skills/mukul975/anthropic-cybersecurity-skills/exploiting-server-side-request-forgery/Gen Agent Trust Hub
exploiting-server-side-request-forgery
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous shell commands and a Python script using the requests library to send HTTP requests to sensitive internal and cloud-based endpoints for vulnerability verification.
- [EXTERNAL_DOWNLOADS]: The documentation references external security tools, providing commands to install interactsh-client via the Go package manager and clone the SSRFmap repository from GitHub.
- [DATA_EXFILTRATION]: The tool is designed to probe for sensitive system data on remote hosts, including AWS/GCP/Azure instance metadata (IAM credentials) and local system files like /etc/passwd, as part of the SSRF exploitation workflow.
Audit Metadata