exploiting-server-side-request-forgery

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides numerous shell commands and a Python script using the requests library to send HTTP requests to sensitive internal and cloud-based endpoints for vulnerability verification.
  • [EXTERNAL_DOWNLOADS]: The documentation references external security tools, providing commands to install interactsh-client via the Go package manager and clone the SSRFmap repository from GitHub.
  • [DATA_EXFILTRATION]: The tool is designed to probe for sensitive system data on remote hosts, including AWS/GCP/Azure instance metadata (IAM credentials) and local system files like /etc/passwd, as part of the SSRF exploitation workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 06:47 PM