hunt-http-smuggling
CommunityDetect and validate request smuggling in the wild
Legal & Compliance#http smuggling#cache poisoning#request parsing#auth bypass#http2 downgrade#burp extension#cdn security testing
Authorjellaharshith
Version1.0.0
Installs0
System Documentation
What problem does it solve?
This Skill helps you hunt for HTTP request smuggling by identifying parser disagreements between a front-end proxy and a back-end server so you can confirm and validate the cross-client impact.
Core Features & Use Cases
- Protocol-vector coverage: Focuses on CL.TE, TE.CL, H2.CL, and H2.TE smuggling paths, including modern HTTP/2 downgrade scenarios.
- Hunting workflow and confirmation: Provides detection approaches (e.g., Burp HTTP Request Smuggler, smuggler tooling, and timing-based confirmation) and validation ideas that distinguish real smuggling effects from self-induced delays.
- Operator targeting guidance: Includes a target-suitability matrix and fingerprinting guidance to prioritize realistic CDN + origin and load balancer/WAF bypass opportunities.
- Chain linkage for real-world triage: References common escalation chains such as cache poisoning, auth bypass, session attachment/credential theft, and reflected XSS at the victim queue level.
Quick Start
Use the hunt-http-smuggling skill to identify whether your target’s front-end/origin stack is vulnerable to CL.TE, TE.CL, or HTTP/2 downgrade smuggling, then confirm exploitability using a timing-based cross-request technique.
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: hunt-http-smuggling Download link: https://github.com/jellaharshith/SWIFT/archive/main.zip#hunt-http-smuggling Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.