skills/skills.volces.com/Path Traversal Audit

Path Traversal Audit

Installation
SKILL.md

phy-path-traversal-audit

Static scanner for OWASP A01:2021 — Broken Access Control / Path Traversal (CWE-22) and Local File Inclusion (CWE-98). Finds file system sinks that accept user-controlled paths, checks for missing containment guards, and flags PHP include/require patterns that allow template injection. Zero external API calls, zero dependencies beyond Python 3 stdlib.

What Is Path Traversal?

An attacker passes ../../etc/passwd or ..%2F..%2Fetc%2Fshadow as a filename parameter. Without validation, your code reads arbitrary files outside the intended base directory. With PHP include, it can lead to Remote Code Execution.

Classic exploit:

GET /api/files?path=../../etc/passwd HTTP/1.1

If your handler does open("uploads/" + request.args["path"]), attacker reads /etc/passwd.

What It Detects

Installs
3
First Seen
Apr 23, 2026
Path Traversal Audit from skills.volces.com