http2-specific-attacks
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download
h2csmugglerfrom the BishopFox GitHub repository and install theh2Python library usingpip3. These are established tools and libraries in the security community used for protocol analysis and testing. - [COMMAND_EXECUTION]: The skill provides numerous command-line examples for using
curl,h2csmuggler, andpythonto perform security testing. These include commands for probing h2c support, testing for smuggling vulnerabilities, and executing pseudo-header injection. These are standard procedures for identifying protocol-level flaws during a penetration test. - [COMMAND_EXECUTION]: A Python script template is included in section 5.1 to demonstrate how HTTP/2 multiplexing can be used to trigger race conditions. This is provided as an example for the agent to understand and replicate the attack pattern in a controlled testing environment.
Audit Metadata