Code Audit
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill http-parameter-pollution -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC http-parameter-pollution --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/http-parameter-pollution .claude/skills/http-parameter-pollution && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "http-parameter-pollution" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/http-parameter-pollution into .claude/skills/http-parameter-pollution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "http-parameter-pollution", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/http-parameter-pollutionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill http-parameter-pollution -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC http-parameter-pollution --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/http-parameter-pollution .agents/skills/http-parameter-pollution && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "http-parameter-pollution" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/http-parameter-pollution into .agents/skills/http-parameter-pollution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "http-parameter-pollution", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill http-parameter-pollution -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC http-parameter-pollution --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/http-parameter-pollution .cursor/skills/http-parameter-pollution && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "http-parameter-pollution" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/http-parameter-pollution into .cursor/skills/http-parameter-pollution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "http-parameter-pollution", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/langbyyi/CyberStrikeAI-SRC.git --path skills/http-parameter-pollution--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill http-parameter-pollution -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC http-parameter-pollution --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/http-parameter-pollution .gemini/skills/http-parameter-pollution && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "http-parameter-pollution" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/http-parameter-pollution into .gemini/skills/http-parameter-pollution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "http-parameter-pollution", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install langbyyi/CyberStrikeAI-SRC http-parameter-pollutionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill http-parameter-pollution -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/http-parameter-pollution .github/skills/http-parameter-pollution && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "http-parameter-pollution" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/http-parameter-pollution into .github/skills/http-parameter-pollution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "http-parameter-pollution", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add langbyyi/CyberStrikeAI-SRC --skill http-parameter-pollution -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install langbyyi/CyberStrikeAI-SRC http-parameter-pollution --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/langbyyi/CyberStrikeAI-SRC.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/http-parameter-pollution .opencode/skills/http-parameter-pollution && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "http-parameter-pollution" agent skill from https://github.com/langbyyi/CyberStrikeAI-SRC/tree/master/skills/http-parameter-pollution into .opencode/skills/http-parameter-pollution/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "http-parameter-pollution", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
http-parameter-pollutionHTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.
HTTP Parameter Pollution is an agent skill from langbyyi/CyberStrikeAI-SRC. HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks. Use when filters and application layers disagree on which value wins, enabling bypass, SSRF second URL, logic abuse, or CSRF token confusion.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Web application vulnerabilities. It works with PHP. The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8f08ebe. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are http and json).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
allowed.hostFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
HTTP Parameter Pollution loads about 2.2k tokens when it runs. Until then it costs about 73 tokens; SKILL.md has 691 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from langbyyi/CyberStrikeAI-SRC at commit 8f08ebe, republished under its Apache-2.0 licence (© langbyyi). 691 words, ~2,194 tokens.
.claude/skills/http-parameter-pollution/SKILL.md (or your agent's skills folder).AI LOAD INSTRUCTION: Model the full request path: browser → CDN/WAF → reverse proxy → app framework → business code. Duplicate keys (
a=1&a=2) are not an error at HTTP level; each hop may pick first, last, join, or array-ify. Test HPP when WAF and app disagree, or when internal HTTP clients rebuild query strings. Routing: when the same parameter name appears multiple times, or when WAF/backend tech stacks differ, use the Section 1 matrix to pick "first/last/join" hypotheses, then design Section 3 scenario chains.
Hypothesis: the security check reads one occurrence of a parameter while the action reads another.
id=1&id=2
id=1&id=1%20OR%201=1
url=https://legit.example&id=https://evil.example
amount=1&amount=9999
csrf=TOKEN_A&csrf=TOKEN_B
user=alice&user=adminapplication/x-www-form-urlencoded
id=1&id=2
multipart/form-data
------boundary
Content-Disposition: form-data; name="id"
1
------boundary
Content-Disposition: form-data; name="id"
2a=1&a=2.a=1&a=2 and a=2&a=1 (some parsers are order-sensitive).Typical defaults — always confirm; middleware and custom parsers override these.
| Technology | Behavior | Example: a=1&a=2 |
|---|---|---|
PHP / Apache ($_GET) | Last occurrence | a=2 |
| ASP.NET / IIS | Often comma-joined (all) | a=1,2 |
| JSP / Tomcat (servlet param) | First occurrence | a=1 |
Python / Django (QueryDict) | Last occurrence | a=2 |
Python / Flask (request.args) | First occurrence | a=1 |
Node.js / Express (req.query) | Array of values | a=['1','2'] (shape may vary by parser version) |
| Perl / CGI | First occurrence | a=1 |
| Ruby / Rack (Rack::Utils) | Last occurrence | a=2 |
Go net/http (ParseQuery) | First occurrence | a=1 |
Why it matters: a WAF on IIS might see 1,2 while PHP backend receives 2 only — or the reverse if a proxy normalizes.
GET /api?q=safe&q=evil HTTP/1.1GET /api?id[]=1&id[]=2 HTTP/1.1GET /api?item[]=a&item=b HTTP/1.1# Literal & inside a value vs new pair — depends on decoder
param=value1%26other=value2
param=value1&other=value2GET /api?user[name]=a&user[role]=user&user[role]=admin HTTP/1.1{"test":"user","test":"admin"}Many parsers keep last key; some keep first. JavaScript JSON.parse keeps the last duplicate key.
Pattern: WAF inspects first value; application uses last.
id=1&id=1%20UNION%20SELECT%20...Also try: benign value in JSON field duplicated in query string, if gateway merges sources differently.
Pattern: validator reads safe URL; fetcher reads internal/evil URL.
url=https://allowed.cdn.example/&url=http://169.254.169.254/Confirm which component (library vs app) consumes which occurrence.
Pattern: duplicate anti-CSRF token so one copy satisfies parser A and another satisfies parser B.
csrf=LEGIT&csrf=IGNORED_OR_ALTUse only in authorized CSRF assessments with a clear state-changing target.
amount=1&amount=5000
quantity=1&quantity=-1
price=9.99&price=0.01Pair with race conditions or server-side rounding for higher impact; HPP alone often needs a split interpretation across layers.
| Tool | How to use |
|---|---|
| Burp Suite | Repeater: duplicate keys in raw query/body; Param Miner / extensions for hidden params; compare responses for first vs last interpretation |
| OWASP ZAP | Manual Request Editor; Automated Scan may not deeply fuzz HPP — prefer manual variants |
| Custom scripts | Build exact raw HTTP (preserve ordering) — some clients normalize duplicates |
Tip: log raw query strings at the app if you control a test lab; some frameworks expose only the “winning” value while logs show the full string.
+-------------------------+
| Duplicate param name |
| same request |
+------------+------------+
|
+------------------+------------------+
| |
+------v------+ +------v------+
| Single app | | WAF / CDN / |
| layer only | | proxy chain |
+------+------+ +------+------+
| |
+---------v---------+ +---------v---------+
| Read framework | | Map each hop: |
| docs + test | | first/last/join/ |
| a=1&a=2 vs swap | | array |
+---------+---------+ +---------+---------+
| |
+------------------+------------------+
|
+------v------+
| Pick attack |
| template |
+------+------+
|
+-----------+-----------+-----------+-----------+
| | | | |
+----v----+ +----v----+ +----v----+ +----v----+ +----v----+
| WAF vs | | SSRF | | CSRF | | Logic | | JSON |
| app | | split | | token | | numeric | | dup key |
| value | | URL | | confuse | | fields | | parsers |
+---------+ +---------+ +---------+ +---------+ +---------+a=1&a=2 — note which value each layer retainsid=1&id=2, id=2&id=1 (both orders)application/x-www-form-urlencoded): amount=1&amount=9999Content-Disposition: form-data; name="id" blocksuser=alice&user=admin, csrf=TOKEN_A&csrf=TOKEN_Burl=https://allowed.host/&url=http://169.254.169.254/amount=1&amount=5000, quantity=1&quantity=-1, price=9.99&price=0.01{"test":"user","test":"admin"} with Content-Type application/jsonid[]=1&id[]=2, user[name]=a&user[role]=adminUse visible http-framework-test for ordered duplicate-key requests and response differentials, and execute-python-script when exact serialization is required. Browser/proxy verification is optional and only applies when those capabilities are visible; do not invent MCP calls.
Safety & scope: HPP testing can change server state (payments, account settings). Run only where explicitly authorized, with scoped accounts, and document parser behavior before high-impact requests.
© langbyyi, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/http-parameter-pollution of langbyyi/CyberStrikeAI-SRC.
Open the folder on GitHubat commit 8f08ebe
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in langbyyi/CyberStrikeAI-SRC, which our catalogue first saw on October 7, 2026.
HTTP Parameter Pollution next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| HTTP Parameter Pollution this skilllangbyyi/CyberStrikeAI-SRC | 133 | 1 repos | ~2.2k | Automated safety check: Pass | Apache-2.0 | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Php Codeigniter Audit0xShe/PHP-Code-Audit-Skill | 402 | 1 repos | ~477 | Automated safety check: Pass | None | |
| WebMuWinds/BUUCTF_Agent | 267 | — | ~463 | Automated safety check: Pass | Apache-2.0 | |
| Security Reviewgithub/awesome-copilot | 40k | 1 repos | ~2.3k | Automated safety check: Notes | MIT | |
| Php Ssrf Audit0xShe/PHP-Code-Audit-Skill | 402 | 1 repos | ~481 | Automated safety check: Pass | None |
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
0xShe/PHP-Code-Audit-Skill
CodeIgniter 框架特效安全审计工具。针对 CodeIgniter 的 CSRF、XSS 输出过滤、数据库查询构造、路由与验证器配置、会话 Cookie 安全等机制进行白盒静态审计,并映射到通用漏洞类型体系(CSRF/AUTH/XSS/SQL/CFG/SESS 等)。
MuWinds/BUUCTF_Agent
Web 安全攻防技术,包括 SQL 注入、XSS、文件上传、命令注入、SSRF、反序列化等常见漏洞的识别与利用. An agent skill from MuWinds/BUUCTF_Agent.
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
0xShe/PHP-Code-Audit-Skill
PHP Web 源码 SSRF 审计工具。识别用户可控 URL/地址进入网络请求 Sink,追踪内网/协议/端口限制与回显,输出可利用性分级、PoC 与修复建议(禁止省略)。
0xShe/PHP-Code-Audit-Skill
Symfony 框架特效安全审计工具。针对 Symfony 常见 security.yaml、CSRF、Twig/Twig raw、表达式与访问控制等框架机制做白盒静态审计,并将风险映射到通用漏洞类型体系(AUTH/CSRF/CFG/XSS/TPL/LOGIC 等)。
langbyyi/CyberStrikeAI-SRC
Automate low-impact web vulnerability verification through Burp MCP.
langbyyi/CyberStrikeAI-SRC
Authentication bypass testing playbook. An agent skill from langbyyi/CyberStrikeAI-SRC.
langbyyi/CyberStrikeAI-SRC
Source control and artifact exposure (.git, .svn, .hg, backups, .env).
langbyyi/CyberStrikeAI-SRC
PHP type juggling and weak comparison (==) bypass. An agent skill from langbyyi/CyberStrikeAI-SRC.
langbyyi/CyberStrikeAI-SRC
WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws.
langbyyi/CyberStrikeAI-SRC
XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces.
Works with
Categories
HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks. HTTP Parameter Pollution is an agent skill from langbyyi/CyberStrikeAI-SRC. HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks.
HTTP Parameter Pollution fits situations like: filters and application layers disagree on which value wins; enabling bypass; SSRF second URL; CSRF token confusion.
Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill http-parameter-pollution -a claude-code`. Or copy the skill folder (skills/http-parameter-pollution in langbyyi/CyberStrikeAI-SRC) into .claude/skills/http-parameter-pollution in your project. Claude Code loads it when a task matches its description.
Run `npx skills add langbyyi/CyberStrikeAI-SRC --skill http-parameter-pollution -a codex`. Or copy the skill folder (skills/http-parameter-pollution in langbyyi/CyberStrikeAI-SRC) into .agents/skills/http-parameter-pollution in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add langbyyi/CyberStrikeAI-SRC --skill http-parameter-pollution -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/http-parameter-pollution, .gemini/skills/http-parameter-pollution, .github/skills/http-parameter-pollution and .opencode/skills/http-parameter-pollution in your project.
SKILL.md names no scripts, command-line tools or credentials: HTTP Parameter Pollution is instructions for the agent only. Our summary lists: Python 3; Node.js.
SKILL.md names 1 domain. In commands or code: allowed.host; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
HTTP Parameter Pollution is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with HTTP Parameter Pollution: Code Audit (3stoneBrother/code-audit, 893 stars), Php Codeigniter Audit (0xShe/PHP-Code-Audit-Skill, 402 stars), Web (MuWinds/BUUCTF_Agent, 267 stars) and Security Review (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
langbyyi (a GitHub user) maintains it in langbyyi/CyberStrikeAI-SRC, which has 133 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on September 27, 2026.
Source: langbyyi/CyberStrikeAI-SRC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.