hunt-ssrf

Detects and exploits Server-Side Request Forgery vulnerabilities in web applications.

3|Updated Nov 12, 2025
One-click install
npx skills add https://github.com/cmndcntrlcyber/rtpi --skill hunt-ssrf-cmndcntrlcyber
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hunt-ssrf
Source: https://github.com/cmndcntrlcyber/rtpi/tree/main/knowledge_seed/bug_hunter_skills/hunt-ssrf
Command: npx skills add https://github.com/cmndcntrlcyber/rtpi --skill hunt-ssrf-cmndcntrlcyber

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill assists in identifying and leveraging SSRF (Server-Side Request Forgery) vulnerabilities within web applications, providing a structured methodology for exploitation and verification.

Core Features & Use Cases

  • Vulnerability Detection: Automated identification of potential SSRF vulnerabilities in a target application.
  • Exploitation Methodology: Offers a detailed guide on how to exploit identified SSRF vulnerabilities for data exfiltration or further system compromise.
  • Use Case: Use this Skill to scan a web application for SSRF vulnerabilities, confirm exploitation, and then use the provided payloads and detection patterns to demonstrate the vulnerability.

Quick Start

Use the 'hunt-ssrf' skill to identify SSRF vulnerabilities in the target application.

Frequently Asked Questions about hunt-ssrf

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I detect and exploit SSRF vulnerabilities in web applications?

To detect and exploit SSRF vulnerabilities in web applications, this Skill provides structured methodologies for identifying, exploiting, and verifying target application weaknesses. It requires manual analysis and interaction to demonstrate the vulnerability.

What is the best way to identify potential SSRF vulnerabilities during a security audit?

The best way to identify potential SSRF vulnerabilities during a security audit is using structured detection methodologies that provide specific payloads and detection patterns. This approach automates identification while requiring manual interaction to confirm exploitation.

Can I use this Skill for red teaming and web application security testing?

Yes, you can use this Skill for red teaming and web application security testing. It is specifically designed for security auditing, providing exploitation methodologies to demonstrate data exfiltration or further system compromise.

How do I verify SSRF exploitation after identifying a vulnerable web application?

To verify SSRF exploitation after identifying a vulnerable web application, the Skill provides specific payloads and detection patterns. You must manually interact with the target application to confirm the vulnerability and demonstrate data exfiltration.

Do I need manual analysis to find Server-Side Request Forgery vulnerabilities?

Yes, you need manual analysis to find Server-Side Request Forgery vulnerabilities. The Skill provides structured methodologies and detection patterns, but successful exploitation and verification require direct manual interaction with the target application.

Related Skills