LogoClawIndex
CasesSkillsAbout
LogoClawIndex

lfi - Test LFI and RFI vulnerabilities

Guides authorized penetration testing for local and remote file inclusion vulnerabilities, including file reads and escalation to code execution.

Tags

Updated: 2026-09-29

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Assess inclusion points
  • Test traversal variants
  • Extract PHP source
  • Execute code through wrappers
  • Poison logs for execution
  • Escalate LFI to RCE
  • Inspect sensitive files
  • Record significant evidence
  • Summarize engagement state

Inputs

  • Target application
  • File inclusion parameter
  • Authorized testing scope
  • Engagement directory
  • Engagement state
  • Penetration testing tools

Outputs

  • Activation message
  • Evidence files
  • Engagement findings summary
  • Confirmed vulnerability status
  • Discovered hosts and services
  • Discovered credentials or tokens
  • Access changes
  • Identified pivot paths
  • Blocked item records

Requirements

  • Explicit written authorization
  • File-inclusion-capable target parameter
  • State MCP server access
  • Required testing tools

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
LFI
RFI
path traversal
file inclusion
PHP wrappers
penetration testing
Assess inclusion points
Test traversal variants
Extract PHP source
Execute code through wrappers
Target application
File inclusion parameter
Authorized testing scope
Activation message
Evidence files
Engagement findings summary