performing-ssrf-vulnerability-exploitation
Tests web application URL parameters for Server-Side Request Forgery by probing cloud metadata endpoints (AWS/GCP/Azure at 169.254.169.254), internal network services, and protocol handlers (file://, gopher://, dict://) using a Python script, including IP-encoding bypass and DNS rebinding checks. Use during authorized penetration testing to confirm SSRF in a URL-fetching parameter and generate a vulnerability report.
How do I install this agent skill?
npx skills add https://github.com/mukul975/anthropic-cybersecurity-skills --skill performing-ssrf-vulnerability-exploitationIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill functions as a security testing tool for identifying SSRF vulnerabilities and performs as described. It presents a low-risk indirect prompt injection surface because it captures and stores raw data from external network responses which may be processed by the agent.
- Socketwarn
2 alerts: gptSecurity
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
When to Use
- When conducting security assessments that involve performing ssrf vulnerability exploitation
- When following incident response procedures for related security events
- When performing scheduled security testing or auditing activities
- When validating security controls through hands-on testing
Prerequisites
- Familiarity with security operations concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities
Instructions
- Install dependencies:
pip install requests - Identify URL parameters in the target application that accept URLs or hostnames.
- Test SSRF payloads:
- Cloud metadata:
http://169.254.169.254/latest/meta-data/ - Internal services:
http://127.0.0.1:port/,http://10.0.0.1/ - Protocol handlers:
file:///etc/passwd,gopher://,dict:// - Bypass techniques: IP encoding, DNS rebinding, URL redirects
- Cloud metadata:
- Analyze responses for information disclosure or internal access confirmation.
- Generate a vulnerability assessment report.
# For authorized penetration testing and lab environments only
python scripts/agent.py --target-url https://app.example.com/fetch?url= --output ssrf_report.json
Examples
AWS Metadata SSRF
GET /fetch?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/
If the response contains AWS credentials (AccessKeyId, SecretAccessKey), SSRF is confirmed with critical impact.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/mukul975/anthropic-cybersecurity-skills/performing-ssrf-vulnerability-exploitation">View performing-ssrf-vulnerability-exploitation on skillZs</a>