file-upload-and-ssrf
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes instructional command-line examples using
curlto test for Server-Side Request Forgery (SSRF) and to verify the execution of uploaded files on a target server. These commands are templates provided for the agent to interact with a user-specified target application as part of a security audit. - [SAFE]: The skill follows security testing best practices by including clear authorization warnings and recommending the use of benign canaries rather than destructive payloads.
- [SAFE]: No evidence of prompt injection, data exfiltration, or obfuscation was found. The skill's technical content is consistent with its stated purpose as a vulnerability research and penetration testing guide.
Audit Metadata