Skip to main content
Run any Skill in Manus
with one click

exploit-ssrf

Stars56
Forks32
UpdatedJune 9, 2026 at 19:01

SSRF/服务器请求伪造危害证明。确认服务端可控 URL、Webhook、图片抓取、PDF 渲染、导入回调、代理下载、重定向跟随或 XML/XXE SSRF 后使用。先识别 URL 解析器、重定向/DNS 行为、fetcher 协议能力和回显/OOB/错误/异步通道,再按受控 callback、metadata 根目录、角色名、localhost/banner 分层证明可达;不读取完整云凭证,不扫描内网,不写入内网服务。

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

SKILL.md
readonly