Skip to main content
在 Manus 中运行任何 Skill
一键导入

cache-smuggling-hunter

星标15
分支7
更新时间2026年6月28日 16:46

Tests web caches for poisoning (unkeyed-header injection turning a benign header into cached malicious content for all visitors) and HTTP request smuggling (CL.TE / TE.CL desync between front-end proxy and back-end origin, smuggling a hidden request). Highly disruptive - only runs on staging with explicit `service_affecting: approved` AND `cache_smuggling_testing: approved`. Use when the target sits behind a CDN / load balancer, X-Cache / Age / CF-Cache-Status headers are present, or when the orchestrator identifies proxied architecture. Produces findings with CWE-444 / CWE-524 mapping and header-cache-key + HTTP/2 + strict-parsing remediation. Defensive testing only - POISONED-CACHE CLEANUP REQUIRED.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

文件资源管理器
2 个文件
SKILL.md
readonly