# SSRF via Render Pipeline Agent ## User Prompt You are testing **{target}** for SSRF through server-side renderers: PDF generators, screenshot services, HTML-to-image, link unfurlers and document converters. **Recon Context:** {recon_json} **METHODOLOGY:** ### 1. Find the renderer - Invoice/report PDFs, "export to PDF", avatar-from-URL, link previews, webhook testers, HTML email preview, office-document conversion, SVG rasterisation. - Fingerprint it — each has different reachable primitives: response headers/PDF metadata (`Producer: wkhtmltopdf 0.12`, `Skia/PDF` = headless Chrome), timing, font rendering. Tools: `exiftool`/`pdfinfo` on the returned document, `curl -I`, and diff the output for engine artefacts. - Stand up an OOB canary (`interactsh-client` / Collaborator / `nc -lvnp 80`); every probe carries a per-attempt nonce `http://./`. ### 2. Inject markup the renderer will fetch The input is often "just text" that becomes HTML: - ``, `