file-upload-and-ssrf

Fail

Audited by Socket on Jun 12, 2026

2 alerts found:

MalwareSecurity
MalwareHIGH
references/upload-ssrf-recipes.md

This fragment is not benign software functionality; it is an offensively oriented exploitation playbook targeting file upload bypass, SSRF (including cloud metadata/IMDS access), and insecure deserialization confirmation via OOB callbacks/gadget concepts. If distributed via a software dependency, it creates a high facilitation risk for real-world exploitation despite the absence of directly embedded executable code.

Confidence: 60%Severity: 90%
SecurityMEDIUM
SKILL.md
Audit Metadata
Analyzed At
Jun 12, 2026, 09:04 PM
Package URL
pkg:socket/skills-sh/mn-youssef%2Fsecurity-skills%2Ffile-upload-and-ssrf%2F@3f4ee7a57642b60a5d04284f2087857d9428d609d7580def5667646487765352
Security Audit — socket — file-upload-and-ssrf