request-smuggling
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides technical instructions and example commands for using various CLI tools, such as
curland specialized Python scripts, to perform security testing. - [EXTERNAL_DOWNLOADS]: References several established security tools and repositories on GitHub (e.g.,
defparam/smuggler,h2csmuggler,http2smugl) for automating the detection of HTTP desync issues. - [DYNAMIC_EXECUTION]: Includes a JavaScript template for a Client-Side Desync (CSD) Proof-of-Concept, which is provided for educational and vulnerability demonstration purposes.
Audit Metadata