ssrf-server-side-request-forgery

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH RISK. This skill is internally consistent as an SSRF exploitation playbook, but its purpose is to equip an AI agent with offensive security and exfiltration techniques, including cloud credential theft, local secret access, OOB callbacks, and SSRF-to-RCE chains. No hidden installer or stealth behavior is present, so this is not confirmed malware, but it is a high-risk offensive skill.

Confidence: 96%Severity: 88%
AnomalyLOW
URL_PARSER_TRICKS.md

The provided content is not executable dependency code; it is an exploit/payload documentation fragment describing SSRF/DNS-rebinding techniques with highly actionable payloads targeting internal services and cloud metadata for credential theft, persistence, and webshell deployment. While this excerpt alone does not prove that the dependency executes malware, it is a serious supply-chain governance red flag (exploit enablement/weaponized content).

Confidence: 62%Severity: 67%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:15 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fssrf-server-side-request-forgery%2F@dd9bc88bb1048a3d0e74dd16fc6eec5fe0b6e23be4903bf5de2aacc0859643b2
Security Audit — socket — ssrf-server-side-request-forgery