File Path Traversal Testing

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Credential file access detected All findings: [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] This skill is an offensive pentest guide for finding and exploiting path traversal and LFI bugs. It is technically accurate and internally consistent with its stated purpose of testing and exploitation. However it contains concrete, weaponizable instructions for remote code execution (log poisoning, PHP wrappers, expect://, etc.) and guidance to access extremely sensitive files. As a published skill, it poses a high abuse risk if used outside authorized testing: treat it as sensitive offensive content. There is no hidden obfuscation or automated exfiltration code present, but the operational instructions meaningfully lower the bar for attackers to exploit vulnerable targets. LLM verification: The skill is a high-fidelity, dual-use pentesting guide for path traversal/LFI. Its capabilities and payloads align with its stated purpose (BENIGN in intent for authorized testing) but the content is sensitive and can be readily abused if used without permission. There are no hidden network exfiltration endpoints or obfuscated payloads, and no direct credential harvesting code — however the omission of explicit legal/ethical guidance and the inclusion of highly sensitive targets increases misus

Confidence: 90%Severity: 80%
Audit Metadata
Analyzed At
Feb 16, 2026, 10:27 AM
Package URL
pkg:socket/skills-sh/jpropato%2Fsiba%2Ffile-path-traversal-testing%2F@70d44d1b13b7945cdf8817a6b3cad062ac8c704e