LogoClawIndex
CasesSkillsAbout
LogoClawIndex

hunting-host-header-and-url-parsing-trust - Hunt host header and URL parsing trust vulnerabilities

Audit trust in Host/forwarded headers and URL parser differentials across links, cache keys, routers, and allowlists.

Tags

Updated: 2026-09-23

Capabilities

Typical Inputs

Typical Outputs

What this skill does

  • Establish origin of request host
  • Map host and URL consumers
  • Separate header trust from parser differentials
  • Evaluate consumer vulnerability impact
  • Verify defensive validation controls
  • Confirm vulnerabilities with crafted requests

Inputs

  • HTTP requests with Host headers
  • Application URL parser implementations
  • Configured base URLs and allowlists
  • Isolated test environment

Outputs

  • Poisoned links in outbound messages
  • Reflected hosts in cached responses
  • Routing logs to internal vhosts
  • Vulnerability audit findings or kill reasons

Requirements

  • Authorization for target system assessment
  • Non-production isolated infrastructure
  • Control over a benign domain

Source

  • Spec: SKILL.md

ClawIndex

OpenClaw Skills & Use Case Index

ClawIndex is an ecosystem-driven index of OpenClaw skills and real-world use cases.

Index

Skills·
Cases

Meta

About·
Disclaimer·
Email·
GitHub
© 2026 ClawIndex All Rights Reserved.
security-audit
host-header-injection
url-parsing
cache-poisoning
web-vulnerabilities
Establish origin of request host
Map host and URL consumers
Separate header trust from parser differentials
Evaluate consumer vulnerability impact
HTTP requests with Host headers
Application URL parser implementations
Configured base URLs and allowlists
Poisoned links in outbound messages
Reflected hosts in cached responses
Routing logs to internal vhosts