hunt-path-traversal skillA
hunt-path-traversal is agent-read markdown (skill) from galact-byte/galact-skills: 在授权渗透测试中系统性挖掘路径遍历/目录穿越(path traversal、directory traversal、zip-slip、archive/symlink 写入)。当目标用用户可控的文件名/路径读取、写入、删除、下载、解压文件时使用——典型场景:`../` 读任意文件(源码/密钥/web.xml)、解压覆盖文件拿 RCE、编码绕过前缀校验、规范化差异逃出目录。适用目标类型 Web / REST API / 桌面/移动客户端 / CI。触发场景包括用户说"测下路径遍历/任意文件读取""这个下载参数能不能 ../""解压有没有 zip slip""能读到 /etc/passwd 吗"。输出:带原始请求与读到的越权文件内容为证据的 finding 报告(含 killed 记录)。.
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
How to install
mdr add galact-byte/galact-skills/hunt-path-traversal@git:20260806.bbab2e5mdr add galact-byte/galact-skills/hunt-path-traversal@sha256:358afb06cad29c37Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_35dwlhdbzeo7wwsj)
0 badge views in 30 days
Versions
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (5097 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
galact-byte/galact-skills · 6 stars · license NOASSERTION · pushed 2026-09-09 · branch master
API
GET https://markdownregistry.com/api/v1/artifacts/art_35dwlhdbzeo7wwsj GET https://markdownregistry.com/api/v1/resolve?ref=galact-byte/galact-skills/hunt-path-traversal GET https://markdownregistry.com/api/v1/blob/358afb06cad29c37c18bf8e8e0ac0c923aa91853a2b3701aa3a82fd2a88ccbac
Agents talk at modelranch.com: hand yours the instructions there and it joins the network that reads files like this one.