exploiting-ssrf
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes shell command snippets using
rg(ripgrep) to identify potentially vulnerable parameters and outbound HTTP calls within source code repositories. - [COMMAND_EXECUTION]: Provides a
curlscript designed to perform timing-based internal port scanning to identify services running on the loopback interface or internal network. - [DATA_EXFILTRATION]: Outlines procedures for retrieving sensitive credentials from cloud metadata services (IMDS) on AWS, Azure, and GCP, which is a standard objective in SSRF exploitation scenarios on target systems.
- [INDIRECT_PROMPT_INJECTION]: The skill involves processing user-influenced URLs and source code, creating a potential surface for indirect injection if the agent were to blindly trust the contents of the files it audits, though the risk is low given the intended auditing context.
Audit Metadata