offensive-ssrf
Server-Side Request Forgery testing checklist: SSRF discovery, blind SSRF with out-of-band, cloud metadata endpoints (AWS/GCP/Azure), SSRF filter bypass techniques (IP encoding, DNS rebinding, redirect chains), and SSRF to RCE escalation. Use for web app SSRF testing and bug bounty. Use when performing authorized red-team, pentest, or research work involving ssrf.
- Compatibility
- claude-code codex opencode
Pinned to revision 626b01ddea63, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/offensive-ssrf/SKILL.md
- skills/offensive-ssrf/LICENSE
- skills/offensive-ssrf/README.md
- skills/offensive-ssrf/agents/openai.yaml
Every link opens the file at its source, pinned to the revision this page describes.