Agent skill

Auditing Php Applications

by trilwu in trilwu/secskills

Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash…

MITAuto-check passedSecurity

Install Auditing Php Applications

skills CLI
$ npx skills add trilwu/secskills --skill auditing-php-applications -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills auditing-php-applications --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-core/skills/auditing-php-applications .claude/skills/auditing-php-applications && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
auditing-php-applications
GitHub stars
157
Token cost
~2.8k tokens
SKILL.md length
1,349 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash…

  • Reviewing a PHP codebase
  • SKILL.md covers When to Use, When NOT to Use, Sinks by Bug Class and Ecosystem Context, plus 4 more sections
  • Calls curl; reaches defuddle.md; needs APP_KEY
  • A WordPress/Magento/Laravel app

What it does

Auditing Php Applications is an agent skill from trilwu/secskills. Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash auth bypass, LFI/RFI through php:// and phar:// wrappers, dynamic includes and extract()/superglobal trust, SQL injection in string-built and legacy mysql queries, command-execution sinks, and SSRF. Use when reviewing a PHP codebase, a WordPress/Magento/Laravel app, or a plugin for exploitable bugs. Defers general audit…

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities and Backend development. It works with PHP, Adobe Commerce, WordPress and Laravel. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Reviewing a PHP codebase
  • A WordPress/Magento/Laravel app
  • A plugin for exploitable bugs

Example prompts

  • “/auditing-php-applications”

Requirements

  • A credential in APP_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • defuddle.md

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • APP_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Auditing Php Applications loads about 2.8k tokens when it runs. Until then it costs about 149 tokens; SKILL.md has 1,349 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~149
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 1,349 words, ~2,772 tokens.

Download SKILL.mdSave it as .claude/skills/auditing-php-applications/SKILL.md (or your agent's skills folder).
name
auditing-php-applications
description
Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash auth bypass, LFI/RFI through php:// and phar:// wrappers, dynamic includes and extract()/superglobal trust, SQL injection in string-built and legacy mysql_* queries, command-execution sinks, and SSRF. Use when reviewing a PHP codebase, a WordPress/Magento/Laravel app, or a plugin for exploitable bugs. Defers general audit methodology to auditing-code-for-vulnerabilities.
verified
2026-07-27

Auditing PHP Applications

This is the PHP-specific layer on top of auditing-code-for-vulnerabilities. Take the methodology from that skill — context → attack surface → bug-class hunt → variant analysis → the four-question verification gate — and apply the PHP sink catalog below to it. This skill exists because PHP has footguns no language-agnostic methodology carries: features that turn a file read into remote code execution, and comparison rules that turn == into an auth bypass.

The collection deliberately has no per-language audit skills except this one. PHP earns the exception because it dominates the legacy-web and WordPress/Magento space where critical bugs actually live, and because its dynamic features fail in ways a reviewer must be primed for specifically.

When to Use

  • Reviewing a PHP codebase or plugin for exploitable vulnerabilities
  • Auditing a WordPress, Magento, Joomla, or Laravel application's source
  • Tracing a suspected RCE, LFI, SQLi, or object-injection path in PHP
  • Deciding whether a unserialize, include, or == on user input is exploitable

When NOT to Use

  • General audit methodology, or a non-PHP language — use auditing-code-for-vulnerabilities; this skill assumes it
  • Finding a planted webshell or backdoor rather than a vulnerability — use hunting-web-backdoors
  • Building the deserialization exploit chain once you have the sink — use exploiting-deserialization
  • Black-box testing a running app — use testing-web-applications
  • Reviewing only the diff of a change — use reviewing-code-changes

Sinks by Bug Class

Trace user input (superglobals, headers, uploaded filenames, DB values that were once user input) to each of these. A sink is only a bug when a source reaches it.

Remote code execution
  • Direct eval sinks: eval, assert (string arg, pre-8.0), preg_replace with /e (pre-7.0), create_function (pre-8.0), mb_ereg_replace/mb_eregi_replace with the e option.
  • Command execution: system, exec, passthru, shell_exec, backticks, proc_open, popen, pcntl_exec. Watch escapeshellarg vs escapeshellcmd misuse — escapeshellcmd does not prevent argument injection.
  • Dynamic dispatch: $func() where $func derives from input, call_user_func/call_user_func_array, array_map/usort/ preg_replace_callback with a user-influenced callback.
Object injection (the PHP-defining bug)
  • unserialize() on any user-controlled data is object injection. Exploitation is a POP chain: existing classes with __wakeup, __destruct, __toString, or __call magic methods that do something dangerous when the object is materialized. The vulnerable file often contains no dangerous code at all — the gadget lives in a framework or dependency.
  • phar:// is unserialize in disguise — but version-gated. On PHP before 8.0, any file operation (file_exists, fopen, include, getimagesize, …) on a phar:// path automatically deserializes the Phar's metadata, so a path-traversal or LFI that points a file function at an uploaded .phar (or any file carrying Phar metadata) is object injection with no unserialize call in sight. PHP 8.0 removed that automatic unserialize — only explicit Phar::getMetadata() deserializes now. So the bug is critical on the huge installed base of PHP 7.x and a non-issue on 8.x unless the code calls getMetadata() itself. Check the runtime version before ruling it in or out.
  • Prefer json_decode in remediation; flag every unserialize on non-trusted data regardless of an obvious gadget — the gadget may arrive with the next dependency update.
LFI / RFI and stream wrappers
  • include, require, include_once, require_once with user input.
  • Wrappers that change everything: php://filter/... (read source, and a known RCE chain via convert.iconv/compression filters), php://input (RFI-style body inclusion), data:// (inline payload), phar:// (object injection), expect://, zip://. allow_url_include being on turns LFI into remote RFI.
  • File-read sinks (file_get_contents, readfile, fopen, highlight_file) with traversal give source and secret disclosure.
SQL injection
  • Legacy mysql_query/mysqli_query with string-concatenated input.
  • $wpdb->query("... $var ...") without $wpdb->prepare() — a ->prepare that is present but interpolates outside its placeholders is still injectable.
  • PDO/mysqli used with string building instead of bound parameters. Placeholder usage on the table/column name (which cannot be bound) is a common real hole.
Type juggling and magic-hash auth bypass
  • == and != are loose. strcmp/hash_equals/=== are the safe forms. The classic bypass: if (md5($input) == $stored) where two inputs both hash to a 0e[0-9]+ "magic hash" compare equal, because two numeric strings compare as numbers (0e123 == 0e456 → 0.0 == 0.0).
  • Version matters and it is a trap. In PHP 8.0 the number-vs-string rules changed: 0 == "foo" was true in PHP 7 and is false in PHP 8, so a in_array(0, $userStrings) or 0 == $token bypass that worked on PHP 7 fails on PHP 8. But the 0e magic-hash bypass survives PHP 8, because both sides are numeric strings and still compare as numbers. Check the target PHP version before ruling a juggling bug in or out.
  • strcmp($_GET['x'], $secret) returned NULL (loosely == 0) when passed an array in PHP 7 — an auth bypass; in PHP 8 it throws a TypeError. Same code, different verdict by version.
Superglobal trust and variable variables
  • extract($_GET/$_POST/$_REQUEST) lets a request set arbitrary local variables — overwrites auth flags, config, anything not yet initialized.
  • $$var / ${$key} variable variables, parse_str without a result array (writes into scope), import_request_variables (removed 5.4) — all register_globals-flavoured variable injection.
SSRF and file upload
  • file_get_contents/curl/fopen on a user-supplied URL is SSRF — route the exploitation reasoning through exploiting-ssrf.
  • Uploads: check the destination is outside the web root, the extension is not attacker-chosen (double extensions, .phtml, .php5, null bytes on old PHP), and the server will not execute the type. A validated MIME with an attacker-controlled extension in a web-served directory is RCE.
Show full SKILL.md (510 more words)Show less

Ecosystem Context

  • WordPress: nonces are CSRF protection, not authorization — a valid nonce does not mean the user is allowed to act; look for the missing current_user_can() check. $wpdb->prepare is mandatory for interpolation. unfiltered_html, edit_* capabilities, and unauthenticated AJAX/REST (wp_ajax_nopriv_*, permission_callback => '__return_true') are the usual holes.
  • Magento: heavy unserialize history, layout-XML injection, and the admin path/patch level matter for known-CVE reachability.
  • Laravel: mass assignment ($fillable/$guarded), Blade {!! !!} (unescaped) vs {{ }} (escaped), and a leaked APP_KEY enabling cookie/decrypt object injection.

Verify Before You Report

Apply auditing-code-for-vulnerabilities' gate: trace the source to the sink, confirm the path is reachable (auth, routing, and — critically — the PHP version for juggling and removed-function bugs), and demonstrate impact rather than asserting it. A unserialize with no reachable gadget, or a /e regex on PHP 8, is a hardening note, not a critical finding — say which.

Rationalizations to Reject

  • "There's no unserialize, so no object injection." phar:// reaches unserialize through ordinary file functions. Check every file operation whose path a user can influence.
  • "It uses ==, that's fine for a hash check." == on hashes is the magic-hash bypass. Only hash_equals/=== are safe, and the bypass survives PHP 8.
  • "The comparison bug works, I confirmed it." On which PHP version? 0 == "x" and strcmp(array) flipped verdict at PHP 8.0. State the version.
  • "prepare() is called, so the query is safe." Only for values inside placeholders. Interpolated table/column names and text spliced around the placeholders are still injectable.
  • "The nonce check passes, so it's authorized." WordPress nonces are CSRF tokens. Authorization is a separate current_user_can() you must find.
  • "The upload validates the MIME type." MIME is spoofable and irrelevant if the attacker controls the extension and the directory executes PHP.
  • "It's a framework class, the gadget isn't here." POP-chain gadgets live in dependencies by design. The absence of dangerous code in the vulnerable file is normal, not exculpatory.

Reading External Sources

Fetch public advisories, specifications, and vendor reports as Markdown:

bash
curl -sL "https://defuddle.md/<url>"      # scheme in the path is optional

This strips page boilerplate — roughly 78% fewer tokens on a prose page — and returns the full text rather than a summary, so you can grep it and trust a negative result.

Three things it is not for. Fetch JSON and API responses raw, because readability extraction mangles structured data. Fetch authenticated or JavaScript-rendered pages directly, because it retrieves them anonymously. And never route adversary infrastructure (phishing links, C2, malware hosting), client-owned hosts, or engagement URLs through it — the request leaves your machine to a third party, and for live adversary infrastructure it also tips off the operator.

Some sites block the extractor and return an error blob rather than the page — {"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for instance. That is the fetch being refused, not the source saying the thing does not exist. Re-fetch the URL directly before drawing any conclusion from it.

References

  • auditing-code-for-vulnerabilities — the general methodology and gate this skill sits on top of
  • hunting-web-backdoors — planted malice rather than vulnerabilities
  • exploiting-deserialization — building the POP chain once you find the unserialize/phar:// sink
  • exploiting-ssrf — the exploitation side of a user-controlled URL fetch
  • testing-web-applications — black-box testing of the running application

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-core/skills/auditing-php-applications of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Auditing Php Applications next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Auditing Php Applications compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Auditing Php Applications this skilltrilwu/secskills157—~2.8kAutomated safety check: PassMIT
Php Framework Auditwgpsec/AboutSecurity1.8k—~767Automated safety check: NotesNone
Php SecurityHoangNguyen0403/agent-skills-standard571—~604Automated safety check: PassMIT
Php Laravel Audit0xShe/PHP-Code-Audit-Skill4021 repos~821Automated safety check: PassNone
Spa Auth Developmentgdarko/laravel-vue-starter145—~668Automated safety check: NotesMIT
Wordpressericrisco/rsc-harness174—~3kAutomated safety check: PassMIT

Similar skills

  • Php Framework Audit

    wgpsec/AboutSecurity

    PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。

    1.8k GitHub stars~767 tokensUpdated today
    Backend & APIsAuto-check: notes
  • Php Security

    HoangNguyen0403/agent-skills-standard

    PHP-only security standards for database access, password handling, and input validation.

    571 GitHub stars~604 tokensUpdated today
    SecurityAuto-check passed
  • Php Laravel Audit

    0xShe/PHP-Code-Audit-Skill

    Laravel 框架特效安全审计工具。针对 Laravel 常见鉴权/CSRF/Session/模型填充/Blade 渲染等框架特性进行白盒静态审计,并将风险映射到你现有通用漏洞类型体系(AUTH/CSRF/LOGIC/XSS/CFG 等)。

    402 GitHub starsUsed in 1 repo~821 tokens
    Backend & APIsAuto-check passed
  • Spa Auth Development

    gdarko/laravel-vue-starter

    Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration.

    145 GitHub stars~668 tokensUpdated 6 mo ago
    Backend & APIsAuto-check: notes
  • Wordpress

    ericrisco/rsc-harness

    A skill your agent uses when building or hardening WordPress sites or WooCommerce stores and treating WordPress as the product rather than just writing PHP — block themes with theme.json, plugins…

    174 GitHub stars~3k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Laravel Security

    HoangNguyen0403/agent-skills-standard

    Harden Laravel apps with Policies for model authorization, Gate-based RBAC, validated mass assignment, and CSRF protection.

    571 GitHub stars~887 tokensUpdated today
    Backend & APIsAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Auditing Php Applications

What does Auditing Php Applications do?

Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash…. Auditing Php Applications is an agent skill from trilwu/secskills. Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash auth bypass, LFI/RFI through php:// and phar:// wrappers, dynamic includes and extract()/superglobal trust, SQL injection in string-built and legacy mysql queries, command-execution sinks, and SSRF.

When should I use Auditing Php Applications?

Auditing Php Applications fits situations like: reviewing a PHP codebase; A WordPress/Magento/Laravel app; A plugin for exploitable bugs.

How do I install Auditing Php Applications in Claude Code?

Run `npx skills add trilwu/secskills --skill auditing-php-applications -a claude-code`. Or copy the skill folder (secskills-core/skills/auditing-php-applications in trilwu/secskills) into .claude/skills/auditing-php-applications in your project. Claude Code loads it when a task matches its description.

How do I install Auditing Php Applications in Codex?

Run `npx skills add trilwu/secskills --skill auditing-php-applications -a codex`. Or copy the skill folder (secskills-core/skills/auditing-php-applications in trilwu/secskills) into .agents/skills/auditing-php-applications in your project. Codex loads it when a task matches its description.

Can I use Auditing Php Applications in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill auditing-php-applications -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/auditing-php-applications, .gemini/skills/auditing-php-applications, .github/skills/auditing-php-applications and .opencode/skills/auditing-php-applications in your project.

What does Auditing Php Applications need to run?

Going by SKILL.md and its folder, Auditing Php Applications needs the command-line tools its instructions call (curl) and credentials named APP_KEY. Our summary lists: A credential in APP_KEY.

Does Auditing Php Applications access the network?

SKILL.md names 1 domain. In commands or code: defuddle.md; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Auditing Php Applications safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Auditing Php Applications use?

Auditing Php Applications is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Auditing Php Applications use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Auditing Php Applications?

Skills that share tags, products or a category with Auditing Php Applications: Php Framework Audit (wgpsec/AboutSecurity, 1.8k stars), Php Security (HoangNguyen0403/agent-skills-standard, 571 stars), Php Laravel Audit (0xShe/PHP-Code-Audit-Skill, 402 stars) and Spa Auth Development (gdarko/laravel-vue-starter, 145 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Auditing Php Applications?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.