Strix•SSRF 测试

Identify SSRF attack surfaces in web applications and cloud environments.

735|96|Updated Apr 23, 2026
One-click install
npx skills add https://github.com/asdfgh1445/ctf-super-hub --skill strix-ssrf
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Strix•SSRF 测试
Source: https://github.com/asdfgh1445/ctf-super-hub/tree/main/strix-ssrf
Command: npx skills add https://github.com/asdfgh1445/ctf-super-hub --skill strix-ssrf

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps security researchers and engineers identify and analyze server-side request forgery (SSRF) flaws to prevent unauthorized network access.

Core Features & Use Cases

  • Assessment of SSRF vulnerabilities in cloud services, internal network interfaces, and web applications.
  • Understanding of attack surface, including cloud metadata, internal services, protocol abuse, and bypass techniques.
  • Use Case: Given a web application's URL parameter, analyze whether SSRF can be triggered to access internal resources like cloud metadata endpoints or internal APIs.

Quick Start

Provide a target URL with potential SSRF vectors to the AI and ask it to evaluate possible vulnerabilities.

Frequently Asked Questions about Strix•SSRF 测试

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What is an SSRF vulnerability and how does it expose internal services?

An SSRF vulnerability allows attackers to coerce a web application into making unauthorized requests to internal services. This flaw enables unauthorized network access by exploiting URL parameters to reach restricted cloud metadata endpoints or internal APIs.

How do I test a URL parameter for SSRF against cloud metadata endpoints?

To test for SSRF, provide a target URL with potential vectors to the AI for evaluation. It analyzes cloud metadata endpoints, internal services, and protocol exploitation techniques to identify potential SSRF risks and attack surfaces.

Can I use this to analyze SSRF bypass techniques in cloud environments?

Yes, you can analyze SSRF bypass techniques in cloud environments. The assessment covers cloud metadata, internal network interfaces, and protocol abuse to help security researchers understand the complete attack surface.

What is the best way to identify SSRF attack surfaces in web applications?

The best way to identify SSRF attack surfaces is by analyzing URL structures and network behaviors. This approach assesses web applications, cloud environments, and internal network protocols to detect potential server-side request forgery risks.

Does this SSRF testing approach work with all cloud providers?

Yes, the SSRF testing approach works with various cloud providers. It uses information about cloud providers, URL structures, and network behaviors to analyze potential server-side request forgery risks across different cloud metadata endpoints.