ssrf-server-side-request-forgery
Audited by Socket on Jul 21, 2026
2 alerts found:
Malwarex2High-risk offensive security skill. Its capabilities align with its stated purpose, but that purpose is to help an AI agent perform SSRF exploitation, secret extraction, internal service abuse, and potential RCE; it also references known callback capture services. Not a supply-chain lure, but dangerous and inappropriate for broad agent use.
The provided fragment is exploit-instruction content detailing SSRF/DNS rebinding and weaponization against internal services, including cloud metadata harvesting and persistence/RCE steps (cron/authorized_keys/webshell). While no executable dependency code is shown, inclusion of this material in a software package is a severe supply-chain red flag and warrants immediate review of the actual package files (entrypoints, install/postinstall scripts, dynamic execution, and network/file/command usage). Treat as potentially malicious/exploitation-facilitating content; confirm intent by examining the surrounding repository/published artifacts.