profile_id: ssrf-generic match_rules: keywords: - ssrf - server-side request forgery vuln_family: ssrf provisioning_mode: real artifact_source: strategy: official-image-or-source required_services: - app seed_actions: - kind: note message: Route callbacks to local sink endpoints only. baseline_actions: - kind: http-get path: / attack_actions: - kind: note message: Exercise local sink endpoints, not external third-party destinations. browser_assertions: required: false success_criteria: - Request sink receives expected callback without crossing authorization boundaries. cleanup_policy: destroy destructive_risk: medium allowed_target_types: - lab-local - lab-public - authorized-third-party