exploiting-ssrf

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes shell command snippets using rg (ripgrep) to identify potentially vulnerable parameters and outbound HTTP calls within source code repositories.
  • [COMMAND_EXECUTION]: Provides a curl script designed to perform timing-based internal port scanning to identify services running on the loopback interface or internal network.
  • [DATA_EXFILTRATION]: Outlines procedures for retrieving sensitive credentials from cloud metadata services (IMDS) on AWS, Azure, and GCP, which is a standard objective in SSRF exploitation scenarios on target systems.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves processing user-influenced URLs and source code, creating a potential surface for indirect injection if the agent were to blindly trust the contents of the files it audits, though the risk is low given the intended auditing context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 08:23 PM
Security Audit — agent-trust-hub — exploiting-ssrf