Atlas / Skills / leoyeai / Phy Path Traversal Audit

Phy Path Traversal AuditSAFE

skills/leoyeai/phy-path-traversal-audit

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
1.0.0
Hosts
1 documented
License
MIT
Stars
2,160
01

Overview

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Read from source at commit 4f3b4a2a472eOBSERVED · 2026-10-08
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
openclawmentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: phy-path-traversal-audit
description: Path traversal and Local File Inclusion (LFI) vulnerability scanner (OWASP A01:2021). Detects user-controlled paths passed to file system sinks in Python/Java/PHP/Node.js/Go/Ruby without containment checks. Identifies missing os.path.abspath+startswith, realpath validation, basename stripping, and PHP include/require with user input. Outputs CWE-22/CWE-23 findings with HTTP taint analysis and per-language safe-path-handling code snippets. Zero competitors on ClawHub.
license: Apache-2.0
tags:
  - security
  - path-traversal
  - lfi
  - owasp
  - python
  - java
  - php
  - nodejs
  - go
  - ruby
metadata:
  author: PHY041
  version: "1.0.0"
---

# phy-path-traversal-audit

Static scanner for **OWASP A01:2021 — Broken Access Control / Path Traversal** (CWE-22) and **Local File Inclusion** (CWE-98). Finds file system sinks that accept user-controlled paths, checks for missing containment guards, and flags PHP `include`/`require` patterns that allow template injection. Zero external API calls, zero dependencies beyond Python 3 stdlib.

## What Is Path Traversal?

An attacker passes `../../etc/passwd` or `..%2F..%2Fetc%2Fshadow` as a filename parameter. Without validation, your code reads arbitrary files outside the intended base directory. With PHP `include`, it can lead to Remote Code Execution.

**Classic exploit:**
```
GET /api/files?path=../../etc/passwd HTTP/1.1
```
If your handler does `open("uploads/" + request.args["path"])`, attacker reads `/etc/passwd`.

## What It Detects

### Python
| Pattern | Severity | Notes |
|---------|----------|-------|
| `open(user_path)` | CRITICAL | Direct file read with user path |
| `open(os.path.join(base, user_input))` without `abspath`+`startswith` | HIGH | Join doesn't sanitize `../` |
| `pathlib.Path(user_path).read_text()` | CRITICAL | pathlib doesn't sanitize traversal |
| `Path(base).joinpath(user_input)` without `.resolve().is_relative_to(base)` | HIGH | |
| `os.listdir(user_path)` | HIGH | Directory listing disclosure |
| `os.open(user_path, os.O_RDONLY)` | CRITICAL | Low-level file open |
| `shutil.copy/move(user_src, ...)` | HIGH | File operation with user src |
| `tarfile.open(user_path)` | HIGH | Zip/tar slip (CVE-class) |
| `zipfile.ZipFile(user_path)` | HIGH | Zip slip attack |

### Java
| Pattern | Severity | Notes |
|---------|----------|-------|
| `new File(baseDir + userInput)` | CRITICAL | String concat without normalization |
| `new FileInputStream(userInput)` | CRITICAL | Direct file read |
| `Paths.get(userInput)` | HIGH | Path construction without validation |
| `Files.readAllBytes(Path.of(userInput))` | CRITICAL | File read |
| `Files.newBufferedReader(Paths.get(userInput))` | CRITICAL | File read |
| `new File(request.getServletContext().getRealPath(userInput))` | CRITICAL | Servlet path traversal |
| `response.setHeader("Content-Disposition", "..."+userInput)` | MEDIUM | Filename injection |

### PHP
| Pattern | Severity | Notes |
|---------|----------|-------|
| `include($_GET['page'])` / `include($_POST['file'])` | CRITICAL | LFI → RCE via log poisoning |
| `require($_GET['file'])` | CRITICAL | LFI |
| `include_once($_GET[...])` / `require_once($_GET[...])` | CRITICAL | LFI |
| `readfile($_GET['file'])` | CRITICAL | File disclosure |
| `file_get_contents($_GET['path'])` | HIGH | File/URL read |
| `fopen($_GET['file'], 'r')` | CRITICAL | File open |
| `file($_GET['path'])` | HIGH | Read file into array |
| `highlight_file($_GET['file'])` | CRITICAL | PHP source disclosure |
| `include("pages/" . $_GET['page'] . ".php")` | HIGH | Partial mitigation (extension added) but still exploitable via null byte on older PHP |

### Node.js / TypeScript
| Pattern | Severity | Notes |
|---------|----------|-------|
| `fs.readFile(req.params.path, ...)` | CRITICAL | Direct file read |
| `fs.readFileSync(req.query.file)` | CRITICAL | Sync file read |
| `fs.createReadStream(req.body.path)` | CRITICAL | Stream file read |
| `res.sendFile(req.params.filename)` | HIGH | Express static file serve |
| `res.download(req.query.file)` | HIGH | File download |
| `path.join(__dirname, req.params.file)` without `path.resolve`+`startsWith` check | HIGH | Join alone is insufficient |
| `require(req.params.module)` | CRITICAL | Path traversal + arbitrary code execution |
| `fs.readdirSync(req.query.dir)` | HIGH | Directory listing |

### Go
| Pattern | Severity | Notes |
|---------|----------|-------|
| `os.Open(r.FormValue("path"))` | CRITICAL | Direct file open |
| `os.ReadFile(r.URL.Query().Get("file"))` | CRITICAL | File read |
| `http.ServeFile(w, r, r.FormValue("path"))` | CRITICAL | File serve — `http.ServeFile` has some built-in protection but verify |
| `filepath.Join(base, r.FormValue("name"))` without `filepath.Clean`+containment | HIGH | |
| `os.Stat(r.FormValue("path"))` | MEDIUM | Path existence disclosure |

### Ruby
| Pattern | Severity | Notes |
|---------|----------|-------|
| `File.open(params[:path])` | CRITICAL | File open |
| `File.read(params[:file])` | CRITICAL | File read |
| `IO.read(params[:file])` | CRITICAL | File read |
| `send_file(params[:path])` | CRITICAL | Rails file serve |
| `send_data(File.read(params[:file]))` | CRITICAL | File read + serve |
| `render params[:template]` | CRITICAL | Template injection (+ path traversal) |
| `erb.result(binding) where erb from params` | CRITICAL | Template injection |

## Containment Guard Detection

After finding a sink, the scanner checks if a safe-path guard exists within ±40 lines. If found, the finding is downgraded or suppressed:

**Python safe guards:**
```python
# Correct: resolve to absolute, then check containment
safe_path = os.path.abspath(os.path.join(BASE_DIR, user_input))
if not safe_path.startswith(BASE_DIR):
    raise PermissionError("path traversal detected")

# Also safe: pathlib.resolve() + is_relative_to()
resolved = (Path(BASE_DIR) / user_input).resolve()
if not resolved.is_relative_to(BASE_DIR):
    raise Value
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

MEDIUMObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
skills/compdf-conversion-cli/scripts/license.xml:9
<key>k5Ey9KFlkqpj+SDkUw+5ED9lTA3En/qUi0zdrydUCH3kMWTE3Eh65NXnFCaxlY2omY2JHnlEoK7Li7oOEvM7eG5VPdcO/sFlMfoCRdnLYdepJ+uLzYwOWR8W4yQVve/clxVFTVRL4DFleKInGdpAxIbHZT2yi4ADAMENls1N1XSLojRuqXePXDeAT/4Mv4TTx0s

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f3b4a2a472efull audit observations/trust-audit/skill/leoyeai__phy-path-traversal-audit.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f3b4a2a472eSAFEB89first audit
06

Questions

What does the Phy Path Traversal Audit skill do?

🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai

Is Phy Path Traversal Audit safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Phy Path Traversal Audit access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Phy Path Traversal Audit work with?

Its documentation mentions openclaw. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4f3b4a2a472e), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement