File Path Traversal Testing

21.8k
davila7davila7

This skill should be used when the user asks to "test for directory traversal", "exploit path traversal vulnerabilities", "read arbitrary files through web applications", "find LFI vulnerabilities", or "access files outside web root". It provides comprehensive file path traversal attack and testing methodologies.

194 days ago

File Path Traversal Testing

3.5k
zebbernzebbern

This skill should be used when the user asks to "test for directory traversal", "exploit path traversal vulnerabilities", "read arbitrary files through web applications", "find LFI vulnerabilities", or "access files outside web root". It provides comprehensive file path traversal attack and testing methodologies.

193 days ago

feishu_file_fetch

1.8k
openclawopenclaw

Implements a Clawdbot extension tool that downloads Feishu files by message_id and file_key, streams to disk with sha256, size limits, and path traversal protection. Use when the user asks to build or update the feishu_file_fetch tool, Feishu file download workflow, or Clawdbot extension handling message_id/file_key inputs.

194 days ago

openclaw-sec

1.8k
Openclaw Skills Openclaw SecOpenclaw Skills Openclaw Sec

AI Agent Security Suite - Real-time protection against prompt injection, command injection, SSRF, path traversal, secrets exposure, and content policy violations

194 days ago

clawdefender

1.8k
openclawopenclaw

Security scanner and input sanitizer for AI agents. Detects prompt injection, command injection, SSRF, credential exfiltration, and path traversal attacks. Use when (1) installing new skills from ClawHub, (2) processing external input like emails, calendar events, Trello cards, or API responses, (3) validating URLs before fetching, (4) running security audits on your workspace. Protects agents from malicious content in untrusted data sources.

194 days ago

neo4j-cypher-guide

1.6k
tomasonjotomasonjo

Comprehensive guide for writing modern Neo4j Cypher read queries. Essential for text2cypher MCP tools and LLMs generating Cypher queries. Covers removed/deprecated syntax, modern replacements, CALL subqueries for reads, COLLECT patterns, sorting best practices, and Quantified Path Patterns (QPP) for efficient graph traversal.

193 days ago

path-traversal-finder

1.5k
Jeremylongshore Claude Code Plugins Plus Skills Path Traversal FinderJeremylongshore Claude Code Plugins Plus Skills Path Traversal Finder

Manage path traversal finder operations. Auto-activating skill for Security Fundamentals. Triggers on: path traversal finder, path traversal finder Part of the Security Fundamentals skill category. Use when working with path traversal finder functionality. Trigger with phrases like "path traversal finder", "path finder", "path".

193 days ago

neo4j-cypher-guide

426
opsmillopsmill

Comprehensive guide for writing modern Neo4j Cypher read queries. Essential for text2cypher MCP tools and LLMs generating Cypher queries. Covers removed/deprecated syntax, modern replacements, CALL subqueries for reads, COLLECT patterns, sorting best practices, and Quantified Path Patterns (QPP) for efficient graph traversal.

194 days ago

security-bun

88
IgorWarzochaIgorWarzocha

Review Bun runtime security audit patterns. Use for auditing Bun-specific vulnerabilities including shell injection, SQL injection, server security, and process spawning. Use proactively when reviewing Bun apps (bun.lockb, bunfig.toml, or bun:* imports present). Examples: - user: "Review this Bun shell script" → audit `$` usage and argument injection - user: "Check my bun:sqlite queries" → verify `sql` tagged template usage - user: "Audit my Bun.serve() setup" → check path traversal and request limits - user: "Is my Bun.spawn() usage safe?" → audit command injection and input validation - user: "Review WebSocket security in Bun" → check authentication before upgrade

194 days ago

security-express

88
IgorWarzochaIgorWarzocha

Review Express.js security audit patterns for middleware and routes. Use for auditing Helmet.js, CORS, body-parser limits, and auth middleware. Use proactively when reviewing Express.js apps. Examples: - user: "Secure my Express app" → add Helmet.js and disable x-powered-by - user: "Check Express CORS config" → verify origin allowlists and credentials - user: "Review Express auth middleware" → check route order and coverage - user: "Scan for Express path traversal" → verify path normalization and validation - user: "Audit Express session config" → check secure, httpOnly, and sameSite flags

194 days ago

File Path Traversal Testing

14
zebbernzebbern

This skill should be used when the user asks to "test for directory traversal", "exploit path traversal vulnerabilities", "read arbitrary files through web applications", "find LFI vulnerabilities", or "access files outside web root". It provides comprehensive file path traversal attack and testing methodologies.

path-traversaldirectory-traversallfi+3
194 days ago

security-bun

6
justinlevinedotmejustinlevinedotme

Review Bun runtime security audit patterns. Use for auditing Bun-specific vulnerabilities including shell injection, SQL injection, server security, and process spawning. Use proactively when reviewing Bun apps (bun.lockb, bunfig.toml, or bun:* imports present). Examples: - user: "Review this Bun shell script" → audit `$` usage and argument injection - user: "Check my bun:sqlite queries" → verify `sql` tagged template usage - user: "Audit my Bun.serve() setup" → check path traversal and request limits - user: "Is my Bun.spawn() usage safe?" → audit command injection and input validation - user: "Review WebSocket security in Bun" → check authentication before upgrade

193 days ago

remediation-config

6
ZateZate

Security fix patterns for configuration and deployment vulnerabilities (path traversal, debug mode, security headers). Provides language-specific secure implementations.

193 days ago

security-express

6
justinlevinedotmejustinlevinedotme

Review Express.js security audit patterns for middleware and routes. Use for auditing Helmet.js, CORS, body-parser limits, and auth middleware. Use proactively when reviewing Express.js apps. Examples: - user: "Secure my Express app" → add Helmet.js and disable x-powered-by - user: "Check Express CORS config" → verify origin allowlists and credentials - user: "Review Express auth middleware" → check route order and coverage - user: "Scan for Express path traversal" → verify path normalization and validation - user: "Audit Express session config" → check secure, httpOnly, and sameSite flags

193 days ago

File Path Traversal Testing

5
agent-skills-hubagent-skills-hub

This skill should be used when the user asks to "test for directory traversal", "exploit path traversal vulnerabilities", "read arbitrary files through web applications", "find LFI vulnerabilities", or "access files outside web root". It provides comprehensive file path traversal attack and testing methodologies.

194 days ago

file-path-traversal

4
ngxtmngxtm

This skill should be used when the user asks to "test for directory traversal", "exploit path traversal vulnerabilities", "read arbitrary files through web applications", "find LFI vu...

193 days ago

vibe-security

4
0x85060x8506

Security intelligence for code analysis. Detects SQL injection, XSS, CSRF, authentication issues, crypto failures, and more. Actions: scan, analyze, fix, audit, check, review, secure, validate, sanitize, protect. Languages: JavaScript, TypeScript, Python, PHP, Java, Go, Ruby. Frameworks: Express, Django, Flask, Laravel, Spring, Rails. Vulnerabilities: SQL injection, XSS, CSRF, authentication bypass, authorization issues, command injection, path traversal, insecure deserialization, weak crypto, sensitive data exposure. Topics: input validation, output encoding, parameterized queries, password hashing, session management, CORS, CSP, security headers, rate limiting, dependency scanning.

193 days ago

cypher-linguist

3
JasonWarrenUKJasonWarrenUK

This skill should be used when the user mentions "Neo4j", "Cypher", "graph database", "graph query", discusses graph relationships, traversals, path finding, or needs help with Cypher syntax. Addresses Neo4j fundamentals, query patterns, performance optimization, and integration with relational databases.

194 days ago

performing-directory-traversal-testing

2
mukul975mukul975

Testing web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on the server by manipulating file path parameters.

penetration-testingdirectory-traversalpath-traversal+3
193 days ago

file-path-traversal

1
rootcastlecorootcastleco

This skill should be used when the user asks to "test for directory traversal", "exploit path traversal vulnerabilities", "read arbitrary files through web applications", "find LFI vu...

193 days ago

find-shortest-path

1
jimmc414jimmc414

For pathfinding and search: shortest path, maze solving, game AI, route planning, graph traversal, BFS/DFS, Dijkstra, A* problems.

193 days ago

Secure Code Review

narlyseorgnarlyseorg

Use when reviewing source code for security vulnerabilities, performing static analysis of a codebase, or auditing code for injection flaws, authentication issues, cryptographic weaknesses, insecure deserialization, SSRF, path traversal, memory-safety bugs, hardcoded secrets, or misconfigurations. Use when the user asks to find security bugs in code, assess code quality from a security perspective, review pull requests for security implications, perform dependency audits, run secrets scans, or review application configuration in source.

193 days ago

file-path-traversal

reikiplanetreikiplanet

This skill should be used when the user asks to test for directory traversal, exploit path traversal vulnerabilities, read arbitrary files through web applications, find LFI vulnerabilities, or similar file path traversal investigations...

194 days ago

path-traversal-finder

nivkazdannivkazdan

Manage path traversal finder operations. Auto-activating skill for Security Fundamentals. Triggers on: path traversal finder, path finder, path Part of the Security Fundamentals skill category. Use when working with path traversal finder functionality. Trigger with phrases like "path traversal finder", "path finder", "path".

193 days ago

File Path Traversal Testing

haniakrim21haniakrim21

This skill should be used when the user asks to "test for directory traversal", "exploit path traversal vulnerabilities", "read arbitrary files through web applications", "find LFI vulnerabilities", or "access files outside web root". It provides comprehensive file path traversal attack and testing methodologies.

193 days ago

file-upload-safety

sharp-skillssharp-skills

Validates, sanitizes, and safely stores uploaded files to prevent malware execution, path traversal, and storage abuse. Use whenever accepting file uploads from users. Triggers on: file upload, multipart, file type validation, MIME type, malware scan, S3 upload, path traversal, file extension, image upload, document upload, upload size limit.

193 days ago

remediation

DryRunSecurityDryRunSecurity

Helps fix security vulnerabilities identified by DryRunSecurity. Activates when the user shares a DryRunSecurity comment (from a GitHub PR or GitLab MR) or asks for help fixing any security finding including SQL injection, XSS, CSRF, SSRF, path traversal, command injection, authentication bypass, authorization flaws, and prompt injection. Researches authoritative sources and applies fixes grounded in the user's specific codebase context.

194 days ago

openclaw-sec

BJS-Innovation-LabBJS-Innovation-Lab

AI Agent Security Suite - Real-time protection against prompt injection, command injection, SSRF, path traversal, secrets exposure, and content policy violations

193 days ago

agentprivacy-grimoire-navigation

mitchuskimitchuski

Spellbook interconnection and traversal methodology for 0xagentprivacy. Activates when designing constellation paths, choosing which grimoire to enter for a given question, constructing spellwebs across acts/chapters/tales, or understanding how the 5 spellbooks form a coherent navigation system. Triggers: "which spellbook", "constellation path", "spellweb", "grimoire", "act sequence", "tale selection", "cross-grimoire".

193 days ago

File Path Traversal Testing

oki3505Foki3505F

This skill should be used when the user asks to 'test for directory traversal', 'exploit path traversal vulnerabilities', 'read arbitrary files through web applications', 'find LFI vulnerabilities', or 'access files outside web root'. It provides comprehensive file path traversal attack and testing methodologies.

193 days ago