ssrf

Warn

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides instructions for targeting sensitive files during exploitation, including system files like /etc/passwd, /etc/hostname, and /proc/self/environ.
  • [DATA_EXFILTRATION]: Instructs the agent on how to retrieve cloud and local credential files such as ~/.aws/credentials and ~/.ssh/id_rsa.
  • [COMMAND_EXECUTION]: Provides a Python one-liner for a local HTTP redirect server used in Time-of-Check-Time-of-Use (TOCTOU) exploitation.
  • [EXTERNAL_DOWNLOADS]: References external security testing and Out-of-Band (OOB) services including interactsh.com, oastify.com, r3dir.me, and 1u.ms.
  • [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface by processing untrusted data from target applications and external state management systems.
  • Ingestion points: Target server responses, input parameters (URL, src, href, etc.), and the get_state_summary() MCP server.
  • Boundary markers: No explicit boundary markers or instructions to disregard embedded commands in the processed data are present.
  • Capability inventory: Execution of security tools (burpsuite, ssrfmap, gopherus, interactsh) and writing data to the engagement/evidence/ directory.
  • Sanitization: No sanitization or validation of external content is specified before processing or logging.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 6, 2026, 09:15 AM
Security Audit — agent-trust-hub — ssrf