request-smuggling
Fail
Audited by Snyk on Jul 6, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The prompt explicitly instructs the agent to capture, log, and include "new credentials or tokens found" in its return summary and to save evidence files (e.g., ssrf-aws-creds.json), which requires outputting secret values verbatim and therefore poses an exfiltration risk.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This document provides explicit, actionable exploitation techniques for HTTP request smuggling that enable deliberate malicious actions — capturing other users' requests and auth tokens (data/credential exfiltration), bypassing access controls, poisoning caches for mass compromise, and creating persistent/remote bypasses (H2/H2C downgrade and connection-state attacks) — representing high-risk, intentional abuse capability.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata