skills/aeondave/malskill/ssrfmap/Gen Agent Trust Hub

ssrfmap

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to clone an external repository (https://github.com/swisskyrepo/SSRFmap) and execute the contained Python scripts, facilitating the execution of unverified code.
  • [EXTERNAL_DOWNLOADS]: It installs third-party software and dependencies from non-trusted sources, specifically using pip3 install for the gopherus package and a requirements file from the cloned repository.
  • [DATA_EXFILTRATION]: The instructions detail how to exfiltrate sensitive data, including local system files (e.g., /etc/passwd) and cloud provider metadata (e.g., AWS/GCP/Azure IMDS endpoints), which could expose credentials.
  • [COMMAND_EXECUTION]: The skill describes methods to abuse the Gopher protocol to interact with and exploit internal services like Redis, MySQL, and FastCGI, potentially leading to unauthorized command execution or remote shells on target infrastructure.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, user-provided HTTP request files (request.txt) to drive automated exploitation logic, creating a surface for indirect injection if the content of these files is not properly sanitized.
  • Ingestion points: request.txt (SKILL.md)
  • Boundary markers: None
  • Capability inventory: Subprocess execution of python3 for tool automation, network operations via ssrfmap.py to external and internal targets, and local file system access for reading request files.
  • Sanitization: No sanitization or validation of the request file contents is described before they are processed by the exploitation tools.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 5, 2026, 10:41 PM
Security Audit — agent-trust-hub — ssrfmap