← back to performing-api-inventory-and-discovery

SkillSpector · performing-api-inventory-and-discovery

independent scanner by NVIDIA · skill by mukul975 · how it works ↗

PASSmax severity: LOWrisk score: 13

Request target host is built from a dynamic or untrusted value. If the host is attacker-influenced, this enables SSRF to arbitrary internal or metadata endpoint; Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack

scanned 2026-07-07

Findings (2)

MEDIUMServer-Side Request Forgeryconfidence: 0.6

Request target host is built from a dynamic or untrusted value. If the host is attacker-influenced, this enables SSRF to arbitrary internal or metadata endpoint

SKILL.md

MEDIUMTool Misuseconfidence: 0.75

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack

SKILL.md

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASSthis skill

Overall severity LOW (risk score in the safe range)

CAUTION

Overall severity MEDIUM

WARNING

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete