenAI |
| ⚙️ Settings | Claude Code configurations | Timeouts, memory settings, output styles |
| 🪝 Hooks | Automation triggers | Pre-commit validation, post-completion actions |
| 🎨 Skills | Reusable capabilities with progressive disclosure | PDF processing, Excel automation, custom workflows |
🛠️ Additional Tools
Beyond the template catalog, Claude Code Templates includes powerful development tools:
📊 Claude Code Analytics
Monitor your AI-powered development sessions in real-time with live state detection and performance metrics.
npx claude-code-templates@latest --analytics
💬 Conversation Monitor
Mobile-optimized interface to view Claude responses in real-time with secure remote access.
# Local access
npx claude-code-templates@latest --chats
# Secure remote access via Cloudflare Tunnel
npx claude-code-templates@latest --chats --tunnel
🔍 Health Check
Comprehensive diagnostics to ensure your Claude Code installation is optimized.
npx claude-code-templates@latest --health-check
🔌 Plugin Dashboard
View marketplaces, installed plugins, and manage permissions from a unified interface.
npx claude-code-templates@latest --plugins
📖 Documentation
📚 docs.aitmpl.com - Complete guides, examples, and API reference for all components and tools.
Contributing
We welcome contributions! Browse existing templates to see what's available, then check our contributing guidelines to add your own agents, commands, MCPs, settings, or hooks.
Please read our Code of Conduct before contributing.
Attribution
This collection includes components from multiple sources:
Scientific Skills:
- K-Dense-AI/claude-scientific-skills by K-Dense Inc. - MIT License (139 scientific skills for biology, chemistry, medicine, and computational research)
Official Anthropic:
- anthropics/skills - Official Anthropic skills (21 skills)
- anthropics/claude-code - Development guides and examples (10 skills)
Community Skills & Agents:
- obra/superpowers by Jesse Obra - MIT License (14 workflow skills)
- alirezarezvani/claude-skills by Alireza Rezvani - MIT License (36 professional role skills)
- wshobson/agents by wshobson - MIT License (48 agents)
- NerdyChefsAI Skills - Community contribution - MIT License (specialized enterprise skills)
Commands & Tools:
- awesome-claude-code by hesreallyhim - CC0 1.0 Universal (21 commands)
- awesome-claude-skills - Apache 2.0 (community skills)
- move-code-quality-skill - MIT License
- cocoindex-claude - Apache 2.0
Each of these resources retains its original license and attribution, as defined by their respective authors. We respect and credit all original creators for their work and contributions to the Claude ecosystem.
📄 License
This project is licensed under the MIT License - see the LICENSE file for details.
🔗 Links
- 🌐 Browse Templates: aitmpl.com
- 📚 Documentation: docs.aitmpl.com
- 💬 Community: GitHub Discussions
- 🐛 Issues: GitHub Issues
Stargazers over time
⭐ Found this useful? Give us a star to support the project!