hunt-ssrf

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [OBFUSCATION]: The skill uses Base64 encoding for illustrative purposes, demonstrating how to bypass filters in a target application. For example, 'aHR0cDovLzE2OS4yNTQuMTY5LjI1NC8=' decodes to a cloud metadata IP. These examples are relevant to the skill's primary purpose of security research.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines processes for ingesting data from external network interactions. While this provides a potential surface for injection, the skill advocates for out-of-band (OOB) validation to ensure integrity and prevent misinterpretation of echoed data.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: Provides documentation on using external security tools like curl, ffuf, and interactsh-client. These are standard tools for security assessments and are intended for manual execution by the user.
  • [DYNAMIC_EXECUTION]: Includes code snippets for JavaScript-based exfiltration and a Python redirect server. These are educational examples and do not constitute automated execution of untrusted code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 11:03 PM
Security Audit — agent-trust-hub — hunt-ssrf