SSRF via Agent URL Fetch Instruction - ATR-2026-00500 (5b77dcce-08f6-5ad8-ab2e-451147800829)
Detects prompts instructing an AI agent to fetch or retrieve content from internal network addresses, exposing SSRF (Server-Side Request Forgery) risk. Covers: cloud metadata endpoints (AWS IMDS 169.254.169.254, GCP metadata.google.internal), localhost and loopback admin panels (127.0.0.1, localhost), RFC-1918 private IP ranges (10.x.x.x, 172.16-31.x.x, 192.168.x.x), and generic internal hostname patterns. These attacks exploit agents with web-fetch tools to pivot to internal services. Generalised from promptfoo SSRF plugin corpus - literal internal.corp.example.com replaced with pattern matching any internal-like hostname or private IP range.
| Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
|---|---|---|---|---|
| LLM Plugin Compromise (adbb0dd5-ff66-4b2f-869f-bfb3fdb45fc8) | MITRE ATLAS Attack Pattern | SSRF via Agent URL Fetch Instruction - ATR-2026-00500 (5b77dcce-08f6-5ad8-ab2e-451147800829) | Agent Threat Rules | 1 |