Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIGitHub CopilotGitHub CopilotGemini CLIGemini CLI+20 more

    Repair Redirect Credential Leakage

    1

    Repair HTTP redirect credential leaks where Authorization, cookies, API keys, proxy credentials, or signed headers cross origin, host, port, or HTTPS-to-HTTP boundaries.

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    0 installsSecurity scanned
    Repair Redirect Credential Leakage

    Repair Redirect Credential Leakage

    Example session with this skill installed

    Inspect this HTTP client for redirect credential leakage. Authorization must remain on approved same-origin redirects but be stripped before cross-origin or downgrade dispatch. Use two local loopback servers and redacted assertions. Preserve redirect status handling, retries, timeouts, TLS checks, and body replay policy.

    • Read your context and instructions
    • Compiled the repair redirect credential

    Redirect boundary defect found. The client changes the URL but reuses an Authorization-bearing shared header map, so a cross-origin 302 receives API credentials and later retries inherit redirect-local mutations. The repair computes the full origin per hop, clones headers per attempt, strips target-inappropriate credentials before dispatch, preserves same-origin behavior and all replay/retry/timeout/TLS rules, and validates both servers without recording secret values.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Prevent API key leakage to untrusted third-party hosts during redirects.Strip sensitive cookies when a request downgrades from HTTPS to HTTP.Isolate request clones to stop header contamination in retry logic.Add redacted metrics to track redirect rejections without logging tokens.

    About this skill

    The problem

    HTTP clients and SDKs often leak sensitive Authorization, Cookie, or Proxy headers when following redirects to external domains or insecure schemes. These vulnerabilities expose API keys and session tokens to untrusted third-party hosts or man-in-the-middle attackers.

    What it does

    • Audits redirect callbacks and request cloning logic for credential persistence across authority boundaries.
    • Implements per-hop credential stripping for cross-origin, host, port, or scheme transitions.
    • Isolates request clones to prevent state contamination during retries or concurrent execution.
    • Adds deterministic loopback tests and redacted observability to verify fix efficacy without logging secrets.
    • Patches 301-308 status code handling to ensure method and body replay policies remain intact.

    Frameworks & tools

    Works with any language or HTTP stack including Node.js (Axios/Fetch), Python (Requests/httpx), Go (net/http), and custom SDK wrappers.

    Why this beats prompting it yourself

    Standard LLM prompts often suggest "just disable redirects" or provide incomplete regex checks that fail on edge cases like port changes or subdomains. This skill follows a rigorous protocol to preserve approved same-origin behavior and timeout budgets while enforcing strict authority validation before dispatch.

    Use cases

    • Fixing signed request headers that persist after a CDN or object storage redirect.
    • Preventing HTTPS-to-HTTP downgrade attacks that leak cookies.
    • Hardening API wrappers where shared request objects contaminate retry attempts.
    • Refactoring legacy SDKs to strip Proxy-Authorization headers on target changes.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 1 month ago

    • Passed all security checks, Safe to install

    Listed1 month ago
    Updatedtoday

    What's inside

    Frequently Asked Questions