File Path Traversal Testing
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a static documentation resource focused on offensive security testing methodologies. It contains no executable scripts or code that runs automatically when the skill is loaded.
- [SAFE]: Shell command examples using tools like
curl,ffuf, andwfuzzare provided purely as educational templates for interacting with remote web targets during authorized penetration testing. - [SAFE]: The sensitive file paths listed (e.g.,
/etc/shadow,/root/.ssh/id_rsa) and exploitation techniques (e.g., log poisoning, PHP wrappers) are documented as potential targets for vulnerability research rather than being accessed or executed by the skill itself. - [SAFE]: The skill includes a dedicated section on prevention and secure coding practices, demonstrating a defensive and educational intent.
- [SAFE]: A Base64-encoded string found in the PHP wrapper section was analyzed and confirmed to be a standard PHP code execution snippet (
<?php system($_GET['c']); ?>) used as a common security research example.
Audit Metadata