file-upload-and-traversal
Path traversal encodings, the file-upload bypass matrix (extension/MIME/magic-byte checks), and file-format-specific attacks (SVG/DOCX/XLSX XXE, PDF launch actions, polyglot images). Converted from master-pentest-prompt.md Phase 6. Use on any file-upload feature or any endpoint that takes a file path/name as input.
Source facts
- Repository
- ankitsingh015/HuntMCP
- Last source activity
- August 24, 2026 at 11:04
- Detected SKILL.md language
- English
- Stars
- 4
- Forks
- 0
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.