offensive-file-upload
File upload vulnerability checklist: MIME type bypass, extension bypass, magic byte manipulation, path traversal in filenames, stored XSS via SVG/HTML upload, server-side processing attacks, and race conditions. Use for assessing file upload endpoints in web app pentests or bug bounty. Use when performing authorized red-team, pentest, or research work involving file upload.
- Compatibility
- claude-code codex opencode
Pinned to revision 626b01ddea63, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/offensive-file-upload/SKILL.md
- skills/offensive-file-upload/LICENSE
- skills/offensive-file-upload/README.md
- skills/offensive-file-upload/agents/openai.yaml
Every link opens the file at its source, pinned to the revision this page describes.