CtrlK
BlogDocsLog inGet started
Tessl Logo

smuggling

HTTP Request Smuggling (HRS) — front-end / back-end parser disagreement attacks that desync the proxy stack. Covers CL.TE, TE.CL, TE.TE, CL.0, HTTP/2 downgrade (h2.cl, h2.te), pipelining, and connection-state pinning. Includes a confirm-desync gate, header obfuscation catalog, and minimal raw-socket Python harnesses (no smuggler.py available in sandbox).

60

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/exploit/web/smuggling/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

70%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A technically rich, well-sequenced skill with strong validation checkpoints and mostly executable harnesses, held back by repetitive prose and a monolithic structure that forgoes file-level progressive disclosure despite its length.

Suggestions

Deduplicate the 'don't brute-force admin credentials' guidance into a single authoritative callout and reference it from the other sections instead of restating it.

Move the Class A/B/C chapters and/or the PortSwigger lab reference into separate reference files (e.g. CLASSES.md, LABS.md) linked one level deep from a leaner SKILL.md overview.

Flesh out the B3 cache-poisoning and sibling-resource enumeration snippets into complete runnable harnesses matching the quality of the variant catalog.

DimensionReasoningScore

Conciseness

Mostly dense and actionable, but the 'do not brute-force admin credentials' guidance is repeated verbatim across 'When This Skill Is Primary', the Class A anti-pattern callout, and 'Why this beats brute-force', and the Class C section is prose-heavy — the body could be tightened without losing clarity.

3 / 5

Actionability

The confirm-desync gate and the CL.TE/TE.CL/TE.TE/CL.0/h2 variant harnesses are copy-paste executable, but a few peripheral patterns (B3 cache poisoning, the sibling-resource enumeration loop) are sketch/placeholder rather than complete runnable code.

4 / 5

Workflow Clarity

Clear sequence (recognition signals → confirm-desync gate → variant catalog → Class A/B/C routing → verification) with an explicit validation checkpoint (the gate) and feedback loops (gate fails → hand back to recon; gate passes → iterate variants; repro ≥3 to confirm).

5 / 5

Progressive Disclosure

Internal section structure is logical, but the skill is a single monolithic ~650-line SKILL.md with no bundle files; content that would benefit from splitting (variant catalog, Class A/B/C chapters, PortSwigger lab reference) is fully inlined rather than disclosed one level deep into reference files.

3 / 5

Total

15

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A highly specific, distinctive description with comprehensive technique coverage, weakened only by the absence of an explicit 'Use when...' trigger clause in the description field itself (trigger guidance is relegated to metadata.when_to_use).

Suggestions

Append an explicit 'Use when ...' clause to the description naming the natural trigger phrases (HTTP request smuggling, HRS, desync, CL.TE/TE.CL, HTTP/2 downgrade) so the description field alone answers 'when' as well as 'what'.

Surface one or two of the most common user phrasings (e.g. 'request smuggling', 'h2c smuggling') directly in the description to round out trigger-term coverage.

DimensionReasoningScore

Specificity

Names the domain and lists many concrete techniques and deliverables — 'CL.TE, TE.CL, TE.TE, CL.0, HTTP/2 downgrade (h2.cl, h2.te), pipelining, and connection-state pinning' plus 'confirm-desync gate, header obfuscation catalog, and minimal raw-socket Python harnesses' — comprehensive coverage with no real gaps.

5 / 5

Completeness

The 'what' is explicit and detailed, but the description field itself contains no 'Use when...' clause or equivalent trigger guidance — trigger terms live in a separate metadata.when_to_use field — so completeness is capped at 3 per the rubric guideline.

3 / 5

Trigger Term Quality

Includes synonyms ('HTTP Request Smuggling' / 'HRS'), 'desync', and technique codes (CL.TE, h2.cl) users would name, but a few natural phrasings (e.g. standalone 'request smuggling', 'h2c') are absent.

4 / 5

Distinctiveness Conflict Risk

A clear, narrow niche (front-end/back-end HTTP parser desync) with distinct technique-specific triggers; minimal overlap risk with other skills.

5 / 5

Total

17

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (657 lines); consider splitting into references/ and linking

Warning

metadata_version

'metadata.version' is missing

Warning

Total

14

/

16

Passed

Repository
PurpleAILAB/Decepticon
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.