exploiting-server-side-request-forgery
Audited by Socket on Mar 15, 2026
2 alerts found:
Obfuscated FileSecurityThis tool is a dual-use SSRF assessment agent that explicitly contains high-risk test capabilities (cloud metadata probing, internal port scanning, alternate protocol testing). The provided fragment shows no signs of obfuscation or deliberate malicious backdoors in itself, but its features can be weaponized if misused. Use strictly in authorized contexts and review the full implementation for safeguards (consent, rate limiting, careful defaults, no exfiltration helpers) before deployment.
The skill is internally consistent with its stated penetration-testing purpose, but it is a high-risk offensive security skill. It equips an AI agent to scan internal networks, trigger OOB callbacks, retrieve cloud metadata credentials, and abuse internal services; the main concern is dangerous capability, not deception.