hunt-http-smuggling

Community

Detect and validate request smuggling in the wild

Authorjellaharshith
Version1.0.0
Installs0

System Documentation

What problem does it solve?

This Skill helps you hunt for HTTP request smuggling by identifying parser disagreements between a front-end proxy and a back-end server so you can confirm and validate the cross-client impact.

Core Features & Use Cases

  • Protocol-vector coverage: Focuses on CL.TE, TE.CL, H2.CL, and H2.TE smuggling paths, including modern HTTP/2 downgrade scenarios.
  • Hunting workflow and confirmation: Provides detection approaches (e.g., Burp HTTP Request Smuggler, smuggler tooling, and timing-based confirmation) and validation ideas that distinguish real smuggling effects from self-induced delays.
  • Operator targeting guidance: Includes a target-suitability matrix and fingerprinting guidance to prioritize realistic CDN + origin and load balancer/WAF bypass opportunities.
  • Chain linkage for real-world triage: References common escalation chains such as cache poisoning, auth bypass, session attachment/credential theft, and reflected XSS at the victim queue level.

Quick Start

Use the hunt-http-smuggling skill to identify whether your target’s front-end/origin stack is vulnerable to CL.TE, TE.CL, or HTTP/2 downgrade smuggling, then confirm exploitability using a timing-based cross-request technique.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: hunt-http-smuggling
Download link: https://github.com/jellaharshith/SWIFT/archive/main.zip#hunt-http-smuggling

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.