ssrf-hunter

Warn

Audited by Socket on Aug 22, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its capabilities align with its stated purpose, but that purpose is offensive SSRF exploitation: cloud credential theft, internal scanning, file access, and OOB exfiltration. Official dependencies are limited, yet the skill materially enables unauthorized compromise and data exfiltration rather than safe defensive assessment.

Confidence: 95%Severity: 93%
SecurityMEDIUM
scripts/ssrf_agent.py

This file implements an offensive SSRF testing/exploitation agent with payloads targeting cloud instance metadata and credential/token endpoints, internal service/port enumeration, SSRF bypass attempts, and file/gopher/dict protocol handler probes. It disables TLS verification (verify=False) and records response previews and headers into logs/report JSON, which may capture sensitive data returned via SSRF. While it is not overtly malware (no persistence/exfil code in the local script), its functionality is high-risk and should be treated as dangerous/dual-use in a dependency context.

Confidence: 74%Severity: 82%
Audit Metadata
Analyzed At
Aug 22, 2026, 08:11 AM
Package URL
pkg:socket/skills-sh/rifteo%2Fskills%2Fssrf-hunter%2F@bb651f1129945ba48504813ac41dc14978616302402181b98b6c9c9ac8c76afa
Security Audit — socket — ssrf-hunter