htmx
Provides HTMX development guidelines for dynamic web applications. Uses HTML attributes to enable interactions with minimal JavaScript.
Your agent can do more. Find the skill that makes it happen.
Find your next superpower If you are an agent, refer to our llms.txt for full access.Provides HTMX development guidelines for dynamic web applications. Uses HTML attributes to enable interactions with minimal JavaScript.
Covers applications that trust the Host header for URL generation, request routing, or access control. Examines password reset poisoning, web cache poisoning, routing-based SSRF, and virtual host bypass.
Covers inconsistencies in parsing duplicate query or body keys across servers, proxies, WAFs, and frameworks. Examines resulting bypasses, SSRF, logic abuse, and CSRF token confusion.
HTTP request smuggling exploits disagreements between a front-end proxy and back-end server on where one HTTP request ends and the next begins, using conflicting Content-Length and Transfer-Encoding: chunked headers (CL.TE, TE.CL, TE.TE variants). Enables bypassing access controls, cache poisoning, session hijacking, and capturing other users' requests. Detect via timing attacks, differential …
Identify and exploit HTTP Request Smuggling (HTTP Desync) vulnerabilities caused by discrepancies in how front-end proxies (load balancers, CDNs) and back-end servers parse the Content-Length and Transfer-Encoding headers. Use this to bypass security controls, hijack user sessions, and poison web caches.
Exploit advanced HTTP Request Smuggling combining Transfer-Encoding vulnerabilities (TE.TE). By obscuring the Transfer-Encoding header, an attacker forces desynchronization between a frontend proxy (which processes the request one way) and the backend server (which processes it another way), allowing the smuggling of malicious requests to bypass security controls or poison caches.
Analyzes binary framing, HPACK compression, h2c upgrade smuggling, pseudo-header injection, and stream multiplexing abuse. Also covers downgrade translation flaws between HTTP/2 and HTTP/1.
Covers named, typed, and keyed clients, DelegatingHandlers, and Microsoft.Extensions.Http.Resilience. Supports retries, circuit breakers, hedging, and HTTP client testing.
Produces a one-page Huawei Cloud BSS billing briefing covering balances, spending attribution, reconciliation, coupons, stored-value cards, and enterprise or partner accounts. Excludes payments, renewals, refunds, deletion, pricing quotes, and non-billing tasks.
Manages the lifecycle of CCI namespaces, networks, deployments, StatefulSets, pods, and public IP pools through the hcloud CLI. Includes status, logs, and metrics, with two-step confirmation for destructive operations.
Provides read-only queries for ECS, BMS, IMS, and AS resources. Covers instances, flavors, quotas, images, network interfaces, scaling configurations and policies, activity logs, lifecycle hooks, and warm pools.
Searches and lists Huawei Cloud agent skills and their categories. Helps identify relevant skills, explain their scope, and install them.
Skills give your agent reusable instructions for a specific job. Pick one, read what it does, and bring it into your workflow.
A name only tells half the story. Search the full description and instructions to find the right fit.
Read the skill, visit its source, and see exactly what you’re adding to your agent.
Copy the install command from a skill page and run it in your project.
npx skillycli add owner/repo --skill name