exploiting-server-side-request-forgery

Fail

Audited by Socket on Mar 15, 2026

2 alerts found:

Obfuscated FileSecurity
Obfuscated FileHIGH
references/api-reference.md

This tool is a dual-use SSRF assessment agent that explicitly contains high-risk test capabilities (cloud metadata probing, internal port scanning, alternate protocol testing). The provided fragment shows no signs of obfuscation or deliberate malicious backdoors in itself, but its features can be weaponized if misused. Use strictly in authorized contexts and review the full implementation for safeguards (consent, rate limiting, careful defaults, no exfiltration helpers) before deployment.

Confidence: 98%
SecurityMEDIUM
SKILL.md

The skill is internally consistent with its stated penetration-testing purpose, but it is a high-risk offensive security skill. It equips an AI agent to scan internal networks, trigger OOB callbacks, retrieve cloud metadata credentials, and abuse internal services; the main concern is dangerous capability, not deception.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 15, 2026, 01:30 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fexploiting-server-side-request-forgery%2F@673fef748c2e0b1faf7a1becb73393725d926b6a