Agent skill

File Access Vuln

by yaklang in yaklang/hack-skills

Entry P1 category router for file access and upload workflows.

MITAuto-check passed

Install File Access Vuln

skills CLI
$ npx skills add yaklang/hack-skills --skill file-access-vuln -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yaklang/hack-skills file-access-vuln --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yaklang/hack-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/file-access-vuln .claude/skills/file-access-vuln && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
file-access-vuln
GitHub stars
2.4k
Token cost
~368 tokens
SKILL.md length
140 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
MIT

At a glance

Entry P1 category router for file access and upload workflows.

  • Works in 3 steps: First identify whether the entry point… → Then locate whether the issue appears in… → Small path-chain and upload-bypass…
  • Testing download endpoints
  • SKILL.md covers When to Use, Skill Map, Recommended Flow and Related Categories
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

File Access Vuln is an agent skill from yaklang/hack-skills. Entry P1 category router for file access and upload workflows. Use when testing download endpoints, file paths, local file inclusion, upload flows, preview pipelines, archive extraction, or storage and sharing boundaries.

Its SKILL.md is about 370 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Helping AI Agent become an awesome practical hacker! The licence is MIT.

When your agent uses it

  • Testing download endpoints
  • Local file inclusion
  • Preview pipelines
  • Archive extraction

Example prompts

  • “/file-access-vuln”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. First identify whether the entry point is a path parameter, download endpoint, or upload workflow
  2. Then locate whether the issue appears in accept, store, process, or serve stages
  3. Small path-chain and upload-bypass samples are merged into the main topic skills; no separate payload entry is needed

What it can do on your machine

Read from SKILL.md and the folder at commit 6fbf0bc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

File Access Vuln loads about 368 tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 140 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~368

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yaklang/hack-skills at commit 6fbf0bc, republished under its MIT licence (© yaklang). 140 words, ~368 tokens.

Download SKILL.mdSave it as .claude/skills/file-access-vuln/SKILL.md (or your agent's skills folder).
name
file-access-vuln
description
Entry P1 category router for file access and upload workflows. Use when testing download endpoints, file paths, local file inclusion, upload flows, preview pipelines, archive extraction, or storage and sharing boundaries.

File Access Router

This is the routing entry point for filesystem paths, download endpoints, upload pipelines, and file preview handling.

When to Use

  • Parameters, filenames, download endpoints, or import flows influence file paths
  • The target supports upload, preview, transcoding, extraction, sharing, download, or proxied file access
  • You need to decide whether this is path traversal/LFI or an upload-validation/processing-chain issue

Skill Map

  • Path Traversal LFI: path traversal, file read, wrapper abuse, include chains
  • Upload Insecure Files: upload validation, storage paths, processing chains, overwrite risk, preview/share boundaries
  1. First identify whether the entry point is a path parameter, download endpoint, or upload workflow
  2. Then locate whether the issue appears in accept, store, process, or serve stages
  3. Small path-chain and upload-bypass samples are merged into the main topic skills; no separate payload entry is needed

© yaklang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/file-access-vuln of yaklang/hack-skills.

Open the folder on GitHubat commit 6fbf0bc

Compare with similar skills

File Access Vuln next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

File Access Vuln compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
File Access Vuln this skillyaklang/hack-skills2.4k—~368Automated safety check: PassMIT
File Uploadsdavila7/claude-code-templates33k4 repos~238Automated safety check: PassMIT
File Upload Accessibilitythedaviddias/Front-End-Checklist74k—~418Automated safety check: PassMIT
Router Onweave-os/router5.6k—~169Automated safety check: PassApache-2.0
Router Offweave-os/router5.6k—~183Automated safety check: PassApache-2.0
Acp Routeropenclaw/openclaw392k—~2.4kAutomated safety check: PassMIT

Similar skills

  • File Uploads

    davila7/claude-code-templates

    Expert at handling file uploads and cloud storage. An agent skill from davila7/claude-code-templates.

    33k GitHub starsUsed in 4 repos~238 tokens
    Backend & APIsAuto-check passed
  • File Upload Accessibility

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing templates, rendered HTML, or shared components related to Make file uploads accessible.

    74k GitHub stars~418 tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Router On

    weave-os/router

    Route Codex through the Weave Router again (turn it back on).

    5.6k GitHub stars~169 tokensUpdated today
    Auto-check passed
  • Router Off

    weave-os/router

    Route Codex to its default provider again (turn the Weave Router off).

    5.6k GitHub stars~183 tokensUpdated today
    Auto-check passed
  • Acp Router

    openclaw/openclaw

    Route plain-language requests for Claude Code, Cursor, Copilot, OpenClaw ACP, OpenCode, Gemini CLI, Qwen, Kiro, Kimi, iFlow, Factory Droid, Kilocode, or explicit ACP harness work into either…

    392k GitHub stars~2.4k tokensUpdated today
    Writing & ContentAuto-check passed
  • Upload R2

    remotion-dev/remotion

    Official

    Upload large Remotion repository assets to the Cloudflare R2 bucket behind remotion.media and replace local public/ assets with hosted URLs.

    63k GitHub stars~535 tokensUpdated today
    Media & CreativeAuto-check: notes

More from yaklang/hack-skills

All 27 skills in this repo
  • Anti Debugging Techniques

    yaklang/hack-skills

    Anti-debugging detection and bypass playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~3.4k tokensUpdated 26 days ago
    Auto-check passed
  • API Auth And JWT Abuse

    yaklang/hack-skills

    API authentication and JWT abuse playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~567 tokensUpdated 26 days ago
    Auto-check passed
  • API Authorization And Bola

    yaklang/hack-skills

    API authorization and BOLA testing playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~449 tokensUpdated 26 days ago
    Auto-check passed
  • API Recon And Docs

    yaklang/hack-skills

    API reconnaissance and documentation review playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~456 tokensUpdated 26 days ago
    Auto-check passed
  • Attack Surface Mapping

    yaklang/hack-skills

    Draw a testable attack surface from one authorized target URL or one application.

    2.4k GitHub stars~2.6k tokensUpdated 26 days ago
    Auto-check passed
  • Classical Cipher Analysis

    yaklang/hack-skills

    Classical cipher analysis playbook. An agent skill from yaklang/hack-skills.

    2.4k GitHub stars~4.8k tokensUpdated 26 days ago
    Auto-check passed

Questions about File Access Vuln

What does File Access Vuln do?

Entry P1 category router for file access and upload workflows. File Access Vuln is an agent skill from yaklang/hack-skills. Entry P1 category router for file access and upload workflows.

When should I use File Access Vuln?

File Access Vuln fits situations like: testing download endpoints; local file inclusion; preview pipelines; archive extraction.

How do I install File Access Vuln in Claude Code?

Run `npx skills add yaklang/hack-skills --skill file-access-vuln -a claude-code`. Or copy the skill folder (skills/file-access-vuln in yaklang/hack-skills) into .claude/skills/file-access-vuln in your project. Claude Code loads it when a task matches its description.

How do I install File Access Vuln in Codex?

Run `npx skills add yaklang/hack-skills --skill file-access-vuln -a codex`. Or copy the skill folder (skills/file-access-vuln in yaklang/hack-skills) into .agents/skills/file-access-vuln in your project. Codex loads it when a task matches its description.

Can I use File Access Vuln in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaklang/hack-skills --skill file-access-vuln -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/file-access-vuln, .gemini/skills/file-access-vuln, .github/skills/file-access-vuln and .opencode/skills/file-access-vuln in your project.

What does File Access Vuln need to run?

SKILL.md names no scripts, command-line tools or credentials: File Access Vuln is instructions for the agent only.

Does File Access Vuln access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is File Access Vuln safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does File Access Vuln use?

File Access Vuln is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does File Access Vuln use?

About 368 tokens (SKILL.md is roughly 1.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to File Access Vuln?

Skills that share tags, products or a category with File Access Vuln: File Uploads (davila7/claude-code-templates, 33k stars), File Upload Accessibility (thedaviddias/Front-End-Checklist, 74k stars), Router On (weave-os/router, 5.6k stars) and Router Off (weave-os/router, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains File Access Vuln?

yaklang (a GitHub organization) maintains it in yaklang/hack-skills, which has 2,418 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on September 13, 2026.

Source: yaklang/hack-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.