Works with the AI tools you already use
Repair Redirect Credential Leakage
Repair HTTP redirect credential leaks where Authorization, cookies, API keys, proxy credentials, or signed headers cross origin, host, port, or HTTPS-to-HTTP boundaries.
$5
Repair Redirect Credential Leakage
Example session with this skill installed
Inspect this HTTP client for redirect credential leakage. Authorization must remain on approved same-origin redirects but be stripped before cross-origin or downgrade dispatch. Use two local loopback servers and redacted assertions. Preserve redirect status handling, retries, timeouts, TLS checks, and body replay policy.
- Read your context and instructions
- Compiled the repair redirect credential
Redirect boundary defect found. The client changes the URL but reuses an Authorization-bearing shared header map, so a cross-origin 302 receives API credentials and later retries inherit redirect-local mutations. The repair computes the full origin per hop, clones headers per attempt, strips target-inappropriate credentials before dispatch, preserves same-origin behavior and all replay/retry/timeout/TLS rules, and validates both servers without recording secret values.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The problem
HTTP clients and SDKs often leak sensitive Authorization, Cookie, or Proxy headers when following redirects to external domains or insecure schemes. These vulnerabilities expose API keys and session tokens to untrusted third-party hosts or man-in-the-middle attackers.
What it does
- Audits redirect callbacks and request cloning logic for credential persistence across authority boundaries.
- Implements per-hop credential stripping for cross-origin, host, port, or scheme transitions.
- Isolates request clones to prevent state contamination during retries or concurrent execution.
- Adds deterministic loopback tests and redacted observability to verify fix efficacy without logging secrets.
- Patches 301-308 status code handling to ensure method and body replay policies remain intact.
Frameworks & tools
Works with any language or HTTP stack including Node.js (Axios/Fetch), Python (Requests/httpx), Go (net/http), and custom SDK wrappers.
Why this beats prompting it yourself
Standard LLM prompts often suggest "just disable redirects" or provide incomplete regex checks that fail on edge cases like port changes or subdomains. This skill follows a rigorous protocol to preserve approved same-origin behavior and timeout budgets while enforcing strict authority validation before dispatch.
Use cases
- Fixing signed request headers that persist after a CDN or object storage redirect.
- Preventing HTTPS-to-HTTP downgrade attacks that leak cookies.
- Hardening API wrappers where shared request objects contaminate retry attempts.
- Refactoring legacy SDKs to strip Proxy-Authorization headers on target changes.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 1 month ago
- Passed all security checks, Safe to install