path-traversal-lfi
Warn
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXFILTRATION]: The skill identifies and encourages the access of highly sensitive files including
/etc/shadow, SSH private keys (~/.ssh/id_rsa), AWS credential files (~/.aws/credentials), and application environment files (.env) containing API keys and database passwords. - [REMOTE_CODE_EXECUTION]: Provides comprehensive methodologies for achieving Remote Code Execution through LFI vulnerabilities, such as log poisoning (Apache/Nginx/SSH), session file poisoning, and exploiting PHP wrappers like
php://input,data://, andphar://. - [COMMAND_EXECUTION]: Includes executable command patterns for injecting PHP payloads via SSH and utilizing various Python-based exploit tools for generating filter chains and triggering AJP vulnerabilities.
- [EXTERNAL_DOWNLOADS]: References multiple third-party exploitation tools and repositories, including
ajpShooter,php_filter_chain_generator, andcnext-exploits, to facilitate advanced attack stages. - [PROMPT_INJECTION]: Contains instructions directed at the AI agent to adopt an 'Expert' persona and prioritize techniques that bypass standard safety filters and 'base model' limitations regarding encoding and escalation.
Audit Metadata