request-smuggling

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references several third-party security tools hosted on GitHub, including 'defparam/smuggler', 'dhmosfunk/simple-http-smuggler-generator', 'h2csmuggler', and 'http2smugl'. These are listed for use by security researchers.\n- [DATA_EXFILTRATION]: Contains a JavaScript template for Client-Side Desync (CSD) that includes a demonstration of data exfiltration using 'navigator.sendBeacon' to an 'attacker.com' endpoint. This is presented as an illustrative PoC for educational purposes.\n- [COMMAND_EXECUTION]: Provides example 'curl' commands and HTTP payload templates for testing various smuggling techniques (CL.TE, TE.CL, CL.0, H2.CL, etc.). These are intended for use in authorized security testing environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 01:24 PM
Security Audit — agent-trust-hub — request-smuggling