SSRF Audit
Installation
SKILL.md
phy-ssrf-audit
Static scanner for OWASP A10:2021 — Server-Side Request Forgery (SSRF) vulnerabilities. Finds all URL-fetching sinks in your codebase, traces HTTP input to those sinks, and checks for missing allowlist/blocklist guards. Flags hardcoded cloud metadata endpoint access as CRITICAL. Zero external API calls, zero dependencies beyond Python 3 stdlib.
Why SSRF Matters in 2026
SSRF lets attackers force your server to fetch internal URLs, bypassing firewalls and reaching:
- AWS IMDS (
169.254.169.254) → steal IAM credentials, account ID, region - GCP metadata (
metadata.google.internal) → steal service account tokens - Azure IMDS (
169.254.169.254/metadata/instance) → steal managed identity tokens - Internal services → Redis, Elasticsearch, Kubernetes API without auth
- Private network scanning → map internal topology via timing side-channels
Real-world examples: Capital One breach (2019), GitLab SSRF (CVE-2021-22214), Confluence SSRF (CVE-2022-26134 adjacent).