ssrf-server-side-request-forgery

Fail

Audited by Socket on Jul 21, 2026

2 alerts found:

Malwarex2
MalwareHIGH
SKILL.md

High-risk offensive security skill. Its capabilities align with its stated purpose, but that purpose is to help an AI agent perform SSRF exploitation, secret extraction, internal service abuse, and potential RCE; it also references known callback capture services. Not a supply-chain lure, but dangerous and inappropriate for broad agent use.

Confidence: 97%Severity: 98%
MalwareHIGH
URL_PARSER_TRICKS.md

The provided fragment is exploit-instruction content detailing SSRF/DNS rebinding and weaponization against internal services, including cloud metadata harvesting and persistence/RCE steps (cron/authorized_keys/webshell). While no executable dependency code is shown, inclusion of this material in a software package is a severe supply-chain red flag and warrants immediate review of the actual package files (entrypoints, install/postinstall scripts, dynamic execution, and network/file/command usage). Treat as potentially malicious/exploitation-facilitating content; confirm intent by examining the surrounding repository/published artifacts.

Confidence: 62%Severity: 85%
Audit Metadata
Analyzed At
Jul 21, 2026, 01:28 PM
Package URL
pkg:socket/skills-sh/strivepan-svg%2Fhack-skills%2Fssrf-server-side-request-forgery%2F@b15a94c95c62985dbb63295642547b49bf8d68118adf76263c54ed16ee9f4b8e
Security Audit — socket — ssrf-server-side-request-forgery