Php Thinkphp Audit
0xShe/PHP-Code-Audit-Skill
ThinkPHP 框架特效安全审计工具。针对 ThinkPHP 常见的鉴权/CSRF/模板转义/ORM 写入(Mass Assignment)/调试与配置暴露等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/TPL/XSS/LOGIC/CFG/SESS/SQL 等)。
Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.
$ npx skills add uphiago/recon-skills --skill error-log-mining -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install uphiago/recon-skills error-log-mining --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/error-log-mining .claude/skills/error-log-mining && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "error-log-mining" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/error-log-mining into .claude/skills/error-log-mining/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "error-log-mining", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/uphiago/recon-skills/tree/main/recon/error-log-miningType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add uphiago/recon-skills --skill error-log-mining -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install uphiago/recon-skills error-log-mining --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/recon/error-log-mining .agents/skills/error-log-mining && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "error-log-mining" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/error-log-mining into .agents/skills/error-log-mining/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "error-log-mining", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add uphiago/recon-skills --skill error-log-mining -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install uphiago/recon-skills error-log-mining --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/recon/error-log-mining .cursor/skills/error-log-mining && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "error-log-mining" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/error-log-mining into .cursor/skills/error-log-mining/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "error-log-mining", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/uphiago/recon-skills.git --path recon/error-log-mining--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add uphiago/recon-skills --skill error-log-mining -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install uphiago/recon-skills error-log-mining --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/recon/error-log-mining .gemini/skills/error-log-mining && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "error-log-mining" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/error-log-mining into .gemini/skills/error-log-mining/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "error-log-mining", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install uphiago/recon-skills error-log-miningInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add uphiago/recon-skills --skill error-log-mining -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/recon/error-log-mining .github/skills/error-log-mining && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "error-log-mining" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/error-log-mining into .github/skills/error-log-mining/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "error-log-mining", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add uphiago/recon-skills --skill error-log-mining -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install uphiago/recon-skills error-log-mining --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/recon/error-log-mining .opencode/skills/error-log-mining && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "error-log-mining" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/error-log-mining into .opencode/skills/error-log-mining/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "error-log-mining", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
error-log-miningMine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.
Error Log Mining is an agent skill from uphiago/recon-skills. Mine errorlog for creds, paths, SQL when leak hunt finds.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/mine_error_log.py`). Compatibility notes: Requires curl, grep, python3
It sits in Security, covering SQL. It works with SQL and PHP. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
curlpython3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DB_PASSWORDAUTH_KEYSECURE_AUTH_KEYLOGGED_IN_KEYNONCE_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires curl, grep, python3
From compatibility in the SKILL.md frontmatter.
Error Log Mining loads about 3.3k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 405 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 405 words, ~3,332 tokens.
.claude/skills/error-log-mining/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Discover and analyze exposed PHP error_log files for server paths, database
errors, SQL fragments, API-key candidates, email addresses, and internal
addresses. Collect a bounded sample and validate the sensitivity of its content
instead of inferring impact from file size or status.
deep-invade Phase 2 on a high-value target.skill_view(name='source-leak-hunt') found an error_log file with HTTP 200.display_errors possibly enabled.terminal with curl, grep, and python3.curl -r for range requests on large files.TARGET="https://example.com"
# Paths to probe
for path in "error_log" "wp-content/debug.log" "debug.log" "errors.log" \
"php_errors.log" "wp-content/error.log" "logs/error.log"; do
code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 5 --connect-timeout 5 "$TARGET/$path")
[[ "$code" == "200" ]] && echo "FOUND: $TARGET/$path"
done
# Download and analyze
curl --max-time 30 --connect-timeout 10 -sk "$TARGET/error_log" -o error_log.txt
python3 analyze_log.py error_log.txt| Extraction Target | Python regex | Value |
|---|---|---|
| Server paths | re.findall(r'/home/[^\s:)]+', txt) | Full directory structure |
| Email addresses | re.findall(r'[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}', txt) | Admin emails |
| DB credentials | DB_USER[^=]*=[\s'\"]*([^'\";\s]+) DB_PASSWORD[^=]*=[\s'\"]*([^'\";\s]+) DB_HOST[^=]*=[\s'\"]*([^'\";\s]+) DB_NAME[^=]*=[\s'\"]*([^'\";\s]+) | Database access |
| API keys | sk-[a-zA-Z0-9]{20,60} AIza[0-9A-Za-z_-]{35} AKIA[0-9A-Z]{16} eyJ[a-zA-Z0-9_-]{10,}\.[a-zA-Z0-9_-]{10,}\.[a-zA-Z0-9_-]{10,} | Stripe, Google, AWS, JWT |
| SQL queries | (?:SELECT|INSERT|UPDATE|DELETE|CREATE TABLE|ALTER TABLE)[^;]{0,300} | DB schema, table names |
| WordPress salts | (?:AUTH_KEY|SECURE_AUTH_KEY|LOGGED_IN_KEY|NONCE_KEY|AUTH_SALT|SECURE_AUTH_SALT|LOGGED_IN_SALT|NONCE_SALT)[^,;]+ | Session hijack potential |
| PHP error types | Counter(re.findall(r'PHP\s+\w+:', txt)).most_common(10) | Error breakdown |
| Date range | re.findall(r'\[(\d{2}-\w{3}-\d{4})', txt) | Log freshness |
TARGET="$1"
OUTDIR="$OUTDIR/error_logs/$TARGET"
mkdir -p "$OUTDIR"
echo "[*] Probing common error log paths on $TARGET..."
ERROR_LOG_PATHS=(
"error_log"
"wp-content/debug.log"
"debug.log"
"errors.log"
"php_errors.log"
"wp-content/error.log"
"logs/error.log"
"log/error.log"
"tmp/php-errors.log"
"wp-content/plugins/debug.log"
"wp-content/themes/debug.log"
)
FOUND_LOGS=()
for path in "${ERROR_LOG_PATHS[@]}"; do
code=$(curl -sk -o /dev/null -w "%{http_code}" --max-time 5 --connect-timeout 5 "https://$TARGET/$path" 2>/dev/null)
if [[ "$code" == "200" ]]; then
# Quick content check to avoid SPA false positives
sample=$(curl -sk --max-time 5 --connect-timeout 5 -r 0-500 "https://$TARGET/$path" 2>/dev/null)
if echo "$sample" | grep -qiE 'PHP|Error|Warning|Stack trace|\[[0-9]{2}-[A-Za-z]{3}-[0-9]{4}'; then
echo "[FOUND] https://$TARGET/$path"
FOUND_LOGS+=("https://$TARGET/$path")
fi
fi
sleep 0.3
done
echo "[+] Found ${#FOUND_LOGS[@]} error log(s)"TARGET="$1"
OUTDIR="$OUTDIR/error_logs/$TARGET"
for url in "${FOUND_LOGS[@]}"; do
fname=$(echo "$url" | sed 's|https\?://||' | sed 's|/|_|g')
echo "[*] Downloading $url..."
# First, check file size
size=$(curl -skI --max-time 10 --connect-timeout 10 "$url" 2>/dev/null | grep -i "content-length" | awk '{print $2}' | tr -d '\r')
if [[ -n "$size" && "$size" -gt 10000000 ]]; then
echo " Large file (${size} bytes) — sampling first 5MB..."
curl -sk --max-time 30 --connect-timeout 10 -r 0-5000000 "$url" -o "$OUTDIR/${fname}_sample.txt" 2>/dev/null
elif [[ -n "$size" && "$size" -gt 1000000 ]]; then
echo " Medium file (${size} bytes) — downloading full..."
curl -sk --max-time 30 --connect-timeout 10 "$url" -o "$OUTDIR/${fname}.txt" 2>/dev/null
else
echo " Small file — downloading full..."
curl -sk --max-time 15 --connect-timeout 10 "$url" -o "$OUTDIR/${fname}.txt" 2>/dev/null
fi
sleep 0.5
doneTARGET="$1"
OUTDIR="$OUTDIR/error_logs/$TARGET"
for logfile in "$OUTDIR"/*.txt "$OUTDIR"/*_sample.txt; do
[[ ! -f "$logfile" ]] && continue
echo ""
echo "═══════════ $(basename "$logfile") ═══════════"
echo ""
# 1. Server Paths
echo "[SERVER PATHS]"
grep -Eo '(/[a-zA-Z0-9_/.-]+\.php)' "$logfile" 2>/dev/null | sort -u | head -20
# 2. Email Addresses
echo ""
echo "[EMAIL ADDRESSES]"
grep -Eo '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}' "$logfile" 2>/dev/null | sort -u | head -15
# 3. Database Credentials
echo ""
echo "[DB CREDENTIALS & CONNECTIONS]"
grep -iE 'mysql_connect|mysqli_connect|new PDO|pg_connect|DB_HOST|DB_USER|DB_PASSWORD|DB_NAME|database.*password|dsn.*mysql' "$logfile" 2>/dev/null | head -10
# 4. SQL Queries
echo ""
echo "[SQL QUERIES]"
grep -iE '(SELECT|INSERT|UPDATE|DELETE|CREATE TABLE|ALTER TABLE|DROP TABLE).*(FROM|INTO|SET)' "$logfile" 2>/dev/null | head -10
# 5. API Keys & Tokens
echo ""
echo "[API KEYS & TOKENS]"
grep -iE 'api[_-]?key|api[_-]?secret|access[_-]?token|auth[_-]?token|bearer [A-Za-z0-9_\-]{20,}|sk-[A-Za-z0-9]{20,}|key=[A-Za-z0-9]{20,}' "$logfile" 2>/dev/null | head -10
# 6. Internal IPs
echo ""
echo "[INTERNAL IPs]"
grep -Eo '(?:10\.|172\.(?:1[6-9]|2[0-9]|3[01])\.|192\.168\.)\d{1,3}\.\d{1,3}' "$logfile" 2>/dev/null | sort -u | head -10
# 7. WordPress specific
echo ""
echo "[WORDPRESS PATHS]"
grep -Eo '/wp-content/(?:plugins|themes|uploads)/[a-zA-Z0-9_/.-]+' "$logfile" 2>/dev/null | sort -u | head -15
# 8. PHP Error Summary
echo ""
echo "[ERROR SUMMARY]"
echo " Fatal errors: $(grep -ci 'Fatal error' "$logfile" 2>/dev/null || echo 0)"
echo " Warnings: $(grep -ci 'Warning' "$logfile" 2>/dev/null || echo 0)"
echo " Notices: $(grep -ci 'Notice' "$logfile" 2>/dev/null || echo 0)"
echo " Parse errors: $(grep -ci 'Parse error' "$logfile" 2>/dev/null || echo 0)"
echo " Deprecated: $(grep -ci 'Deprecated' "$logfile" 2>/dev/null || echo 0)"
echo " Stack traces: $(grep -ci 'Stack trace' "$logfile" 2>/dev/null || echo 0)"
# 9. Date Range
echo ""
echo "[DATE RANGE]"
first=$(grep -Eo '\[[0-9]{2}-[A-Za-z]{3}-[0-9]{4} [0-9]{2}:[0-9]{2}:[0-9]{2}[^\]]*\]' "$logfile" 2>/dev/null | head -1)
last=$(grep -Eo '\[[0-9]{2}-[A-Za-z]{3}-[0-9]{4} [0-9]{2}:[0-9]{2}:[0-9]{2}[^\]]*\]' "$logfile" 2>/dev/null | tail -1)
[[ -n "$first" ]] && echo " First: $first"
[[ -n "$last" ]] && echo " Last: $last"
# 10. Plugin/Theme Names from Paths
echo ""
echo "[PLUGINS FROM ERRORS]"
grep -Eo '/wp-content/plugins/\K[a-zA-Z0-9_-]+' "$logfile" 2>/dev/null | sort -u | head -20
echo ""
echo "[THEMES FROM ERRORS]"
grep -Eo '/wp-content/themes/\K[a-zA-Z0-9_-]+' "$logfile" 2>/dev/null | sort -u | head -10
sleep 0.3
doneTARGET="$1"
OUTDIR="$OUTDIR/error_logs/$TARGET"
SUMMARY="$OUTDIR/intel_summary.md"
cat > "$SUMMARY" << EOF
# Error Log Intelligence — $TARGET
## Credentials Found
EOF
for logfile in "$OUTDIR"/*.txt "$OUTDIR"/*_sample.txt; do
[[ ! -f "$logfile" ]] && continue
# DB credentials
grep -iE 'DB_HOST|DB_USER|DB_PASSWORD|DB_NAME' "$logfile" 2>/dev/null | while read -r line; do
echo "- $line" >> "$SUMMARY"
done
# API keys
grep -iE 'api[_-]?key.*=|api[_-]?secret.*=|access[_-]?token.*=' "$logfile" 2>/dev/null | while read -r line; do
echo "- $line" >> "$SUMMARY"
done
done
echo "" >> "$SUMMARY"
echo "## Server Paths" >> "$SUMMARY"
grep -Eo '/[a-zA-Z0-9_/.-]+\.php' "$OUTDIR"/*.txt 2>/dev/null | sort -u | head -30 | while read -r line; do
echo "- $line" >> "$SUMMARY"
done
echo "" >> "$SUMMARY"
echo "## Email Addresses" >> "$SUMMARY"
grep -Eo '[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}' "$OUTDIR"/*.txt 2>/dev/null | sort -u | while read -r line; do
echo "- $line" >> "$SUMMARY"
done
echo "" >> "$SUMMARY"
echo "## Plugins Discovered" >> "$SUMMARY"
grep -Eo '/wp-content/plugins/\K[a-zA-Z0-9_-]+' "$OUTDIR"/*.txt 2>/dev/null | sort -u | while read -r line; do
echo "- $line" >> "$SUMMARY"
done
echo ""
echo "[+] Intelligence summary saved to $SUMMARY"# Does error log reveal the DB name? Cross-ref with wp-config leak
DB_NAME=$(grep -Eo 'DB_NAME["\x27\s:=]+["\x27][a-zA-Z0-9_]+' $OUTDIR/error_logs/*/intel_summary.md 2>/dev/null)
echo "DB name from logs: $DB_NAME"
# Does it reveal internal hostnames?
HOSTNAMES=$(grep -Eo '(?:[a-zA-Z0-9-]+\.(?:internal|local|lan|corp|priv))' $OUTDIR/error_logs/*/*.txt 2>/dev/null | sort -u)
[[ -n "$HOSTNAMES" ]] && echo "Internal hostnames:" && echo "$HOSTNAMES"
# Are there file inclusion paths that indicate LFI potential?
LFI_PATHS=$(grep -Eo '(?:include|require|include_once|require_once)\s*\(\s*[\x27"]([^\x27"]+\.php)' $OUTDIR/error_logs/*/*.txt 2>/dev/null | sort -u)
[[ -n "$LFI_PATHS" ]] && echo "Potential LFI paths:" && echo "$LFI_PATHS"import re
from collections import Counter
def mine_error_log(txt):
results = {}
# Server paths
results['paths'] = sorted(set(re.findall(r'/home/[^\s:)]+', txt)))[:20]
# Email addresses
results['emails'] = sorted(set(re.findall(r'[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}', txt)))[:20]
# DB credentials (4 patterns extracted from php error context)
db_creds = set()
for pat in [r"DB_USER[^=]*=[\s'\"]*([^'\";\s]+)",
r"DB_PASSWORD[^=]*=[\s'\"]*([^'\";\s]+)",
r"DB_HOST[^=]*=[\s'\"]*([^'\";\s]+)",
r"DB_NAME[^=]*=[\s'\"]*([^'\";\s]+)"]:
for m in re.findall(pat, txt): db_creds.add(m)
results['db_creds'] = sorted(db_creds)
# API keys (5 pattern classes — all extracted from error context)
api_keys = set()
for pat in [r'sk-[a-zA-Z0-9]{20,60}', # Stripe
r'AIza[0-9A-Za-z_-]{35}', # Google
r'AKIA[0-9A-Z]{16}', # AWS IAM
r'pk_[a-zA-Z0-9]+', # Publishable keys
r'eyJ[a-zA-Z0-9_-]{10,}\.[a-zA-Z0-9_-]{10,}\.[a-zA-Z0-9_-]{10,}']: # JWT
for m in re.findall(pat, txt): api_keys.add(m)
results['api_keys'] = sorted(api_keys)[:10]
# SQL queries
results['sql_queries'] = re.findall(
r'(?:SELECT|INSERT|UPDATE|DELETE|CREATE TABLE|ALTER TABLE)[^;]{0,300}',
txt, re.I)[:10]
# WordPress salts (session hijack potential)
results['wp_salts'] = re.findall(
r"(?:AUTH_KEY|SECURE_AUTH_KEY|LOGGED_IN_KEY|NONCE_KEY|AUTH_SALT|SECURE_AUTH_SALT|LOGGED_IN_SALT|NONCE_SALT)[^,;]+",
txt)
# Error type breakdown
results['error_types'] = Counter(re.findall(r'PHP\s+\w+:', txt)).most_common(10)
# Date range
dates = re.findall(r'\[(\d{2}-\w{3}-\d{4})', txt)
if dates:
results['date_range'] = f"{dates[0]} to {dates[-1]} ({len(set(dates))} unique dates)"
return resultsContent-Length before downloading
and use a bounded range such as curl -r 0-5000000 for an initial sample.error_log.1, error_log.old, error_log-YYYYMMDD)./error_log might be a custom 404 page or SPA catch-all. Always check content for PHP + error type pattern before analyzing.[date] PHP Warning:, Stack trace:, Fatal error:) to be valid./home/user/public_html/).© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (scripts) in recon/error-log-mining of uphiago/recon-skills.
Open the folder on GitHubat commit 1260244
Error Log Mining next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Error Log Mining this skilluphiago/recon-skills | 1.3k | — | ~3.3k | Automated safety check: Pass | MIT | |
| Php Thinkphp Audit0xShe/PHP-Code-Audit-Skill | 402 | 1 repos | ~779 | Automated safety check: Pass | None | |
| Geoflowyaojingang/GEOFlow | 3.8k | — | ~722 | Automated safety check: Pass | AGPL-3.0 | |
| Php Codeigniter Audit0xShe/PHP-Code-Audit-Skill | 402 | 1 repos | ~477 | Automated safety check: Pass | None | |
| WebMuWinds/BUUCTF_Agent | 267 | — | ~463 | Automated safety check: Pass | Apache-2.0 | |
| Python Reviewliuyanghejerry/Clausura | 204 | — | ~164 | Automated safety check: Pass | MIT |
0xShe/PHP-Code-Audit-Skill
ThinkPHP 框架特效安全审计工具。针对 ThinkPHP 常见的鉴权/CSRF/模板转义/ORM 写入(Mass Assignment)/调试与配置暴露等机制进行白盒静态审计,并映射到通用漏洞类型体系(AUTH/CSRF/TPL/XSS/LOGIC/CFG/SESS/SQL 等)。
yaojingang/GEOFlow
Operate/develop GEOFlow CLI/Laravel/admin/API, topics/专题 and topic tasks, theme libraries/replication, sites/leads/Agent, channel sync and legacy yao-geoflow-cli/design/template migration.
0xShe/PHP-Code-Audit-Skill
CodeIgniter 框架特效安全审计工具。针对 CodeIgniter 的 CSRF、XSS 输出过滤、数据库查询构造、路由与验证器配置、会话 Cookie 安全等机制进行白盒静态审计,并映射到通用漏洞类型体系(CSRF/AUTH/XSS/SQL/CFG/SESS 等)。
MuWinds/BUUCTF_Agent
Web 安全攻防技术,包括 SQL 注入、XSS、文件上传、命令注入、SSRF、反序列化等常见漏洞的识别与利用. An agent skill from MuWinds/BUUCTF_Agent.
liuyanghejerry/Clausura
Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura.
hostinger/api-mcp-server
Move an existing website from another host to Hostinger web hosting (Shared, Cloud or Agency plans) without downtime: WordPress sites from a files archive and SQL dump, static and PHP sites from an…
uphiago/recon-skills
Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.
uphiago/recon-skills
Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints
uphiago/recon-skills
A skill your agent uses when starting or restructuring an authorized external web and API assessment.
uphiago/recon-skills
Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect
uphiago/recon-skills
A skill your agent uses when protected HTTP routes return 401 or 403.
uphiago/recon-skills
Map organization IP infrastructure via ASN, CIDR, TLD expansion, and reverse DNS.
Categories
Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills. Error Log Mining is an agent skill from uphiago/recon-skills. Mine errorlog for creds, paths, SQL when leak hunt finds.
Error Log Mining fits situations like: tasks that involve SQL.
Run `npx skills add uphiago/recon-skills --skill error-log-mining -a claude-code`. Or copy the skill folder (recon/error-log-mining in uphiago/recon-skills) into .claude/skills/error-log-mining in your project. Claude Code loads it when a task matches its description.
Run `npx skills add uphiago/recon-skills --skill error-log-mining -a codex`. Or copy the skill folder (recon/error-log-mining in uphiago/recon-skills) into .agents/skills/error-log-mining in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill error-log-mining -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/error-log-mining, .gemini/skills/error-log-mining, .github/skills/error-log-mining and .opencode/skills/error-log-mining in your project.
Going by SKILL.md and its folder, Error Log Mining needs Python for the scripts in its folder, the command-line tools its instructions call (curl and python3) and credentials named DB_PASSWORD, AUTH_KEY, SECURE_AUTH_KEY and LOGGED_IN_KEY. Our summary lists: Python 3; A credential in AUTH_KEY; A credential in SECURE_AUTH_KEY. Compatibility (from SKILL.md): Requires curl, grep, python3.
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Error Log Mining is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Error Log Mining: Php Thinkphp Audit (0xShe/PHP-Code-Audit-Skill, 402 stars), Geoflow (yaojingang/GEOFlow, 3.8k stars), Php Codeigniter Audit (0xShe/PHP-Code-Audit-Skill, 402 stars) and Web (MuWinds/BUUCTF_Agent, 267 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,294 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.
Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.