path-traversal-lfi
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFEDATA_EXFILTRATIONOBFUSCATIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADS
Full Analysis
- [CREDENTIALS_UNSAFE]: The playbook targets high-value sensitive files including password hashes in
/etc/shadow, SSH private keys in~/.ssh/id_rsa, and cloud provider credentials in~/.aws/credentials. - [DATA_EXFILTRATION]: Provides specific instructions for reading
/proc/self/environto extract environment variables, which often contain application secrets, database passwords, and API keys. - [OBFUSCATION]: Details multiple techniques for bypassing security controls, including double URL encoding, overlong UTF-8 sequences, and the 'Ghost Bits' attack which uses Unicode homoglyphs (阮 and 阯) to masquerade as path delimiters (dots and slashes).
- [REMOTE_CODE_EXECUTION]: Outlines detailed methodologies for achieving code execution through Local File Inclusion (LFI). This includes poisoning web server access logs, SSH authentication logs, and mail logs with PHP payloads, as well as exploiting PHP wrappers like
php://inputanddata://. - [COMMAND_EXECUTION]: Instructs on the use of several offensive security tools such as
ajpShooter.pyfor Ghostcat exploitation,php_filter_chain_generator.pyfor filter-based RCE, andiis_shortname_scanner.jarfor Windows environment enumeration. - [PROMPT_INJECTION]: The skill uses an
AI LOAD INSTRUCTIONblock to programmatically define the agent's behavior as an 'Expert Attack Playbook,' potentially influencing the agent's response patterns towards offensive actions. - [PRIVILEGE_ESCALATION]: Describes escalation paths from initial file read capabilities to full system compromise and root access through the extraction of sensitive system files.
- [EXTERNAL_DOWNLOADS]: Mentions and provides examples for fetching remote shells and malicious packages from attacker-controlled domains (e.g.,
attacker.com) viapearcmdand Remote File Inclusion (RFI).
Audit Metadata