path-traversal-lfi

Warn

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXFILTRATION]: The skill identifies and encourages the access of highly sensitive files including /etc/shadow, SSH private keys (~/.ssh/id_rsa), AWS credential files (~/.aws/credentials), and application environment files (.env) containing API keys and database passwords.
  • [REMOTE_CODE_EXECUTION]: Provides comprehensive methodologies for achieving Remote Code Execution through LFI vulnerabilities, such as log poisoning (Apache/Nginx/SSH), session file poisoning, and exploiting PHP wrappers like php://input, data://, and phar://.
  • [COMMAND_EXECUTION]: Includes executable command patterns for injecting PHP payloads via SSH and utilizing various Python-based exploit tools for generating filter chains and triggering AJP vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: References multiple third-party exploitation tools and repositories, including ajpShooter, php_filter_chain_generator, and cnext-exploits, to facilitate advanced attack stages.
  • [PROMPT_INJECTION]: Contains instructions directed at the AI agent to adopt an 'Expert' persona and prioritize techniques that bypass standard safety filters and 'base model' limitations regarding encoding and escalation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 21, 2026, 01:24 PM
Security Audit — agent-trust-hub — path-traversal-lfi