lfi - Test LFI and RFI vulnerabilities
Guides authorized penetration testing for local and remote file inclusion vulnerabilities, including file reads and escalation to code execution.
Tags
Updated: 2026-09-29Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Assess inclusion points
- Test traversal variants
- Extract PHP source
- Execute code through wrappers
- Poison logs for execution
- Escalate LFI to RCE
- Inspect sensitive files
- Record significant evidence
- Summarize engagement state
Inputs
- Target application
- File inclusion parameter
- Authorized testing scope
- Engagement directory
- Engagement state
- Penetration testing tools
Outputs
- Activation message
- Evidence files
- Engagement findings summary
- Confirmed vulnerability status
- Discovered hosts and services
- Discovered credentials or tokens
- Access changes
- Identified pivot paths
- Blocked item records
Requirements
- Explicit written authorization
- File-inclusion-capable target parameter
- State MCP server access
- Required testing tools
