ssrf-server-side-request-forgery

Fail

Audited by Socket on Apr 10, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

MALICIOUS. This skill’s stated purpose is offensive exploitation, and its actual footprint matches that: it teaches an AI agent to probe targets, exfiltrate cloud/Kubernetes secrets, use known callback collectors, and chain SSRF into internal service abuse and RCE. There is limited installer risk in the skill itself, but the exploit guidance and exfiltration-oriented data flows make it fundamentally unsafe.

Confidence: 97%Severity: 99%
Audit Metadata
Analyzed At
Apr 10, 2026, 06:20 AM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Fssrf-server-side-request-forgery%2F@97d399b64bbf4c45d826257eed8d9e0b4c42a60e