Install
$ agentstack add skill-zhaoxuya520-reverse-skill-competition-request-normalization-smuggling ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Competition Request Normalization Smuggling
Use this skill only as a downstream specialization after $ctf-sandbox-orchestrator is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to $ctf-sandbox-orchestrator first.
Use this skill when request interpretation changes between proxy, middleware, and backend parser layers.
Reply in Simplified Chinese unless the user explicitly requests English.
Quick Start
- Map every parsing hop: client-facing proxy, gateway, app server, and downstream service.
- Record path normalization, header canonicalization, transfer framing, and host derivation at each hop.
- Capture one accepted baseline request and one differential request with minimal delta.
- Prove which hop interprets the request differently.
- Reproduce one minimal differential path that yields decisive behavior.
Workflow
1. Map Parse And Routing Boundaries
- Record
Host, forwarded headers, path decoding, slash collapsing, dot-segment handling, and case behavior. - Note
Content-Length,Transfer-Encoding, chunk framing, and connection reuse behavior when relevant. - Keep edge parser and backend parser decisions side by side.
2. Prove Differential Interpretation
- Build paired requests that differ in one canonicalization dimension only.
- Capture proxy logs, backend logs, route match, and downstream request shape.
- Show where route, auth scope, or body boundary diverges.
3. Reduce To Decisive Smuggling Chain
- Compress to: crafted request -> parser differential across hops -> unintended routed request or hidden endpoint reach -> resulting effect.
- State whether root cause is path normalization drift, header ambiguity, transfer framing differential, or host-derivation confusion.
- If the chain becomes primarily runtime routing without framing tricks, hand off to runtime routing skill.
Read This Reference
- Load
references/request-normalization-smuggling.mdfor parse-differential checklist and evidence packaging.
What To Preserve
- Raw request pairs, hop-by-hop interpretation, and final routed target
- Exact normalization or framing delta that flips behavior
- One minimal replayable differential request path
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: zhaoxuya520
- Source: zhaoxuya520/reverse-skill
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.