skills/aeondave/malskill/cloud-ctf/Gen Agent Trust Hub

cloud-ctf

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill accesses highly sensitive local credential files including ~/.aws/credentials and ~/.aws/config. It also provides instructions for extracting the SAM and SYSTEM registry hives from Windows disk images to recover NTLM hashes for further pivoting.
  • [EXTERNAL_DOWNLOADS]: The skill downloads tools from unverified external sources, including the enumerate-iam utility from a third-party GitHub repository (andresriancho/enumerate-iam) and the dsnap forensic tool via the Python package manager.
  • [REMOTE_CODE_EXECUTION]: Instructions direct the agent to clone and execute Python scripts from external repositories. It also describes how to achieve remote code execution on AWS Lambda by using UpdateFunctionCode to inject arbitrary zip payloads.
  • [PRIVILEGE_ESCALATION]: Detailed methodologies are provided for escaping privileged containers by overwriting the host's core_pattern. It also details techniques for bypassing entrypoint security using BASH_FUNC and performing privilege escalation on Google Cloud Platform via SSH key metadata injection.
  • [DYNAMIC_EXECUTION]: The skill demonstrates unsafe YAML deserialization using yaml.load(body, Loader=yaml.Loader) on untrusted data from SQS queues, and explicitly shows RCE payloads using !!python/object/apply:os.system.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Processes untrusted data from multiple cloud service entry points including S3 bucket objects, SQS message bodies, and DynamoDB records.
  • Boundary markers: Lacks boundary markers or specific instructions to treat external data as untrusted during processing.
  • Capability inventory: Utilizes extensive capabilities such as file system writes, network requests, and shell command execution across various platforms.
  • Sanitization: Fails to sanitize external data before passing it to dangerous execution sinks, specifically in the context of SQS message processing.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 5, 2026, 10:39 PM
Security Audit — agent-trust-hub — cloud-ctf