performing-blind-ssrf-exploitation

Fail

Audited by Socket on Apr 12, 2026

1 alert found:

Malware
MalwareHIGH
references/api-reference.md

The provided code is strongly indicative of malicious/offensive intent: it actively crafts SSRF probe requests, includes OOB callback confirmation infrastructure, performs blind timing-based detection, executes internal port scanning via SSRF, and supplies multiple SSRF bypass payload formats targeting high-value metadata and internal services. If included in a dependency, it represents a high misuse/security risk. Malware behavior (e.g., credential theft code) is not directly demonstrated, but the exploitation workflow is directly usable for credential/data exposure via SSRF.

Confidence: 80%Severity: 92%
Audit Metadata
Analyzed At
Apr 12, 2026, 06:20 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fperforming-blind-ssrf-exploitation%2F@e1f407b755dc9ca13ad40dc884ded721621ffac9
Security Audit — socket — performing-blind-ssrf-exploitation