competition-request-normalization-smugglinglisted
Install: claude install-skill Saprophytic-seattle561/reverse-skill
# Competition Request Normalization Smuggling
Use this skill only as a downstream specialization after `$ctf-sandbox-orchestrator` is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to `$ctf-sandbox-orchestrator` first.
Use this skill when request interpretation changes between proxy, middleware, and backend parser layers.
Reply in Simplified Chinese unless the user explicitly requests English.
## Quick Start
1. Map every parsing hop: client-facing proxy, gateway, app server, and downstream service.
2. Record path normalization, header canonicalization, transfer framing, and host derivation at each hop.
3. Capture one accepted baseline request and one differential request with minimal delta.
4. Prove which hop interprets the request differently.
5. Reproduce one minimal differential path that yields decisive behavior.
## Workflow
### 1. Map Parse And Routing Boundaries
- Record `Host`, forwarded headers, path decoding, slash collapsing, dot-segment handling, and case behavior.
- Note `Content-Length`, `Transfer-Encoding`, chunk framing, and connection reuse behavior when relevant.
- Keep edge parser and backend parser decisions side by side.
### 2. Prove Differential Interpretation
- Build paired requests that differ in one canonicalization dimension only.
- Capture proxy logs, backend logs, route match, and downstream request shape.
- Show where route, auth scope, or body boundary