cloud-security-technique

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents a wide range of commands for cloud provider CLI tools (AWS, Azure, GCP) and container management utilities (kubectl, docker). These are intended to be executed in the target cloud environment to perform security triage and enumeration.
  • [PRIVILEGE_ESCALATION]: Includes extensive reference materials for identifying and exploiting misconfigurations in cloud identity systems (e.g., AWS IAM policy versions, Azure RBAC assignments, GCP service account impersonation) and container environments (e.g., privileged mode, capability abuse) to gain elevated permissions.
  • [DATA_EXFILTRATION]: Outlines methodologies for identifying and accessing sensitive information such as credentials from cloud metadata services (IMDS), environment variables in serverless functions, and secrets stored in cloud-native storage buckets or parameter stores.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data retrieved from cloud provider APIs and CLI tool outputs, which represents a potential surface for indirect prompt injection.
  • Ingestion points: Outputs from cloud provider CLI tools (aws, az, gcloud) and network responses from metadata services.
  • Boundary markers: The instructions do not define specific delimiters or instructions for the agent to treat these external outputs as untrusted content.
  • Capability inventory: The skill utilizes broad command execution and network access capabilities within the cloud context.
  • Sanitization: There are no instructions for validating or sanitizing the content of the data retrieved from the cloud environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:40 PM
Security Audit — agent-trust-hub — cloud-security-technique