CR

crlf-injection

An expert playbook for identifying and exploiting CRLF injection vulnerabilities.

Install

mkdir -p .claude/skills/crlf-injection && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/17048" && unzip -o skill.zip -d .claude/skills/crlf-injection && rm skill.zip

Installs to .claude/skills/crlf-injection

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

>-
2 chars · catalog descriptionno explicit “when” trigger
Advanced

Key capabilities

  • →Detect CRLF injection using basic probes
  • →Identify response body injection via double CRLF
  • →Exploit session fixation through Set-Cookie injection
  • →Achieve XSS via response body injection
  • →Perform cache poisoning by injecting headers/body

How it works

The skill identifies vulnerabilities where unsanitized user input containing CRLF characters can split HTTP headers or inject content into the response body.

Inputs & outputs

You give it
User input reflected in HTTP response headers, Location redirects, Set-Cookie values, or log files
You get back
Injected headers, response body, XSS payload execution, session fixation, or cache poisoning

When to use crlf-injection

  • →Test for CRLF injection
  • →Check for HTTP response splitting
  • →Validate header input sanitation
  • →Assess cache poisoning risks

About crlf-injection

Details the process of identifying CRLF injection, including how to probe for header splitting and body injection. It provides guidance on detection techniques and exploitation scenarios like session fixation and cache poisoning.

>-

When not to use it

  • →When user input does not reach HTTP response headers, Location redirects, Set-Cookie values, or log files
  • →When carriage-return/line-feed characters cannot split or inject content

Limitations

  • →The skill relies on user input being reflected in specific HTTP contexts
  • →The skill's effectiveness depends on the server's handling of CRLF characters
  • →The skill does not bypass all filtering mechanisms

How it compares

This skill provides a structured playbook for detecting and exploiting CRLF injection, unlike general vulnerability scanning.

Compared to similar skills

crlf-injection side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
crlf-injection (this skill)05moNo flagsAdvanced
reverse-engineering-tools735moNo flagsAdvanced
game-hacking-techniques424moNo flagsAdvanced
solidity-security154moNo flagsIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

reverse-engineering-tools

gmh5225

Guide for reverse engineering tools and techniques used in game security research. Use this skill when working with debuggers, disassemblers, memory analysis tools, binary analysis, or decompilers for game security research.

73204

game-hacking-techniques

gmh5225

Guide for game hacking techniques and cheat development. Use this skill when researching memory manipulation, code injection, ESP/aimbot development, overlay rendering, or game exploitation methodologies.

42128

solidity-security

wshobson

Master smart contract security best practices to prevent common vulnerabilities and implement secure Solidity patterns. Use when writing smart contracts, auditing existing contracts, or implementing security measures for blockchain applications.

15115

1password

openclaw

Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.

2799

senior-security

davila7

Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.

3191

ghidra

mitsuhiko

Reverse engineer binaries using Ghidra's headless analyzer. Decompile executables, extract functions, strings, symbols, and analyze call graphs without GUI.

16105

Search skills

Search the agent skills registry