offensive-cloud-role

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions to execute cloud management commands such as aws sts get-caller-identity to establish principal identity within a cloud environment.
  • [PRIVILEGE_ESCALATION]: The instructions encourage the agent to identify paths for lateral movement and role assumption, specifically questioning if a workload identity allows movement into Kubernetes clusters or if a role can assume another role.
  • [DATA_EXFILTRATION]: The skill directs the agent to search for sensitive information and credentials stored in cloud services like AWS S3 buckets, Azure Blobs, Secrets Manager, and Parameter Store.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill instructs the agent to read and enumerate data from external cloud storage resources (S3 buckets, Azure Blobs).
  • Boundary markers: Absent. No instructions are provided to the agent to treat content from these external resources as untrusted or to ignore instructions contained within them.
  • Capability inventory: The agent is directed to use cloud CLI tools which possess capabilities for file writing, network communication, and resource management.
  • Sanitization: Absent. The skill does not define methods to filter or escape content retrieved from external cloud storage.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:39 PM
Security Audit — agent-trust-hub — offensive-cloud-role