CLAUDE CODE MARKETPLACES
SkillsMarketplacesMCPDigestLearnJobsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Web & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web CrawlingAutomation & Workflows
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Learn
  • Feedback
  • Privacy Policy
  • Jobs
  • Advertise

Built for the Claude Code community with Claude Code by @mertduzgun

Independent project, not affiliated with Anthropic
  1. Skills
  2. /
  3. yaklang
  4. /
  5. hack-skills
  6. /
  7. Path Traversal Lfi

Path Traversal Lfi

Editor's Note

This is a thorough path traversal and LFI exploitation playbook that covers the full chain from basic directory traversal to remote code execution. It walks through encoding bypass techniques (URL, double-URL, overlong UTF-8), OS-specific targets like /proc/self/environ for credential leaks, and the critical PHP wrapper attacks using php://filter for source code extraction and php://input for RCE. The log poisoning section is especially useful, showing how to inject PHP into Apache logs via User-Agent headers then include them for execution. It also routes you to the ghost-bits-cast-attack skill when you're hitting Java backends where standard traversal sequences get blocked by WAFs. Good reference when you need to escalate from read-only file access to actual code execution.

Install

npx skills add https://github.com/yaklang/hack-skills --skill path-traversal-lfi
Votes
0
Installs514
GitHub Stars636
Categories
Backend & APIsTesting & QASecurityAI & Agent BuildingJava & JVMPHP & Laravel
First SeenMay 16, 2026
View on GitHub

Comments

Login to comment

Related Backend & APIs Skills

View all →
vercel-react-best-practices

vercel-labs/agent-skills

5
402.7k
26.6k
3
React and Next.js performance optimization guide with 64 prioritized rules across 8 categories.
azure-storage

microsoft/azure-skills

0
320.2k
964
Unified access to Azure blob storage, file shares, queues, tables, and data lake services.
entra-app-registration

microsoft/azure-skills

0
320k
964
Microsoft Entra ID app registration, OAuth 2.0 configuration, and MSAL integration for secure application authentication.
azure-resource-visualizer

microsoft/azure-skills

0
319.7k
964
Transform Azure resource groups into detailed architecture diagrams showing resource relationships and configurations.
azure-aigateway

microsoft/azure-skills

0
319.7k
964
Configure Azure API Management as an AI Gateway for models, MCP tools, and agents with built-in governance policies.
remotion-best-practices

remotion-dev/skills

0
312.3k
3.2k
Domain-specific knowledge base for building videos with Remotion and React.