ssrf

Fail

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: CRITICAL
Full Analysis
  • [SAFE]: The skill is entirely informational, providing documentation on SSRF vulnerabilities and security testing methodologies. It does not contain executable scripts or automated logic that performs these actions without user guidance.
  • [DATA_EXPOSURE]: The documentation references sensitive file paths (e.g., /etc/passwd, /etc/hosts, /proc/self/environ, win.ini) and cloud metadata endpoints (e.g., 169.254.169.254, metadata.google.internal) exclusively as example payloads for vulnerability testing.
  • [COMMAND_EXECUTION]: The skill lists curl commands as practical examples for manual verification of internal service access (e.g., Redis, MongoDB, Docker). These are documented for use by a security researcher and are not executed by the skill itself.
  • [OBFUSCATION]: The skill describes various IP and URL encoding techniques (decimal, octal, hex, and URL parser confusion) as methods to bypass security filters. These are provided for educational purposes to demonstrate how SSRF mitigations can be circumvented.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 22, 2026, 05:35 PM
Security Audit — agent-trust-hub — ssrf