request-smuggling
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references several third-party security tools hosted on GitHub, including 'defparam/smuggler', 'dhmosfunk/simple-http-smuggler-generator', 'h2csmuggler', and 'http2smugl'. These are listed for use by security researchers.\n- [DATA_EXFILTRATION]: Contains a JavaScript template for Client-Side Desync (CSD) that includes a demonstration of data exfiltration using 'navigator.sendBeacon' to an 'attacker.com' endpoint. This is presented as an illustrative PoC for educational purposes.\n- [COMMAND_EXECUTION]: Provides example 'curl' commands and HTTP payload templates for testing various smuggling techniques (CL.TE, TE.CL, CL.0, H2.CL, etc.). These are intended for use in authorized security testing environments.
Audit Metadata