CkSKILLS: Skill for Claude Code

.agents/skills/file-handling/SKILL.md

file-handling is a skill for Claude Code, Codex from zhaji2333/CkSKILLS. It costs 111 tokens per session (1,550 once invoked), scanned C, original, MIT.

A security-testing guide for file uploads, downloads, previews, imports, archives, and other features that read or write files.

In plain words
What is it for?
Use it during authorized testing of upload forms, file-export endpoints, document or media processing, archive tools, and user-controlled file paths.
Why use it?
It helps identify unsafe filename handling, path traversal, file-type checks, archive extraction, and processing of formats such as PDFs, images, or spreadsheets.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: installed under .agents/ (shared by several agents).

This is zhaji2333/CkSKILLS's own configuration. It tells Claude Code and Codex how to work on CkSKILLS itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything CkSKILLS configures →

Reuse

Borrowing it

Nothing to install: this file belongs to zhaji2333/CkSKILLS. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/zhaji2333/CkSKILLS/main/.agents/skills/file-handling/SKILL.md
Clone the repo
git clone --depth 1 https://github.com/zhaji2333/CkSKILLS

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for file-handling

README.md
[![agentmods](https://agentmods.dev/badge/skills/zhaji2333/ckskills/file-handling/github.svg)](https://agentmods.dev/skills/zhaji2333/ckskills/file-handling)
Your own site
<a href="https://agentmods.dev/skills/zhaji2333/ckskills/file-handling"><img src="https://agentmods.dev/badge/skills/zhaji2333/ckskills/file-handling/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for file-handling

Your own site · 80×15
<a href="https://agentmods.dev/skills/zhaji2333/ckskills/file-handling"><img src="https://agentmods.dev/badge/skills/zhaji2333/ckskills/file-handling.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 111 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,550 The whole file, excluding the scripts and references it only reads on demand.
Security scan C 1 finding. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00111 $0.01550
Opus 5 $0.00056 $0.00775
Sonnet 5 $0.00022 $0.00310
Haiku 4.5 $0.00011 $0.00155

Measured 10d ago against content hash 18081ed3e44a, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade C, and why

file-handling scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reaches for credential fileshighPrivilege escalation

SSH keys, cloud credentials, git-credentials, .npmrc, /etc/shadow: reading these is how a config file becomes a credential leak.

- /etc/passwd、/etc/shadow(读权限)
.agents/skills/file-handling/SKILL.md · 120 lines

How it starts

The opening of the file, as written. The whole thing — 120 lines — stays where its author put it; the contents beside it link to each section on GitHub.

file-handling — 文件与路径安全专项深度挖掘

何时调用(触发条件)

  • 文件上传:头像/附件/证件/导入文件
  • 文件下载/导出:报表、日志、备份
  • 文件预览/处理:PDF/Office、图片裁剪缩放、音视频处理
  • 压缩包处理:在线解压/打包
  • 文件路径参数可控:filename、path、file、template
  • 在线编辑器/IDE、终端/Shell 模拟、数据库查询工具

一、文件操作类场景表(全景)

场景 漏洞类型 挖掘要点
文件上传(头像/附件/证件) 任意文件上传→getshell 后缀绕过、MIME绕过、内容检测绕过、二次渲染绕过
文件下载/导出 任意文件读取/路径穿越 ../遍历、绝对路径、编码绕过、符号链接
文件预览(PDF/Office) SSRF/XXE/RCE 远程URL加载、OLE对象、宏执行
文件导入(Excel/CSV/XML) XXE/CSV注入/公式注入/反序列化 =cmd、外部实体、恶意序列化数据
图片处理(裁剪/缩放/水印) ImageMagick RCE/SSRF MVG/SVG payload、url:协议
视频/音频处理 FFmpeg SSRF/文件读取 concat协议、file://、HLS playlist
压缩包处理(解压/打包) 路径穿越/Zip Slip/符号链接 ../覆盖关键文件、软链接读取
日志下载/审计导出 敏感信息泄露/路径穿越 日志中含token/密码、文件名可控

二、漏洞类型全景

类型 场景 挖掘要点
F1. 任意文件上传 头像、附件、导入 类型/扩展名/内容校验
F2. 路径穿越 下载接口、模板加载 ../规范化检查
F3. 任意文件读取/删除 导出报表、缓存处理 路径白名单
F4. 文件包含(LFI/RFI) 动态include php://filter等协议

三、文件上传绕过技术

扩展名:.php5/.phtml/.phar/.htaccess/.user.ini
双扩展:shell.php.jpg / shell.jpg.php
%00截断:shell.php%00.jpg
内容:GIF89a头、图片马

进阶绕过思路:

  • MIME 类型伪造(Content-Type 改为 image/png)
  • 内容检测绕过:图片马 + 二次渲染差异注入
  • 解析差异:nginx 解析漏洞、Apache 多后缀、IIS 分号截断
  • 上传点复用:头像路径 → 包含执行 / 路径可控覆盖
  • .user.ini / .htaccess 覆盖

四、路径穿越与任意文件读写

测试向量:

../ 、 ..%2f 、 %252e%252e%252f 、 ..%c0%af
绝对路径:/etc/passwd、C:\Windows\win.ini
编码:Unicode(\u002e\u002e/)、十六进制、双重编码
符号链接:上传软链接指向敏感文件

验证目标:

  • /etc/passwd、/etc/shadow(读权限)
  • 应用配置文件(数据库密码、AK/SK)
  • 源码文件(.py/.java/.php/.jar)
  • 删除接口:任意文件删除 → 配合 getshell/持久化

五、文件处理引擎攻击

ImageMagick

  • MVG/SVG payload、url: 协议(SSRF)
  • 已知 CVE:ImageTragick 系列

FFmpeg

  • concat 协议、file:// 读取
  • HLS playlist 注入

Office/PDF 预览

  • 宏执行、OLE 对象(RCE)
  • 外部实体(XXE)

压缩包

  • Zip Slip:解压路径穿越覆盖关键文件
  • 符号链接:解压软链接读取任意文件
  • Zip 炸弹:DoS

导入文件

  • CSV 公式注入:=cmd+HYPERLINK
  • XML/Office:XXE
  • 反序列化对象(.ser/.bin)

六、特殊功能类扩展

场景 漏洞类型 挖掘要点
在线解压/打包 路径穿越/DoS Zip炸弹、符号链接攻击
在线编辑器/IDE 任意文件读写/RCE 文件路径可控、代码执行
终端/Shell模拟 命令注入/逃逸 命令过滤绕过、沙箱逃逸
数据库查询工具 SQL注入/越权 查询语句可控、连接信息泄露

Read the full file on GitHub · 120 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 10d ago First seen · 120 lines · 111 tokens per session scan C 18081ed3e44a

Subscribe to this mod's changes

file-handling is a skill published in the GitHub repository zhaji2333/CkSKILLS (80 stars, last pushed 9d ago), licensed MIT. It adds 111 tokens to every session and 1,550 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it C with 1 finding (reaches for credential files). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other skills, from other repositories

new

Create a new project to start development quickly.

clacky-ai/openclacky · 10 tokens

winui-setup

Install and verify the prerequisites the win-dev-skills WinUI 3 toolchain depends on — .NET SDK 8.0.100+, WinApp CLI 0.6+, and Developer Mode. Use only when the user explicitly asks to set up or repair the toolchain. Do not invoke automatically when another skill reports a missing prerequisite; tell the user what is…

microsoft/win-dev-skills · 88 tokens

winui-wpf-migration

Migrate WPF applications to WinUI 3 — namespace replacement (System.Windows → Microsoft.UI.Xaml), control mapping (DataGrid→ListView, WrapPanel→ItemsRepeater, TabControl→TabView), threading (Dispatcher→DispatcherQueue), imaging (System.Drawing→BitmapImage), MVVM conversion to CommunityToolkit.Mvvm, and…

microsoft/win-dev-skills · 100 tokens

xcode-compilation-analyzer

Analyze Swift and mixed-language compile hotspots using build timing summaries and Swift frontend diagnostics, then produce a recommend-first source-level optimization plan. Use when a developer reports slow compilation, type-checking warnings, expensive clean-build compile phases, long CompileSwiftSources tasks…

AvdLee/Xcode-Build-Optimization-Agent-Skill · 74 tokens

cli-builder

Build production-quality CLIs with language detection and a five-step approval-gated workflow. Use when wrapping an existing module or app. Don't use for GUI/TUI apps, web APIs, or one-off shell scripts.

luongnv89/skills · 46 tokens

rails-dev

Opinionated Rails conventions: rich models, concerns, CRUD-everything, state-as-records, minimal dependencies, Minitest with fixtures. Load this skill BEFORE any code-level thinking, not only before editing a file. It is required the moment a task touches Rails code in ANY way: designing or even just discussing a data…

tech-leads-club/agent-skills · 199 tokens