Agent skill

HTTP Parameter Pollution

by langbyyi in langbyyi/CyberStrikeAI-SRC

HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.

Apache-2.0Auto-check passedSecurity

Install HTTP Parameter Pollution

skills CLI
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill http-parameter-pollution -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install langbyyi/CyberStrikeAI-SRC http-parameter-pollution --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/http-parameter-pollution .claude/skills/http-parameter-pollution && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
http-parameter-pollution
GitHub stars
133
Used in
1 other repo
Token cost
~2.2k tokens
SKILL.md length
691 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
Apache-2.0

At a glance

HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.

  • Works in 4 steps: SERVER BEHAVIOR MATRIX → PAYLOAD PATTERNS → ATTACK SCENARIOS → …
  • Filters and application layers disagree on which value wins
  • SKILL.md covers QUICK START, 1. SERVER BEHAVIOR MATRIX, 2. PAYLOAD PATTERNS and 3. ATTACK SCENARIOS, plus 5 more sections
  • Reaches allowed.host

What it does

HTTP Parameter Pollution is an agent skill from langbyyi/CyberStrikeAI-SRC. HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks. Use when filters and application layers disagree on which value wins, enabling bypass, SSRF second URL, logic abuse, or CSRF token confusion.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities. It works with PHP. The licence is Apache-2.0.

When your agent uses it

  • Filters and application layers disagree on which value wins
  • Enabling bypass
  • SSRF second URL
  • CSRF token confusion

Example prompts

  • “/http-parameter-pollution”

Requirements

  • Python 3
  • Node.js

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. SERVER BEHAVIOR MATRIX
  2. PAYLOAD PATTERNS
  3. ATTACK SCENARIOS
  4. TOOLS

What it can do on your machine

Read from SKILL.md and the folder at commit 8f08ebe. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are http and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • allowed.host

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

HTTP Parameter Pollution loads about 2.2k tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 691 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~73
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from langbyyi/CyberStrikeAI-SRC at commit 8f08ebe, republished under its Apache-2.0 licence (© langbyyi). 691 words, ~2,194 tokens.

Download SKILL.mdSave it as .claude/skills/http-parameter-pollution/SKILL.md (or your agent's skills folder).
name
http-parameter-pollution
description
HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks. Use when filters and application layers disagree on which value wins, enabling bypass, SSRF second URL, logic abuse, or CSRF token confusion.

SKILL: HTTP Parameter Pollution (HPP)

AI LOAD INSTRUCTION: Model the full request path: browser → CDN/WAF → reverse proxy → app framework → business code. Duplicate keys (a=1&a=2) are not an error at HTTP level; each hop may pick first, last, join, or array-ify. Test HPP when WAF and app disagree, or when internal HTTP clients rebuild query strings. Routing: when the same parameter name appears multiple times, or when WAF/backend tech stacks differ, use the Section 1 matrix to pick "first/last/join" hypotheses, then design Section 3 scenario chains.

QUICK START

Hypothesis: the security check reads one occurrence of a parameter while the action reads another.

First-pass payloads
text
id=1&id=2
id=1&id=1%20OR%201=1
url=https://legit.example&id=https://evil.example
amount=1&amount=9999
csrf=TOKEN_A&csrf=TOKEN_B
user=alice&user=admin
Body variants (repeat for POST)
text
application/x-www-form-urlencoded
id=1&id=2

multipart/form-data
------boundary
Content-Disposition: form-data; name="id"
1
------boundary
Content-Disposition: form-data; name="id"
2
Quick methodology
  1. Fingerprint front stack (CDN/WAF) vs origin (language/framework) using baseline a=1&a=2.
  2. Send both orders: a=1&a=2 and a=2&a=1 (some parsers are order-sensitive).
  3. If JSON: test duplicate keys and Content-Type confusion (see Section 2).

1. SERVER BEHAVIOR MATRIX

Typical defaults — always confirm; middleware and custom parsers override these.

TechnologyBehaviorExample: a=1&a=2
PHP / Apache ($_GET)Last occurrencea=2
ASP.NET / IISOften comma-joined (all)a=1,2
JSP / Tomcat (servlet param)First occurrencea=1
Python / Django (QueryDict)Last occurrencea=2
Python / Flask (request.args)First occurrencea=1
Node.js / Express (req.query)Array of valuesa=['1','2'] (shape may vary by parser version)
Perl / CGIFirst occurrencea=1
Ruby / Rack (Rack::Utils)Last occurrencea=2
Go net/http (ParseQuery)First occurrencea=1

Why it matters: a WAF on IIS might see 1,2 while PHP backend receives 2 only — or the reverse if a proxy normalizes.


2. PAYLOAD PATTERNS

2.1 Basic duplicate key
http
GET /api?q=safe&q=evil HTTP/1.1
2.2 Array-style (PHP / some frameworks)
http
GET /api?id[]=1&id[]=2 HTTP/1.1
2.3 Mixed array + scalar
http
GET /api?item[]=a&item=b HTTP/1.1
2.4 Encoded ampersand (parser differential)
text
# Literal & inside a value vs new pair — depends on decoder
param=value1%26other=value2
param=value1&other=value2
2.5 Nested / bracket keys
http
GET /api?user[name]=a&user[role]=user&user[role]=admin HTTP/1.1
2.6 JSON duplicate keys
json
{"test":"user","test":"admin"}

Many parsers keep last key; some keep first. JavaScript JSON.parse keeps the last duplicate key.


3. ATTACK SCENARIOS

3.1 HPP + WAF bypass

Pattern: WAF inspects first value; application uses last.

text
id=1&id=1%20UNION%20SELECT%20...

Also try: benign value in JSON field duplicated in query string, if gateway merges sources differently.

3.2 HPP + SSRF

Pattern: validator reads safe URL; fetcher reads internal/evil URL.

text
url=https://allowed.cdn.example/&url=http://169.254.169.254/

Confirm which component (library vs app) consumes which occurrence.

3.3 HPP + CSRF

Pattern: duplicate anti-CSRF token so one copy satisfies parser A and another satisfies parser B.

text
csrf=LEGIT&csrf=IGNORED_OR_ALT

Use only in authorized CSRF assessments with a clear state-changing target.

3.4 HPP + business logic (e.g. payment)
text
amount=1&amount=5000
quantity=1&quantity=-1
price=9.99&price=0.01

Pair with race conditions or server-side rounding for higher impact; HPP alone often needs a split interpretation across layers.


Show full SKILL.md (294 more words)Show less

4. TOOLS

ToolHow to use
Burp SuiteRepeater: duplicate keys in raw query/body; Param Miner / extensions for hidden params; compare responses for first vs last interpretation
OWASP ZAPManual Request Editor; Automated Scan may not deeply fuzz HPP — prefer manual variants
Custom scriptsBuild exact raw HTTP (preserve ordering) — some clients normalize duplicates

Tip: log raw query strings at the app if you control a test lab; some frameworks expose only the “winning” value while logs show the full string.


DECISION TREE

text
                    +-------------------------+
                    | Duplicate param name    |
                    | same request            |
                    +------------+------------+
                                 |
              +------------------+------------------+
              |                                     |
       +------v------+                       +------v------+
       | Single app  |                       | WAF / CDN / |
       | layer only  |                       | proxy chain |
       +------+------+                       +------+------+
              |                                     |
    +---------v---------+                 +---------v---------+
    | Read framework    |                 | Map each hop:     |
    | docs + test       |                 | first/last/join/  |
    | a=1&a=2 vs swap   |                 | array             |
    +---------+---------+                 +---------+---------+
              |                                     |
              +------------------+------------------+
                                 |
                          +------v------+
                          | Pick attack |
                          | template    |
                          +------+------+
                                 |
         +-----------+-----------+-----------+-----------+
         |           |           |           |           |
    +----v----+ +----v----+ +----v----+ +----v----+ +----v----+
    | WAF vs  | | SSRF    | | CSRF    | | Logic   | | JSON    |
    | app     | | split   | | token   | | numeric | | dup key |
    | value   | | URL     | | confuse | | fields  | | parsers |
    +---------+ +---------+ +---------+ +---------+ +---------+

TESTING CHECKLIST

  • Fingerprint front-end stack (CDN/WAF) vs back-end framework using baseline a=1&a=2 — note which value each layer retains
  • Test duplicate parameters in query string: id=1&id=2, id=2&id=1 (both orders)
  • Test duplicate parameters in POST body (application/x-www-form-urlencoded): amount=1&amount=9999
  • Test duplicate parameters in multipart forms: repeat Content-Disposition: form-data; name="id" blocks
  • Test WAF bypass via HPP: place benign value first for WAF, malicious payload second for app (or vice versa depending on stack)
  • Test authentication bypass: user=alice&user=admin, csrf=TOKEN_A&csrf=TOKEN_B
  • Test SSRF via HPP: url=https://allowed.host/&url=http://169.254.169.254/
  • Test business logic abuse: amount=1&amount=5000, quantity=1&quantity=-1, price=9.99&price=0.01
  • Test JSON duplicate keys: {"test":"user","test":"admin"} with Content-Type application/json
  • Test array-style parameters: id[]=1&id[]=2, user[name]=a&user[role]=admin
  • Verify findings by comparing raw query strings logged at the app layer vs what the WAF/proxy reports

TARGET TOOL ADAPTATION

Use visible http-framework-test for ordered duplicate-key requests and response differentials, and execute-python-script when exact serialization is required. Browser/proxy verification is optional and only applies when those capabilities are visible; do not invent MCP calls.

Safety & scope: HPP testing can change server state (payments, account settings). Run only where explicitly authorized, with scoped accounts, and document parser behavior before high-impact requests.

  • csrf — HPP can bypass CSRF token validation
  • xss — HPP can evade WAF XSS filters
  • sqli — HPP can bypass SQL injection WAF rules
  • open-redirect — Duplicate URL parameters can confuse redirect filters

© langbyyi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/http-parameter-pollution of langbyyi/CyberStrikeAI-SRC.

Open the folder on GitHubat commit 8f08ebe

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in langbyyi/CyberStrikeAI-SRC, which our catalogue first saw on October 7, 2026.

Compare with similar skills

HTTP Parameter Pollution next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

HTTP Parameter Pollution compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
HTTP Parameter Pollution this skilllangbyyi/CyberStrikeAI-SRC1331 repos~2.2kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Php Codeigniter Audit0xShe/PHP-Code-Audit-Skill4021 repos~477Automated safety check: PassNone
WebMuWinds/BUUCTF_Agent267—~463Automated safety check: PassApache-2.0
Security Reviewgithub/awesome-copilot40k1 repos~2.3kAutomated safety check: NotesMIT
Php Ssrf Audit0xShe/PHP-Code-Audit-Skill4021 repos~481Automated safety check: PassNone

Similar skills

  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Php Codeigniter Audit

    0xShe/PHP-Code-Audit-Skill

    CodeIgniter 框架特效安全审计工具。针对 CodeIgniter 的 CSRF、XSS 输出过滤、数据库查询构造、路由与验证器配置、会话 Cookie 安全等机制进行白盒静态审计,并映射到通用漏洞类型体系(CSRF/AUTH/XSS/SQL/CFG/SESS 等)。

    402 GitHub starsUsed in 1 repo~477 tokens
    SecurityAuto-check passed
  • Web

    MuWinds/BUUCTF_Agent

    Web 安全攻防技术,包括 SQL 注入、XSS、文件上传、命令注入、SSRF、反序列化等常见漏洞的识别与利用. An agent skill from MuWinds/BUUCTF_Agent.

    267 GitHub stars~463 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes
  • Php Ssrf Audit

    0xShe/PHP-Code-Audit-Skill

    PHP Web 源码 SSRF 审计工具。识别用户可控 URL/地址进入网络请求 Sink,追踪内网/协议/端口限制与回显,输出可利用性分级、PoC 与修复建议(禁止省略)。

    402 GitHub starsUsed in 1 repo~481 tokens
    SecurityAuto-check passed
  • Php Symfony Audit

    0xShe/PHP-Code-Audit-Skill

    Symfony 框架特效安全审计工具。针对 Symfony 常见 security.yaml、CSRF、Twig/Twig raw、表达式与访问控制等框架机制做白盒静态审计,并将风险映射到通用漏洞类型体系(AUTH/CSRF/CFG/XSS/TPL/LOGIC 等)。

    402 GitHub starsUsed in 1 repo~599 tokens
    SecurityAuto-check passed

More from langbyyi/CyberStrikeAI-SRC

All 13 skills in this repo
  • Burp MCP Vuln Check

    langbyyi/CyberStrikeAI-SRC

    Automate low-impact web vulnerability verification through Burp MCP.

    133 GitHub stars~3.1k tokensUpdated 10 days ago
    Auto-check passed
  • Authbypass Authentication Flaws

    langbyyi/CyberStrikeAI-SRC

    Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.

    133 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Insecure Source Code Management

    langbyyi/CyberStrikeAI-SRC

    Source control and artifact exposure (.git, .svn, .hg, backups, .env).

    133 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check: notes
  • Type Juggling

    langbyyi/CyberStrikeAI-SRC

    PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.

    133 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed
  • Websocket Security

    langbyyi/CyberStrikeAI-SRC

    WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.

    133 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Xslt Injection

    langbyyi/CyberStrikeAI-SRC

    XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces.

    133 GitHub starsUsed in 1 repo~3k tokens
    Auto-check passed

Works with

Categories

Questions about HTTP Parameter Pollution

What does HTTP Parameter Pollution do?

HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks. HTTP Parameter Pollution is an agent skill from langbyyi/CyberStrikeAI-SRC. HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.

When should I use HTTP Parameter Pollution?

HTTP Parameter Pollution fits situations like: filters and application layers disagree on which value wins; enabling bypass; SSRF second URL; CSRF token confusion.

How do I install HTTP Parameter Pollution in Claude Code?

Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill http-parameter-pollution -a claude-code`. Or copy the skill folder (skills/http-parameter-pollution in langbyyi/CyberStrikeAI-SRC) into .claude/skills/http-parameter-pollution in your project. Claude Code loads it when a task matches its description.

How do I install HTTP Parameter Pollution in Codex?

Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill http-parameter-pollution -a codex`. Or copy the skill folder (skills/http-parameter-pollution in langbyyi/CyberStrikeAI-SRC) into .agents/skills/http-parameter-pollution in your project. Codex loads it when a task matches its description.

Can I use HTTP Parameter Pollution in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbyyi/CyberStrikeAI-SRC --skill http-parameter-pollution -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/http-parameter-pollution, .gemini/skills/http-parameter-pollution, .github/skills/http-parameter-pollution and .opencode/skills/http-parameter-pollution in your project.

What does HTTP Parameter Pollution need to run?

SKILL.md names no scripts, command-line tools or credentials: HTTP Parameter Pollution is instructions for the agent only. Our summary lists: Python 3; Node.js.

Does HTTP Parameter Pollution access the network?

SKILL.md names 1 domain. In commands or code: allowed.host; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is HTTP Parameter Pollution safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does HTTP Parameter Pollution use?

HTTP Parameter Pollution is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does HTTP Parameter Pollution use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to HTTP Parameter Pollution?

Skills that share tags, products or a category with HTTP Parameter Pollution: Code Audit (3stoneBrother/code-audit, 893 stars), Php Codeigniter Audit (0xShe/PHP-Code-Audit-Skill, 402 stars), Web (MuWinds/BUUCTF_Agent, 267 stars) and Security Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains HTTP Parameter Pollution?

langbyyi (a GitHub user) maintains it in langbyyi/CyberStrikeAI-SRC, which has 133 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on September 27, 2026.

Source: langbyyi/CyberStrikeAI-SRC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.