Borrowing it
Nothing to install: this file belongs to zhaji2333/CkSKILLS. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/zhaji2333/CkSKILLS/main/.agents/skills/file-handling/SKILL.mdgit clone --depth 1 https://github.com/zhaji2333/CkSKILLSWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zhaji2333/ckskills/file-handling)<a href="https://agentmods.dev/skills/zhaji2333/ckskills/file-handling"><img src="https://agentmods.dev/badge/skills/zhaji2333/ckskills/file-handling/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zhaji2333/ckskills/file-handling"><img src="https://agentmods.dev/badge/skills/zhaji2333/ckskills/file-handling.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00111 | $0.01550 |
| Opus 5 | $0.00056 | $0.00775 |
| Sonnet 5 | $0.00022 | $0.00310 |
| Haiku 4.5 | $0.00011 | $0.00155 |
Grade C, and why
file-handling scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Reaches for credential fileshighPrivilege escalation
SSH keys, cloud credentials, git-credentials, .npmrc, /etc/shadow: reading these is how a config file becomes a credential leak.
- /etc/passwd、/etc/shadow(读权限) How it starts
The opening of the file, as written. The whole thing — 120 lines — stays where its author put it; the contents beside it link to each section on GitHub.
file-handling — 文件与路径安全专项深度挖掘
何时调用(触发条件)
- 文件上传:头像/附件/证件/导入文件
- 文件下载/导出:报表、日志、备份
- 文件预览/处理:PDF/Office、图片裁剪缩放、音视频处理
- 压缩包处理:在线解压/打包
- 文件路径参数可控:filename、path、file、template
- 在线编辑器/IDE、终端/Shell 模拟、数据库查询工具
一、文件操作类场景表(全景)
| 场景 | 漏洞类型 | 挖掘要点 |
|---|---|---|
| 文件上传(头像/附件/证件) | 任意文件上传→getshell | 后缀绕过、MIME绕过、内容检测绕过、二次渲染绕过 |
| 文件下载/导出 | 任意文件读取/路径穿越 | ../遍历、绝对路径、编码绕过、符号链接 |
| 文件预览(PDF/Office) | SSRF/XXE/RCE | 远程URL加载、OLE对象、宏执行 |
| 文件导入(Excel/CSV/XML) | XXE/CSV注入/公式注入/反序列化 | =cmd、外部实体、恶意序列化数据 |
| 图片处理(裁剪/缩放/水印) | ImageMagick RCE/SSRF | MVG/SVG payload、url:协议 |
| 视频/音频处理 | FFmpeg SSRF/文件读取 | concat协议、file://、HLS playlist |
| 压缩包处理(解压/打包) | 路径穿越/Zip Slip/符号链接 | ../覆盖关键文件、软链接读取 |
| 日志下载/审计导出 | 敏感信息泄露/路径穿越 | 日志中含token/密码、文件名可控 |
二、漏洞类型全景
| 类型 | 场景 | 挖掘要点 |
|---|---|---|
| F1. 任意文件上传 | 头像、附件、导入 | 类型/扩展名/内容校验 |
| F2. 路径穿越 | 下载接口、模板加载 | ../规范化检查 |
| F3. 任意文件读取/删除 | 导出报表、缓存处理 | 路径白名单 |
| F4. 文件包含(LFI/RFI) | 动态include | php://filter等协议 |
三、文件上传绕过技术
扩展名:.php5/.phtml/.phar/.htaccess/.user.ini
双扩展:shell.php.jpg / shell.jpg.php
%00截断:shell.php%00.jpg
内容:GIF89a头、图片马
进阶绕过思路:
- MIME 类型伪造(Content-Type 改为 image/png)
- 内容检测绕过:图片马 + 二次渲染差异注入
- 解析差异:nginx 解析漏洞、Apache 多后缀、IIS 分号截断
- 上传点复用:头像路径 → 包含执行 / 路径可控覆盖
- .user.ini / .htaccess 覆盖
四、路径穿越与任意文件读写
测试向量:
../ 、 ..%2f 、 %252e%252e%252f 、 ..%c0%af
绝对路径:/etc/passwd、C:\Windows\win.ini
编码:Unicode(\u002e\u002e/)、十六进制、双重编码
符号链接:上传软链接指向敏感文件
验证目标:
- /etc/passwd、/etc/shadow(读权限)
- 应用配置文件(数据库密码、AK/SK)
- 源码文件(.py/.java/.php/.jar)
- 删除接口:任意文件删除 → 配合 getshell/持久化
五、文件处理引擎攻击
ImageMagick
- MVG/SVG payload、
url:协议(SSRF) - 已知 CVE:ImageTragick 系列
FFmpeg
concat协议、file://读取- HLS playlist 注入
Office/PDF 预览
- 宏执行、OLE 对象(RCE)
- 外部实体(XXE)
压缩包
- Zip Slip:解压路径穿越覆盖关键文件
- 符号链接:解压软链接读取任意文件
- Zip 炸弹:DoS
导入文件
- CSV 公式注入:
=cmd、+HYPERLINK - XML/Office:XXE
- 反序列化对象(.ser/.bin)
六、特殊功能类扩展
| 场景 | 漏洞类型 | 挖掘要点 |
|---|---|---|
| 在线解压/打包 | 路径穿越/DoS | Zip炸弹、符号链接攻击 |
| 在线编辑器/IDE | 任意文件读写/RCE | 文件路径可控、代码执行 |
| 终端/Shell模拟 | 命令注入/逃逸 | 命令过滤绕过、沙箱逃逸 |
| 数据库查询工具 | SQL注入/越权 | 查询语句可控、连接信息泄露 |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 120 lines · 111 tokens per session scan C 18081ed3e44a
file-handling is a skill published in the GitHub repository zhaji2333/CkSKILLS (80 stars, last pushed 9d ago), licensed MIT. It adds 111 tokens to every session and 1,550 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it C with 1 finding (reaches for credential files). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
new
Create a new project to start development quickly.
winui-setup
Install and verify the prerequisites the win-dev-skills WinUI 3 toolchain depends on — .NET SDK 8.0.100+, WinApp CLI 0.6+, and Developer Mode. Use only when the user explicitly asks to set up or repair the toolchain. Do not invoke automatically when another skill reports a missing prerequisite; tell the user what is…
winui-wpf-migration
Migrate WPF applications to WinUI 3 — namespace replacement (System.Windows → Microsoft.UI.Xaml), control mapping (DataGrid→ListView, WrapPanel→ItemsRepeater, TabControl→TabView), threading (Dispatcher→DispatcherQueue), imaging (System.Drawing→BitmapImage), MVVM conversion to CommunityToolkit.Mvvm, and…
xcode-compilation-analyzer
Analyze Swift and mixed-language compile hotspots using build timing summaries and Swift frontend diagnostics, then produce a recommend-first source-level optimization plan. Use when a developer reports slow compilation, type-checking warnings, expensive clean-build compile phases, long CompileSwiftSources tasks…
cli-builder
Build production-quality CLIs with language detection and a five-step approval-gated workflow. Use when wrapping an existing module or app. Don't use for GUI/TUI apps, web APIs, or one-off shell scripts.
rails-dev
Opinionated Rails conventions: rich models, concerns, CRUD-everything, state-as-records, minimal dependencies, Minitest with fixtures. Load this skill BEFORE any code-level thinking, not only before editing a file. It is required the moment a task touches Rails code in ANY way: designing or even just discussing a data…