profile_id: path-traversal-generic match_rules: keywords: - path traversal - directory traversal vuln_family: path-traversal provisioning_mode: real artifact_source: strategy: official-image-or-source required_services: - app seed_actions: - kind: note message: Use inert marker files inside isolated volume mounts only. baseline_actions: - kind: http-get path: / attack_actions: - kind: note message: Validate canonicalization failures with marker files rather than real secrets. browser_assertions: required: false success_criteria: - Marker file outside intended root becomes reachable or denial path is confirmed. cleanup_policy: destroy destructive_risk: medium allowed_target_types: - lab-local - lab-public - authorized-third-party