performing-blind-ssrf-exploitation

mukul975/performing-blind-ssrf-exploitation · Agent Skill (multi-file)

by mukul975 · bundle

Published · Last updated


Detect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions, and timing analysis to access internal services and cloud metadata endpoints.

SKILL.md

Files

This skill is a package of 4 files. Install with the command above, or download the folder.

  • 📄SKILL.md entry
  • 📁references
  • 📄api-reference.md 5.0 KB
  • 📁scripts
  • ⚙️agent.py 9.3 KB
  • 📄LICENSE 11.0 KB

Related

  1. exploiting-server-side-request-forgery · mukul975 bundle
    Identify and exploit SSRF vulnerabilities to access internal services, cloud metadata, and restricted network resources during authorized penetration tests.
    24.6k
    repo stars
  2. performing-ssrf-vulnerability-exploitation · mukul975 bundle
    Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services, and protocol handlers through user-controllable URL parameters.
    24.6k
    repo stars
  3. ssrf · shulkwisec
    Detect and exploit Server-Side Request Forgery vulnerabilities by identifying user-controlled URL parameters, testing for internal service access, cloud metadata endpoints, and file scheme reads, with bypass techniques for common filters.
    21
    repo stars
  4. conducting-cloud-penetration-testing · mukul975 bundle
    Perform authorized penetration testing against AWS, Azure, and GCP cloud environments using cloud-specific tools and methodologies, with findings mapped to the MITRE ATT&CK Cloud matrix.
    24.6k
    repo stars
  5. aws-metadata-ssrf · shulkwisec bundle
    Exploit SSRF vulnerabilities in AWS EC2-hosted applications to extract IAM credentials and User Data from the Instance Metadata Service, including techniques for bypassing basic filters against IMDSv1.
    21
    repo stars
  6. xxe · shulkwisec
    Detect and exploit XML External Entity (XXE) injection vulnerabilities in XML parsers, including file disclosure, SSRF, and blind out-of-band exfiltration.
    21
    repo stars

Frequently asked questions

How do I install the performing-blind-ssrf-exploitation skill?

Run npx skillmds add mukul975/performing-blind-ssrf-exploitation in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.

What does the performing-blind-ssrf-exploitation skill do?

Detect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions, and timing analysis to access internal services and cloud metadata endpoints. It is listed under Security, DevOps & Infra, Penetration Testing on SkillMD.

Is performing-blind-ssrf-exploitation safe to use?

SkillMD's automated safety review verdict for this skill is CAUTION. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: PASS. Capability flags: executes scripts, makes network calls, reads secrets. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.

Which AI agents work with performing-blind-ssrf-exploitation?

This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.

Is performing-blind-ssrf-exploitation free to use?

Yes. Installing skills from SkillMD is free. This skill is licensed under Apache-2.

Who published performing-blind-ssrf-exploitation?

mukul975 (@mukul975) published this skill. Their other Agent Skills are listed on their SkillMD profile.