# ssrfmcp

> ssrfmcp — cognis-digital-ssrfmcp. Use this tool when you need to test consent-based SSRF vulnerabilities in MCP servers by fetching URLs, providing a harness to probe and identify potential security weaknesses. It solves problems related to server security testing and vulnerability assessment, accepting URLs as input and outputting probe results. Ideal for use in penetration testing and security auditing contexts.

Canonical page: https://skillsregistry.net/skills/cognis-digital-ssrfmcp  
JSON: https://api.skillsregistry.net/v1/skills/cognis-digital-ssrfmcp

## Description

Consent-based SSRF probe harness for MCP servers that fetch URLs

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** container
- **Runtime environment:** vm
- **Updated:** 2026-09-21

## Source

- **Source listing:** [GitHub](https://github.com/cognis-digital/ssrfmcp)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "cognis-digital-ssrfmcp"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/cognis-digital-ssrfmcp` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/cognis-digital-ssrfmcp/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
