web-ssrf
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill is internally consistent as an SSRF exploitation guide, but it gives an AI agent explicit offensive security instructions, uses OAST callback collectors, and describes escalation to cloud metadata, credential theft, and RCE. There is little supply-chain concern, but the capability itself is high risk and inappropriate outside authorized security testing.
Confidence: 95%Severity: 91%
Audit Metadata