file-access-vuln
๐ฏSkillfrom yaklang/hack-skills
Installation
npx vibeindex add yaklang/hack-skills --skill file-access-vulnnpx skills add yaklang/hack-skills --skill file-access-vuln~/.claude/skills/file-access-vuln/SKILL.mdSecurity category skill that routes AI agents to file upload, download, LFI, and path control vulnerability testing techniques, serving as an entry point for file operation security assessments.
Same repository
yaklang/hack-skills(102 items)
SKILL.md
More from this repository10
A comprehensive security skills knowledge base covering 14 domains including web security, API security, privilege escalation, Active Directory attacks, reverse engineering, and cryptography, built for penetration testing, CTF competitions, and authorized security research.
Security skill providing comprehensive SQL injection attack playbooks covering union-based, blind, error-based, and time-based SQLi techniques with database-specific payloads for penetration testing and CTF competitions.
A deep-topic security skill covering code obfuscation and deobfuscation techniques including control flow flattening, opaque predicates, string encryption, and analysis of obfuscation tools such as OLLVM, Themida, and VMProtect with automated deobfuscation workflows.
A curated security skills knowledge base covering 14 domains โ including mobile security, web/API security, privilege escalation, Active Directory attacks, binary exploitation, and AI/ML security โ organized as 100 deep-topic skills for penetration testing, bug bounty, and CTF competitions.
Category router skill from the HACK.SKILLS security arsenal that directs AI agents to specialized API security testing skills covering REST, GraphQL, and mobile backend attack surfaces.
Security knowledge skill covering XSS attack techniques including polyglot payloads, vendor-specific WAF bypasses (Cloudflare, Akamai, Incapsula, WordFence), CSP bypass, DOM clobbering, and CSS injection data exfiltration.
Security knowledge skill providing a reconnaissance methodology framework including Java middleware fingerprint matrix and leak detection checklists for the information-gathering phase of security testing.
Security knowledge skill covering SSRF attack techniques including cloud metadata exploitation across 6 platforms, DNS rebinding, headless browser attacks, and Gopher/Redis RCE chains, from the HACK.SKILLS arsenal.
A security skill for API reconnaissance and documentation analysis, covering API endpoint discovery, OpenAPI/Swagger specification analysis, and techniques for finding hidden or undocumented endpoints.
Security skill covering business logic vulnerability testing including race conditions, pricing manipulation, workflow bypass, and state machine attacks for penetration testing and authorized security research.