AgentReadyHomeAgent ListingRuntimePricing

← Agent Listing

hunt-ssrf (Claude-BugHunter)

Agent SkillsFreeOpen Source

SSRF-hunting skill from 15 public reports incl. AWS/GCP/Azure metadata and gopher-to-Redis-RCE chains.

🛡️ AgentReady threat assessment

MAESTRO 7-layer threat model + OWASP AIVSS risk score for hunt-ssrf (Claude-BugHunter), derived from its capabilities.

AIVSS 8.7 · High
View MAESTRO 7-layer threat model →

These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.

Overview

An offensive skill for hunting Server-Side Request Forgery, built from 15 disclosed reports covering AWS/GCP/Azure metadata SSRF, DNS rebinding, gopher-protocol-to-Redis-RCE, link-preview and headless-browser PDF SSRF chains. Mandates out-of-band Collaborator confirmation for blind cases. Surface: guides crafting SSRF payloads and OOB exfil against live targets.

Key features and capabilities

Use cases