crlf-injection

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides educational content regarding CRLF injection vulnerabilities. It includes detection payloads (e.g., %0D%0ANew-Header:injected), exploitation scenarios (Session Fixation, XSS, Cache Poisoning), and filter bypass techniques (Double encoding, Unicode bypass).
  • [SAFE]: No executable scripts (Python/Node.js) are included. The code snippets provided are for demonstration purposes in PHP, Python, Node.js, and Java, serving as examples of vulnerable code patterns for security researchers.
  • [SAFE]: The skill does not request network access, sensitive file access, or contain instructions to override AI safety guidelines. The routing section refers to other skills within the same repository structure for further learning.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 01:23 PM
Security Audit — agent-trust-hub — crlf-injection