ssrfmap

Fail

Audited by Socket on Sep 5, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent as an SSRF exploitation guide, but its actual capability set is an offensive security toolkit for an AI agent: internal port scanning, cloud metadata extraction, service abuse, and possible callback/reverse-shell workflows. The third-party collaborator endpoint and complementary exploit tooling raise risk, while install provenance is mostly same-project/open-source rather than covert or clearly malicious.

Confidence: 92%Severity: 78%
MalwareHIGH
references/ssrf-bypass.md

This fragment is a plain-text, exploitation-oriented payload catalog for SSRF bypassing. It explicitly targets localhost/private IP representations, cloud instance metadata endpoints associated with credential/user-data theft, and includes dangerous non-HTTP schemes (gopher/file/dict/etc.) and internal port guidance to enable internal discovery and data exfiltration in a vulnerable context. Even though there is no executable logic here, its content materially increases attack capability and should be treated as high-risk if present in an operational dependency.

Confidence: 88%Severity: 98%
Audit Metadata
Analyzed At
Sep 5, 2026, 10:45 PM
Package URL
pkg:socket/skills-sh/aeondave%2Fmalskill%2Fssrfmap%2F@323f62a4a405f1da4f84856a0a8527b0e60cf520d7ab1a2916d4b0619033e8c6
Security Audit — socket — ssrfmap