Summary
- PHP 源码文件操作类漏洞审计。当在 PHP 白盒审计中需要检测文件相关漏洞时触发。
- 覆盖 5 类文件风险: 任意文件上传(类型绕过/路径穿越/二次渲染)、任意文件读取(include/fread/路径穿越)、
- 任意文件写入(日志注入/配置覆盖)、文件系统竞争(TOCTOU/符号链接)、归档提取漏洞(Zip…
wgpsec/aboutsecurity
npx skills add https://github.com/wgpsec/aboutsecurity
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
>- Audits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege esc…
111K installsAudit a website's SEO with Firecrawl. Use when the user asks for an SEO audit, metadata and hea…
31.6K installsAudits Python + BigQuery pipelines for cost safety, idempotency, and production readiness. Retu…
8.8K installsSecurity audit of a codebase — web apps, APIs, services, CLI tools, libraries, daemons, and mor…
5.4K installsAnalyze a repository to generate recommended Claude Code settings.json permissions. Use when se…
3.9K installsOther skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
master