Phy Ssrf Audit

Server-Side Request Forgery (SSRF) vulnerability scanner (OWASP A10:2021). Detects URL-fetching sinks in Python/Java/Node.js/PHP/Go/Ruby that accept user-controlled URLs without validation. Flags cloud metadata endpoint access (AWS IMDS 169.254.169.254, GCP metadata.google.internal, Azure IMDS), DNS rebinding exposure, missing allowlist checks. Outputs CWE-918 findings with HTTP taint analysis and per-framework fix snippets. Zero competitors on ClawHub.

LeoYeAI Updated

File contents

LeoYeAI/openclaw-master-skills/tree/main/skills/phy-ssrf-audit commit 1a8136f287

Frequently asked questions

npx skillmds@latest add leoyeai-openclaw-master-skills/phy-ssrf-audit