SSRF Audit

Installation
SKILL.md

phy-ssrf-audit

Static scanner for OWASP A10:2021 — Server-Side Request Forgery (SSRF) vulnerabilities. Finds all URL-fetching sinks in your codebase, traces HTTP input to those sinks, and checks for missing allowlist/blocklist guards. Flags hardcoded cloud metadata endpoint access as CRITICAL. Zero external API calls, zero dependencies beyond Python 3 stdlib.

Why SSRF Matters in 2026

SSRF lets attackers force your server to fetch internal URLs, bypassing firewalls and reaching:

  • AWS IMDS (169.254.169.254) → steal IAM credentials, account ID, region
  • GCP metadata (metadata.google.internal) → steal service account tokens
  • Azure IMDS (169.254.169.254/metadata/instance) → steal managed identity tokens
  • Internal services → Redis, Elasticsearch, Kubernetes API without auth
  • Private network scanning → map internal topology via timing side-channels

Real-world examples: Capital One breach (2019), GitLab SSRF (CVE-2021-22214), Confluence SSRF (CVE-2022-26134 adjacent).

What It Detects

Installs
4
First Seen
Apr 22, 2026
SSRF Audit from skills.volces.com