CtrlK
BlogDocsLog inGet started
Tessl Logo

file-path-traversal

This skill should be used when the user asks to "test for directory traversal", "exploit path traversal vulnerabilities", "read arbitrary files through web applications", "find LFI vulnerabilities", or "access files outside web root". It provides comprehensive file path traversal attack and testing methodologies.

58

Quality

66%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/file-path-traversal/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, technique-rich body with copy-paste payloads, tool commands, and both exploit and remediation code — its command coverage is essentially complete. Its weaknesses are verbosity (it explains traversal fundamentals and HTTP/filesystem prerequisites Claude already knows, and duplicates payload/target listings in a Quick Reference) and a total absence of progressive disclosure: ~480 lines of catalogs inlined into SKILL.md with no reference files.

Suggestions

Move the Phase 5-6 target-file catalogs, the encoding-variant tables, and the Quick Reference into references/ files (e.g. references/linux-targets.md, references/windows-targets.md, references/payloads.md) and keep a 10-20 line overview plus one-line links in SKILL.md.

Delete or compress the padding Claude doesn't need: the 'Attack principle' bullets, the 'Impact' prose, the Prerequisites section (HTTP structure, filesystem layout), and the Quick Reference tables that duplicate Phases 3-6.

Add explicit validation checkpoints between steps, e.g. 'Confirm a hit by checking the response for `root:x:0:0` before proceeding to escalation', and wire the Troubleshooting table entries back to the phase where each failure occurs.

DimensionReasoningScore

Conciseness

The ~480-line body repeatedly explains concepts Claude already knows — 'Path traversal occurs when applications use user input to construct file paths', '`../` sequence moves up one directory', prerequisite lists like 'HTTP request/response structure' and 'Linux and Windows filesystem layout'. It is also internally redundant: the Quick Reference tables (payloads, target files, encoding variants) restate material already given in Phases 3-6. This matches anchor 2 ('noticeably verbose; several unnecessary explanations or padded sections'); it is above 1 because the payload/command content itself is dense rather than padded prose, but below 3 because the padding and duplication are substantial, not incidental.

2 / 5

Actionability

The content is copy-paste ready throughout: concrete curl invocations with payloads, runnable ffuf/wfuzz command lines with real wordlist paths (LFI-Jhaddix.txt), null-byte/encoding/Unicode bypass payloads, PHP wrapper URLs, and working prevention code in both PHP and Python. The common cases (Linux and Windows targets, GET parameters, cookie-based templates, automation, RCE escalation) are all covered with specific examples. It barely misses nothing executable — the Burp Suite section is numbered GUI steps and Phase 9 is comment-style methodology, but these are inherently instructional and concrete.

5 / 5

Workflow Clarity

The skill is organized as a clear ten-phase pipeline (understand → identify traversal points → basic exploitation → bypasses → Linux/Windows targets → automation → RCE escalation → methodology → prevention), and Phase 9 restates it as an ordered 8-step testing sequence. Most checkpoints are present: Burp filtering 'by size/content for success', ffuf `-mc 200`, wfuzz `--hc 404`, and a Troubleshooting table with failure→remedy mappings. It falls short of 5 because verification of a successful read (e.g., confirming `root:` lines for /etc/passwd) is left implicit rather than stated as an explicit validation step. The batch-fuzzing operations do carry response filters, so the batch-operation cap at 3 is not triggered.

4 / 5

Progressive Disclosure

There is no references/ directory at all — the entire catalog lives inline in a single ~480-line SKILL.md, including large target-file listings (Phases 5-6), payload tables, and encoding variants that clearly belong in separate reference files loaded on demand. Section headers and tables do provide real structure, which lifts it above anchor 2 ('no section headers, content inlined'), but it squarely matches anchor 3: structure exists, yet content that should be split into reference files is inline and nothing is offloaded. It cannot score 4+ because there are no well-signaled one-level-deep references to move detail behind.

3 / 5

Total

14

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solidly functional description with excellent explicit 'use when' trigger phrasing covering the natural terminology (directory/path traversal, LFI, arbitrary file read). Its weakness is the capability clause, which leans on the vague over-claim 'comprehensive ... methodologies' instead of enumerating the concrete testing actions the skill actually provides.

Suggestions

Replace 'It provides comprehensive file path traversal attack and testing methodologies' with 3-4 concrete capabilities, e.g. 'Identifies traversal-susceptible parameters, tests encoding and filter-bypass payloads, and escalates LFI to RCE via log poisoning and PHP wrappers'.

Add the spelled-out synonym 'local file inclusion' alongside 'LFI' so the trigger matches users who don't know the acronym.

DimensionReasoningScore

Specificity

The description names the domain ('file path traversal attack and testing') and a couple of concrete actions via its trigger phrases ('test for directory traversal', 'read arbitrary files through web applications'), but the capability clause itself is generic and over-claiming ('provides comprehensive ... methodologies') without enumerating what the skill actually does (e.g., identify traversal parameters, bypass filters, escalate LFI to RCE). It sits between anchor 2 (domain named, minimal actions) and anchor 4 (several specific actions listed) — the triggers gesture at actions but the 'what' is vague, so it lands at 3. It does not reach 4 because no distinct concrete capabilities are stated; it is above 2 because the quoted trigger phrases do name real, testable actions.

3 / 5

Completeness

Both halves are present: an explicit 'This skill should be used when...' clause with five concrete trigger phrases, and a 'what' statement ('It provides comprehensive file path traversal attack and testing methodologies'). It does not merit 5 because the 'what' half is buzzword-adjacent ('comprehensive ... methodologies') rather than concretely stating capabilities; it is comfortably above 3 because the 'when' is explicit and the 'what' names the domain and activity type.

4 / 5

Trigger Term Quality

Natural terms users would actually say are well covered: "test for directory traversal", "exploit path traversal vulnerabilities", "find LFI vulnerabilities", "read arbitrary files through web applications", "access files outside web root". It falls short of anchor 5's 'comprehensive coverage including synonyms and file extensions' because 'local file inclusion' is only present as the acronym 'LFI', and variants like 'dot-dot-slash' or 'LFI' spelled out are missing. It clearly exceeds anchor 3 ('some relevant keywords, missing common variations') since both full phrases and the common acronym appear.

4 / 5

Distinctiveness Conflict Risk

The niche is clear — web file path traversal / LFI — with distinct trigger phrases that would not fire for unrelated skills. Minor overlap risk remains with closely related web-security skills (e.g., general web vulnerability scanning or file-upload testing), since 'read arbitrary files through web applications' is broad enough to collide with adjacent skills. Not 5 (some overlap risk with sibling web-exploitation skills); not 3 (the LFI/traversal vocabulary is quite specific).

4 / 5

Total

15

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
zebbern/claude-code-guide
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.