Skip to content

docs: add SSRF security review guidance - #115

Open
m4tinbeigi-official wants to merge 1 commit into
anthropics:mainfrom
m4tinbeigi-official:feat/ssrf-review-guidance
Open

m4tinbeigi-official wants to merge 1 commit into
anthropics:mainfrom
m4tinbeigi-official:feat/ssrf-review-guidance

Conversation

@m4tinbeigi-official

Copy link
Copy Markdown

Fixes #83.

This PR adds explicit SSRF guidance to the security review prompt.

The existing prompt already excludes path-only SSRF findings, but it does not positively describe the SSRF patterns reviewers should look for. This change adds guidance for cases where untrusted input controls the scheme/protocol, host, port, DNS target, redirect target, or full URL used by a server-side request.

It also covers common SSRF targets and bypass patterns, including localhost, link-local addresses, private network ranges, cloud metadata endpoints, redirects, DNS rebinding, alternate IP encodings, userinfo tricks, IPv6 literals, and allowlist validation gaps.

The false-positive filter is also clarified so path-only URL control remains excluded while high-signal SSRF findings involving host/protocol/full-URL control are preserved.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Missing security review guidance for SSRF

1 participant