phy-path-traversal-auditPath traversal and Local File Inclusion (LFI) vulnerability scanner (OWASP A01:2021). Detects user-controlled paths passed to file system sinks in Python/Jav...
Install via ClawdBot CLI:
clawdbot install phy041/phy-path-traversal-auditGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdCalls external URL not in known-safe list
https://canlah.aiAudited Sep 7, 2026 · audit v1.0
Generated Sep 7, 2026
A security consultant audits a client's web application for path traversal vulnerabilities. They use the skill to scan the codebase, identify risky file handling, and provide recommendations and safe code snippets to remediate issues.
A DevOps engineer integrates the skill into a CI/CD pipeline to automatically scan code changes for path traversal vulnerabilities. This ensures that any new code merged into the repository is checked for security issues before deployment.
A maintainer of an open-source project uses the skill to perform a security review of contributions, scanning for path traversal flaws in file handling code across multiple languages to maintain the project's security posture.
A trainer uses the skill to demonstrate path traversal vulnerabilities in their secure coding bootcamp. Students can run scans on sample code to see how vulnerabilities are detected and learn how to apply the suggested safe guards.
A security team within a government agency uses the skill to assess custom-built applications for path traversal vulnerabilities, ensuring compliance with security standards and protecting sensitive data from unauthorized access.
Offer the skill as part of a SaaS platform where developers can scan their repositories. Users pay a subscription fee based on the number of scans or the size of the team.
Security consulting firms use the skill to deliver comprehensive path traversal audits as a paid service. They charge per project or hourly, and the skill speeds up the analysis.
The skill is integrated into existing developer tools (e.g., IDE plugins or Git hooks) and sold as a premium feature. Users pay a one-time license fee or an annual maintenance fee.
💬 Integration Tip
Integrate the skill into CI/CD workflows or code editors to automatically scan for path traversal vulnerabilities at commit time. Provide results in a machine-readable format to facilitate quick remediation.
Scored Sep 7, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...