web-vuln-ssrf
Audited by Socket on Aug 19, 2026
2 alerts found:
Securityx2SUSPICIOUS. The skill’s capabilities match its stated purpose, but that purpose is an offensive security workflow for AI agents: it actively probes targets, bypasses SSRF filters, tests file/gopher access, and attempts cloud metadata and credential extraction. Install provenance is mostly legitimate, but the external OOB service, disabled TLS checks, sensitive token handling, and autonomous exploit guidance make the overall security risk high.
This fragment is non-executable instructional content that nonetheless provides highly actionable SSRF bypass payloads and cloud metadata exploitation paths (AWS/GCP/Azure), including clear escalation concepts toward credential theft and potential RCE via internal services. While it does not demonstrate runtime malicious behavior by itself, its operational specificity and offense-oriented nature make it a significant supply-chain security concern and should be treated as suspicious/harmful packaging content pending context on how the dependency is used.