cloud-ctf
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill accesses highly sensitive local credential files including
~/.aws/credentialsand~/.aws/config. It also provides instructions for extracting theSAMandSYSTEMregistry hives from Windows disk images to recover NTLM hashes for further pivoting. - [EXTERNAL_DOWNLOADS]: The skill downloads tools from unverified external sources, including the
enumerate-iamutility from a third-party GitHub repository (andresriancho/enumerate-iam) and thedsnapforensic tool via the Python package manager. - [REMOTE_CODE_EXECUTION]: Instructions direct the agent to clone and execute Python scripts from external repositories. It also describes how to achieve remote code execution on AWS Lambda by using
UpdateFunctionCodeto inject arbitrary zip payloads. - [PRIVILEGE_ESCALATION]: Detailed methodologies are provided for escaping privileged containers by overwriting the host's
core_pattern. It also details techniques for bypassing entrypoint security usingBASH_FUNCand performing privilege escalation on Google Cloud Platform via SSH key metadata injection. - [DYNAMIC_EXECUTION]: The skill demonstrates unsafe YAML deserialization using
yaml.load(body, Loader=yaml.Loader)on untrusted data from SQS queues, and explicitly shows RCE payloads using!!python/object/apply:os.system. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Processes untrusted data from multiple cloud service entry points including S3 bucket objects, SQS message bodies, and DynamoDB records.
- Boundary markers: Lacks boundary markers or specific instructions to treat external data as untrusted during processing.
- Capability inventory: Utilizes extensive capabilities such as file system writes, network requests, and shell command execution across various platforms.
- Sanitization: Fails to sanitize external data before passing it to dangerous execution sinks, specifically in the context of SQS message processing.
Recommendations
- AI detected serious security threats
Audit Metadata