ssrf
Fail
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: CRITICALCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides
grepcommands to help auditors find network request functions in source code. These commands are diagnostic and used within the local environment. - [SAFE]: The automated security alert for
references/sinks.md(HttpRequest-inf) is a heuristic detection of the HTTP request function names (e.g.,fetch,axios,requests) listed in a reference table. These are legitimate auditing patterns given the skill's purpose. - [SAFE]: Content within
poc-skeleton.mdcontains example code and URLs for cloud metadata services (e.g., AWS, GCP, Azure). These are instructional templates for security professionals and are not executed or accessed by the skill's operational logic.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
Audit Metadata