AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Competition Request Normalization Smuggling

skill-zhaoxuya520-reverse-skill-competition-request-normalization-smuggling · by zhaoxuya520

Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for parser differentials, HTTP normalization gaps, ambiguous headers, path decoding drift, transfer-framing mismatches, and request smuggling routes. Use when the user asks to trace proxy and backend parse differences, conflicting path normalization, Host or forwarded-header ambiguity, CL/TE issues, or routing outcomes t…

No reviews yet
0 installs
3 views
0.0% view→install

Install

$ agentstack add skill-zhaoxuya520-reverse-skill-competition-request-normalization-smuggling

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-zhaoxuya520-reverse-skill-competition-request-normalization-smuggling)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Competition Request Normalization Smuggling? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Competition Request Normalization Smuggling

Use this skill only as a downstream specialization after $ctf-sandbox-orchestrator is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to $ctf-sandbox-orchestrator first.

Use this skill when request interpretation changes between proxy, middleware, and backend parser layers.

Reply in Simplified Chinese unless the user explicitly requests English.

Quick Start

  1. Map every parsing hop: client-facing proxy, gateway, app server, and downstream service.
  2. Record path normalization, header canonicalization, transfer framing, and host derivation at each hop.
  3. Capture one accepted baseline request and one differential request with minimal delta.
  4. Prove which hop interprets the request differently.
  5. Reproduce one minimal differential path that yields decisive behavior.

Workflow

1. Map Parse And Routing Boundaries

  • Record Host, forwarded headers, path decoding, slash collapsing, dot-segment handling, and case behavior.
  • Note Content-Length, Transfer-Encoding, chunk framing, and connection reuse behavior when relevant.
  • Keep edge parser and backend parser decisions side by side.

2. Prove Differential Interpretation

  • Build paired requests that differ in one canonicalization dimension only.
  • Capture proxy logs, backend logs, route match, and downstream request shape.
  • Show where route, auth scope, or body boundary diverges.

3. Reduce To Decisive Smuggling Chain

  • Compress to: crafted request -> parser differential across hops -> unintended routed request or hidden endpoint reach -> resulting effect.
  • State whether root cause is path normalization drift, header ambiguity, transfer framing differential, or host-derivation confusion.
  • If the chain becomes primarily runtime routing without framing tricks, hand off to runtime routing skill.

Read This Reference

  • Load references/request-normalization-smuggling.md for parse-differential checklist and evidence packaging.

What To Preserve

  • Raw request pairs, hop-by-hop interpretation, and final routed target
  • Exact normalization or framing delta that flips behavior
  • One minimal replayable differential request path

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.