Agent skill

Hunt Upload

by Encod3d-Sec in Encod3d-Sec/TORCH

File upload attack hunting - extension/content-type/magic-byte bypass to web-shell RCE, path traversal in filename, SVG/XML XSS, zip slip, and pixel-flood DoS.

MITAuto-check passedSecurity

Install Hunt Upload

skills CLI
$ npx skills add Encod3d-Sec/TORCH --skill hunt-upload -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Encod3d-Sec/TORCH hunt-upload --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Encod3d-Sec/TORCH.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt/hunt-upload .claude/skills/hunt-upload && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-upload
GitHub stars
329
Token cost
~1.2k tokens
SKILL.md length
532 words
Files
1
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

File upload attack hunting - extension/content-type/magic-byte bypass to web-shell RCE, path traversal in filename, SVG/XML XSS, zip slip, and pixel-flood DoS.

  • Works in 9 steps: Baseline: upload a valid file; note… → Extension bypass → Content-Type / magic-byte bypass: set… → …
  • Tasks that involve File uploads and storage
  • SKILL.md covers Wiki, Attack surface, Methodology and Evasion (when a layer rejects), plus 4 more sections
  • Calls python3

What it does

Hunt Upload is an agent skill from Encod3d-Sec/TORCH. File upload attack hunting - extension/content-type/magic-byte bypass to web-shell RCE, path traversal in filename, SVG/XML XSS, zip slip, and pixel-flood DoS. Wiki-first, FIND schema output.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering File uploads and storage and Web application vulnerabilities. The repository describes itself as: Karpathy LLM based claude harness for PenetrationTesting / Bugbounty using obsidian. The licence is MIT.

When your agent uses it

  • Tasks that involve File uploads and storage
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/hunt-upload”

Requirements

  • Python 3

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Baseline: upload a valid file; note stored path, returned URL, filename transformation, and whether it is reachable + executed by the…
  2. Extension bypass
  3. Content-Type / magic-byte bypass: set Content-Type: image/png; prepend real magic bytes (GIF89a;, \xFF\xD8\xFF JPEG, %PDF-) before the…
  4. Path traversal in filename: filename="../../../../var/www/html/shell.php" to escape the upload dir / overwrite files.
  5. SVG / XML: SVG with -> stored XSS ([[xss]]); SVG/XML with external entity -> [[xxe]] (file read/SSRF).
  6. Archive: zip-slip (../ paths inside zip) on extract; symlink in archive -> read host files.
  7. Image processing: ImageMagick/Ghostscript (ImageTragick CVE-2016-3714), pixel-flood DoS, EXIF payload executed by a downstream parser.
  8. Confirm by execution, through Burp. Request the uploaded shell in Burp Repeater (operator visibility) and run a command (?cmd=id); OOB…
  9. Distill (confirmed, generic): per hunt-core, python3 scripts/wiki-stage.py --kind technique --slug --target-page…

What it can do on your machine

Read from SKILL.md and the folder at commit d21b6c9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hunt Upload loads about 1.2k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 532 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Encod3d-Sec/TORCH at commit d21b6c9, republished under its MIT licence (© Encod3d-Sec). 532 words, ~1,227 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-upload/SKILL.md (or your agent's skills folder).
name
hunt-upload
description
File upload attack hunting - extension/content-type/magic-byte bypass to web-shell RCE, path traversal in filename, SVG/XML XSS, zip slip, and pixel-flood DoS. Wiki-first, FIND schema output.

Hunt: File Upload

Assumes hunt-core for the scope gate, two-account rule, confirmation gate, enumeration limits, stop conditions, wiki protocol, FIND output, and Deadends. Do not re-derive any of that here.

Wiki

qmd_query "file upload webshell extension content-type magic-byte bypass SVG XXE zip slip path traversal" via wiki-search MCP

Hub: [[web-moc]] (live index). Primary page: [[file-upload]]. Payload arsenal: wiki/payloads/file-upload.md. Anchors: [[path-traversal-lfi]].

Attack surface

Rank the sinks first - not every upload reaches code:

  • Avatar / profile / logo / signature fields - most common; frequently re-encoded, so check whether the original bytes are served back.
  • Document / CSV / XML import - parser sinks (XXE, formula injection, zip).
  • Ticket / message attachments - often served under the original name and type from a reachable path.
  • Image-processing (thumbnails -> ImageMagick/Ghostscript), SVG/PDF render, EXIF parsers - the processor is the bug, not the store.
  • Firmware / plugin / theme upload - direct code load; highest value when present.

Then attack in layers, cheapest first: extension -> content-type -> magic-byte -> parser/render.

Methodology

  1. Baseline: upload a valid file; note stored path, returned URL, filename transformation, and whether it is reachable + executed by the server.
  2. Extension bypass:
shell.php  shell.phtml  shell.php5  shell.phar  shell.pHp
shell.php.jpg   shell.jpg.php   shell.php%00.jpg   shell.php;.jpg
shell.php/   shell.php....   (trailing dot/space on Windows)
.htaccess  ->  AddType application/x-httpd-php .jpg   (then upload .jpg shell)
web.config (IIS)   .jsp/.jspx/.war (Java)   .asp/.aspx (IIS)
  1. Content-Type / magic-byte bypass: set Content-Type: image/png; prepend real magic bytes (GIF89a;, \xFF\xD8\xFF JPEG, %PDF-) before the payload; polyglot (valid image + PHP).
  2. Path traversal in filename: filename="../../../../var/www/html/shell.php" to escape the upload dir / overwrite files.
  3. SVG / XML: SVG with <script> -> stored XSS ([[xss]]); SVG/XML with external entity -> [[xxe]] (file read/SSRF).
  4. Archive: zip-slip (../ paths inside zip) on extract; symlink in archive -> read host files.
  5. Image processing: ImageMagick/Ghostscript (ImageTragick CVE-2016-3714), pixel-flood DoS, EXIF payload executed by a downstream parser.
  6. Confirm by execution, through Burp. Request the uploaded shell in Burp Repeater (operator visibility) and run a command (?cmd=id); OOB callback if blind. For traversal, fetch the written/read target back from the path you claimed it hit.
  7. Distill (confirmed, generic): per hunt-core, python3 scripts/wiki-stage.py --kind technique --slug <slug> --target-page techniques/web/file-upload.md.

Evasion (when a layer rejects)

Double extension (shell.php.jpg / shell.jpg.php), null byte (shell.php%00.jpg), content-type spoof (Content-Type: image/png on a script), magic-byte prefix (GIF89a; + payload), and case variation (.pHp, .PHtml). Combine them - a single-layer allowlist rarely survives extension + content-type + magic-byte applied together.

Show full SKILL.md (201 more words)Show less

Chaining

  • Upload -> web-shell RCE: once a shell executes, hand off hunt-rce for post-exploitation and CVE-specific escalation.
  • SVG/HTML -> stored XSS: hand off hunt-xss (marker discipline, blind-XSS beacon for a stored context).
  • SVG/XML/DOCX -> XXE: hand off hunt-injection (OOB-mandatory for blind XXE).

Confirmation gate

NOT confirmation: the upload was accepted; a 200 or a returned file URL; the file shows up in a listing; a stored path you have not fetched back; a script uploaded but never requested; a traversal filename accepted with nothing actually read or written outside the upload dir.

IS confirmation: the uploaded file executed as code - fetch it back and it runs your command (?cmd=id returns output) or fires an OOB callback when blind; or the traversal demonstrably wrote or read outside the upload dir, proven by fetching that target back. SVG/XML: the script fires in a victim context, or the external entity returns file contents / an OOB hit. Reproduce in a clean session.

Severity

CRITICAL if code execution; HIGH if stored XSS / XXE / arbitrary file write to a sensitive path; MEDIUM if upload of a dangerous type with no execution path proven.

Deadends

Append: - [ ] upload <host> <endpoint> -- ext+CT+magic+traversal all blocked; files re-encoded + served from CDN no-exec

Record which layers you cleared and which held, so the next pass does not retry them.

© Encod3d-Sec, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt/hunt-upload of Encod3d-Sec/TORCH.

Open the folder on GitHubat commit d21b6c9

Compare with similar skills

Hunt Upload next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Upload compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Upload this skillEncod3d-Sec/TORCH329—~1.2kAutomated safety check: PassMIT
File Path Traversal DetectionTencent/AI-Infra-Guard6.8k—~789Automated safety check: PassApache-2.0
Security Reviewtrycompai/comp2k—~853Automated safety check: PassAGPL-3.0
Server Sidetransilienceai/communitytools562—~484Automated safety check: PassMIT
Wp Security Reviewjorgerosal/wordpress-skills102—~6.4kAutomated safety check: PassMIT
Web Xxes0ld13rr/pentestcode828—~585Automated safety check: PassMIT

Similar skills

  • File Path Traversal Detection

    Tencent/AI-Infra-Guard

    Detect unsafe file handling and path traversal in upload/save/extract flows.

    6.8k GitHub stars~789 tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Review

    trycompai/comp

    Check code for the most common, high-risk security vulnerabilities (broken access control, tenant isolation, injection, secrets, SSRF, auth/session, unsafe file handling, mass assignment) before it…

    2k GitHub stars~853 tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Server Side

    transilienceai/communitytools

    Server-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection.

    562 GitHub stars~484 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Wp Security Review

    jorgerosal/wordpress-skills

    WordPress security code review and vulnerability detection. An agent skill from jorgerosal/wordpress-skills.

    102 GitHub stars~6.4k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Web Xxe

    s0ld13rr/pentestcode

    XML External Entity injection detection→file-read/SSRF→proof for web apps.

    828 GitHub stars~585 tokensUpdated 7 days ago
    Documents & OfficeAuto-check passed
  • Laravel Security

    affaan-m/ECC

    Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.

    276k GitHub starsUsed in 3 repos~2k tokens
    Backend & APIsAuto-check passed

More from Encod3d-Sec/TORCH

All 35 skills in this repo
  • Runs a bug-bounty engagement through a script that tracks the current pass, builds a board of rows from recon and prints the next required action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Checks that the bb, pt and ctf workflow driver is set up correctly on a machine: vault content, skill symlinks, hooks, imports and a live smoke test, with fixes for failures.

    329 GitHub stars~611 tokensUpdated 1 mo ago
    Auto-check passed
  • Opens a visible Chromium window on a Kali VM so an operator can complete a manual login or CAPTCHA while the agent watches and acts through the chrome-devtools MCP.

    329 GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • CTF Campaign Driver

    Encod3d-Sec/TORCH

    Runs a capture-the-flag box from first scan to root with a driver script that tracks progress and prints the next action each turn.

    329 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Decides when a main pentesting agent should hand a fully-specified, mechanical exploit-compile or privilege-escalation step to a cheaper sub-agent, and how to specify that handoff safely.

    329 GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check: notes
  • Adaptive Web Fuzzing

    Encod3d-Sec/TORCH

    Adaptive web fuzzing for pentests, bug bounty and CTF work: picks the smallest suitable SecLists wordlist per target surface and calibrates filters against soft-404 responses.

    329 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Hunt Upload

What does Hunt Upload do?

File upload attack hunting - extension/content-type/magic-byte bypass to web-shell RCE, path traversal in filename, SVG/XML XSS, zip slip, and pixel-flood DoS. Hunt Upload is an agent skill from Encod3d-Sec/TORCH. File upload attack hunting - extension/content-type/magic-byte bypass to web-shell RCE, path traversal in filename, SVG/XML XSS, zip slip, and pixel-flood DoS.

When should I use Hunt Upload?

Hunt Upload fits situations like: tasks that involve File uploads and storage; tasks that involve Web application vulnerabilities.

How do I install Hunt Upload in Claude Code?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-upload -a claude-code`. Or copy the skill folder (skills/hunt/hunt-upload in Encod3d-Sec/TORCH) into .claude/skills/hunt-upload in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Upload in Codex?

Run `npx skills add Encod3d-Sec/TORCH --skill hunt-upload -a codex`. Or copy the skill folder (skills/hunt/hunt-upload in Encod3d-Sec/TORCH) into .agents/skills/hunt-upload in your project. Codex loads it when a task matches its description.

Can I use Hunt Upload in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Encod3d-Sec/TORCH --skill hunt-upload -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-upload, .gemini/skills/hunt-upload, .github/skills/hunt-upload and .opencode/skills/hunt-upload in your project.

What does Hunt Upload need to run?

Going by SKILL.md and its folder, Hunt Upload needs the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Hunt Upload access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Hunt Upload safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hunt Upload use?

Hunt Upload is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Upload use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Upload?

Skills that share tags, products or a category with Hunt Upload: File Path Traversal Detection (Tencent/AI-Infra-Guard, 6.8k stars), Security Review (trycompai/comp, 2k stars), Server Side (transilienceai/communitytools, 562 stars) and Wp Security Review (jorgerosal/wordpress-skills, 102 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Upload?

Encod3d-Sec (a GitHub user) maintains it in Encod3d-Sec/TORCH, which has 329 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on September 1, 2026.

Source: Encod3d-Sec/TORCH on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.