Url Parser Confusion Testing

Detect SSRF filter bypasses and URL-parsing inconsistencies caused by malformed URL syntax — triple-slash (http:///host/path), backslashes, encoded delimiters, userinfo, numeric IP forms, IPv4-mapped IPv6. Use when reviewing URL validation, hostname allowlists, SSRF protections, redirect handling, or any code that parses user-supplied URLs (curl/libcurl CURLU, WHATWG URL, Python urllib, Node, Go, Java). Reproduces and extends HackerOne

SecurityTalent Updated

File contents

SecurityTalent/bugskill-ai/tree/main/Personal-Claude-Code-Agent-Skills/url-parser-confusion-testing commit da8663a596

Frequently asked questions

npx skillmds@latest add securitytalent/url-parser-confusion-testing