ssrfmap
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions to clone an external repository (https://github.com/swisskyrepo/SSRFmap) and execute the contained Python scripts, facilitating the execution of unverified code.
- [EXTERNAL_DOWNLOADS]: It installs third-party software and dependencies from non-trusted sources, specifically using
pip3 installfor thegopheruspackage and a requirements file from the cloned repository. - [DATA_EXFILTRATION]: The instructions detail how to exfiltrate sensitive data, including local system files (e.g., /etc/passwd) and cloud provider metadata (e.g., AWS/GCP/Azure IMDS endpoints), which could expose credentials.
- [COMMAND_EXECUTION]: The skill describes methods to abuse the Gopher protocol to interact with and exploit internal services like Redis, MySQL, and FastCGI, potentially leading to unauthorized command execution or remote shells on target infrastructure.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, user-provided HTTP request files (
request.txt) to drive automated exploitation logic, creating a surface for indirect injection if the content of these files is not properly sanitized. - Ingestion points:
request.txt(SKILL.md) - Boundary markers: None
- Capability inventory: Subprocess execution of
python3for tool automation, network operations viassrfmap.pyto external and internal targets, and local file system access for reading request files. - Sanitization: No sanitization or validation of the request file contents is described before they are processed by the exploitation tools.
Recommendations
- AI detected serious security threats
Audit Metadata