chaos-engineering-on-aws

Warn

Audited by Socket on Sep 21, 2026

30 alerts found:

Securityx9Anomalyx21
SecurityMEDIUM
references/fis-templates/database-connection-exhaustion/ssm-automation.yaml

This is an explicit AWS fault-injection/load-generation automation, not covert malware based on the supplied code. It intentionally consumes database connection capacity and therefore presents a high availability and operational risk if misconfigured or run against production. It also contains a significant command-injection risk because multiple parameters are interpolated into a shell command without safe escaping or strict validation. Secret retrieval is an expected part of the database test, but requires tightly scoped IAM permissions and controlled input. Use only with strong authorization, bounded parameters, isolated targets, and safer argument passing.

Confidence: 98%Severity: 90%
AnomalyLOW
references/workflow-guide_zh.md

The visible fragment is operational documentation for controlled AWS and Kubernetes fault-injection testing, not apparent malware. It contains high-impact administrative procedures that can disrupt infrastructure and modify network or access policies, so execution requires strict authorization, parameter validation, least-privilege roles, bounded targets, tested rollback, and supervision. The unseen scripts and templates are security-critical and cannot be judged from this fragment alone.

Confidence: 96%Severity: 62%
SecurityMEDIUM
references/scenario-library_zh.md

The fragment documents legitimate but high-impact AWS chaos-engineering experiments. It is not itself evidence of malware or obfuscation, but executing the commands can intentionally disrupt production networking and services and requires powerful IAM permissions. Use only with strict target validation, least-privilege roles, monitoring, tested stop conditions, and non-production environments.

Confidence: 97%Severity: 78%
AnomalyLOW
scripts/setup-prerequisites.sh

The code appears to be a legitimate chaos-engineering setup script and contains no clear malicious behavior, data theft, obfuscation, persistence, or suspicious exfiltration. It does create highly privileged infrastructure capabilities by design. The unquoted SNS argument expansion, broad IAM permissions, direct resource tagging, and implicit use of the current Kubernetes context warrant review and hardening before use in production.

Confidence: 97%Severity: 58%
SecurityMEDIUM
references/prerequisites-checklist_zh.md

该片段是面向 AWS FIS 混沌工程的权限和前置条件文档,未显示恶意软件、数据窃取或隐蔽后门。其主要风险是故障注入角色权限过于广泛,尤其是 Resource: *、服务级通配符和 ssm:SendCommand,若角色或 iam:PassRole 被滥用,可能导致大范围基础设施中断或配置破坏。应限制资源 ARN、缩小动作集合、隔离实验账户并严格控制 FIS 启动权限。

Confidence: 97%Severity: 72%
AnomalyLOW
references/fis-templates/cloudfront-impairment/cloudfront-impairment-tag-based-automation.yaml

This fragment appears to implement an intentional AWS Fault Injection Simulator disruption test rather than malware. It deliberately denies public and authenticated S3 object reads for selected buckets and invalidates CloudFront caches, then attempts restoration. The operation is highly availability-impacting by design. The broad exception handling around get_bucket_policy and deletion of empty policies introduce a meaningful risk of accidental policy loss or failed restoration, particularly under permission, transient, or concurrent-update conditions. Review authorization, target validation, rollback guarantees, and policy version/concurrency handling before use.

Confidence: 94%Severity: 68%
AnomalyLOW
examples/13-az-power-interruption.md

The shown fragment describes an intentional AWS chaos-engineering deployment and does not exhibit clear malware or supply-chain attack behavior. It does carry substantial operational risk because the documented FIS experiment can disrupt compute, storage, database, cache, and network services, and the inline policy grants broad wildcard-scoped permissions. Review the omitted tagging logic and complete templates before use, and restrict deployment and experiment-start permissions to authorized operators.

Confidence: 90%Severity: 62%
AnomalyLOW
references/fis-templates/aurora-global-failover/aurora-global-region-failover-automation.yaml

The code is an openly documented, purpose-consistent AWS disaster-recovery automation runbook. It contains no evident malware, obfuscated payloads, credential theft, exfiltration, persistence, or command execution. It does have significant operational security risk because it performs a production database switchover or data-loss-allowing failover based on caller-controlled input and automatically chooses the first secondary cluster. IAM authorization, target validation, replication-health checks, and explicit approval controls should be enforced outside or around this runbook.

Confidence: 98%Severity: 68%
AnomalyLOW
examples/13-az-power-interruption_zh.md

该片段描述的是显式启动的 AWS 可用区故障注入实验,具有高影响的基础设施操作,但未发现恶意载荷、凭据窃取、数据外传或隐蔽持久化行为。主要安全问题是实验本身的破坏性以及 IAM 权限过宽,应在隔离环境中运行并进一步审查未展示的 CloudFormation/Lambda 实现。

Confidence: 91%Severity: 62%
SecurityMEDIUM
MCP_SETUP_GUIDE.md

No direct malware or covert data theft is evident in this documentation. It presents legitimate AWS chaos-engineering setup instructions, but it creates substantial supply-chain and authorization risk by executing unpinned @latest packages and an unverified cloned repository with access to AWS and Kubernetes credentials. The FullAccess IAM examples and enabled write operations materially increase potential impact. Pin versions or commits, verify package and repository provenance, use isolated identities, and enforce least-privilege policies before deployment.

Confidence: 98%Severity: 78%
SecurityMEDIUM
SKILL_EN.md

This is a documented AWS chaos-engineering workflow with explicitly destructive capabilities, not evidence of malware in the supplied fragment. The main risk is authorized-but-dangerous infrastructure disruption caused by enabling write operations and executing FIS, Chaos Mesh, or kubectl actions. Review the referenced scripts, MCP server packages, IAM policies, and external Chaosmesh-MCP repository before use, and require independent authorization and environment isolation.

Confidence: 96%Severity: 72%
AnomalyLOW
MCP_SETUP_GUIDE_zh.md

该片段是基础设施故障演练的 MCP 配置指南,未发现明确的恶意载荷、凭证外传或后门行为。主要安全风险来自使用未固定的 @latest 包、直接执行未经完整性验证的 GitHub 代码、暴露高权限凭证,以及示例 IAM 策略过度授权。建议固定包版本和 Git commit,验证来源与哈希,使用短期凭证和最小权限,并在隔离环境中执行 FIS/Chaos Mesh 操作。

Confidence: 97%Severity: 58%
AnomalyLOW
references/fis-templates/sqs-queue-impairment/sqs-queue-impairment-tag-based-automation.yaml

This fragment implements an explicit, temporary SQS disruption and restoration workflow consistent with an AWS fault-injection or resilience test. The permission changes are potentially high impact but are not evidence of malware by themselves, and no credential theft, exfiltration, persistence, or arbitrary code execution is visible. Risk is primarily operational: insufficient input authorization or failed cleanup could leave queues inaccessible. Assessment is limited because the file is truncated and the deny-all implementation is not shown.

Confidence: 93%Severity: 58%
AnomalyLOW
examples/09-elasticache-az-power.md

This fragment is chaos-engineering documentation and an AWS FIS experiment definition, not malware. It contains an intentionally disruptive ElastiCache AZ power-interruption action and broadly scoped IAM permissions, so it should only be executed in an approved environment with tightly controlled role access, tagging, and stop-condition validation. No credential theft, data exfiltration, obfuscation, persistence, or unauthorized malicious behavior is evident.

Confidence: 98%Severity: 62%
AnomalyLOW
examples/09-elasticache-az-power_zh.md

该片段是用于 AWS ElastiCache AZ 故障注入的混沌工程配置和操作说明,不包含明显恶意软件、数据窃取或后门行为。其主要风险来自预期中的破坏性云操作、ALL 目标选择、通配资源权限以及停止条件覆盖不足。应仅在获批的隔离环境或明确授权的生产实验中执行,并在替换占位符和验证目标标签后使用。

Confidence: 98%Severity: 68%
AnomalyLOW
examples/06-database-connection-exhaustion.md

The supplied fragment is operational documentation for an authorized AWS chaos-engineering experiment, not evident malware. It intentionally exhausts database connections and uses privileged AWS actions, creating a significant availability and misconfiguration risk if run outside an isolated, approved environment. The referenced templates must be reviewed before use, especially their IAM permissions, credential handling, target selection, and cleanup logic.

Confidence: 96%Severity: 62%
AnomalyLOW
examples/04-az-network-disrupt.md

The content is legitimate, readable AWS chaos-engineering documentation for validating multi-AZ resilience. It contains an intentionally disruptive FIS operation that could cause significant availability impact if misconfigured or run against production, but there are no indicators of supply-chain malware, credential theft, obfuscation, unauthorized exfiltration, or backdoor behavior. Review IAM permissions, target scope, alarm coverage, and environment before execution.

Confidence: 99%Severity: 62%
AnomalyLOW
examples/04-az-network-disrupt_zh.md

No malware or supply-chain attack behavior is present. This is a legitimate AWS chaos-engineering example designed to disrupt one AZ and test failover. It presents a high operational-impact risk if executed against production or if subnet targeting and stop conditions are misconfigured, but it does not exhibit malicious behavior.

Confidence: 99%Severity: 58%
AnomalyLOW
examples/03-eks-pod-kill.md

This is a documented Kubernetes chaos-engineering experiment for intentional single-Pod termination and recovery validation. It contains no evidence of malware, supply-chain compromise, credential theft, or covert data exfiltration. Execution is potentially disruptive because it targets production and uses immediate termination; it should be restricted to authorized environments with validated replicas, selectors, RBAC, monitoring, cleanup, and log-handling controls.

Confidence: 97%Severity: 56%
SecurityMEDIUM
references/fis-templates/database-connection-exhaustion/ssm-role-iam-policy.json

This is not executable malware, but it is a high-risk IAM policy because it combines EC2 creation, role passing, arbitrary SSM shell execution, security-group modification, and unrestricted Secrets Manager read access. The missing tag condition contradicts the statement name and may allow management of any matching instances. The wildcard account and resource scopes should be restricted before deployment.

Confidence: 98%Severity: 90%
AnomalyLOW
examples/03-eks-pod-kill_zh.md

The fragment is a legitimate chaos-engineering runbook for testing Kubernetes Pod recovery. It intentionally performs a destructive production operation, so it carries a meaningful availability and operational risk, especially because gracePeriod is zero and the helper scripts are not shown. No malware, credential theft, suspicious exfiltration, obfuscation, or unauthorized persistence is evident in the supplied content. Verify namespace/RBAC behavior, target selection, backups, replica count, and helper-script contents before execution.

Confidence: 97%Severity: 55%
AnomalyLOW
references/fis-templates/sqs-queue-impairment/README.md

No evidence of malware or covert malicious behavior appears in the supplied documentation. It describes a legitimate but intentionally disruptive AWS FIS/SSM resilience experiment. Operational risk is material because execution can deny access to tagged SQS queues and depends on the security scope of omitted IAM policies. Review target selection, permissions, rollback behavior, and test-account isolation before use.

Confidence: 97%Severity: 63%
AnomalyLOW
references/templates/progressive-network-degradation.json

This is an AWS FIS chaos-engineering experiment intentionally designed to degrade network and Lambda performance for selected resources. It presents an operational availability risk if misconfigured or executed against production, especially because subnet selection uses ALL, but it contains no apparent malicious behavior or supply-chain attack indicators. Authorization, target scope, and dependency behavior should be validated before execution.

Confidence: 98%Severity: 52%
AnomalyLOW
references/templates/az-power-interruption.json

This is an AWS chaos-engineering experiment intended to simulate an Availability Zone power interruption. It contains intentionally disruptive AWS actions but no evidence of malware or covert supply-chain behavior. Its security and operational risk is significant if deployed against unintended resources or with an overprivileged role, particularly because several target selections use ALL.

Confidence: 99%Severity: 62%
SecurityMEDIUM
references/templates/cascade-db-to-app.json

The fragment is an intentional chaos-engineering experiment designed to test cascading failure handling. It contains no evidence of malware, credential theft, obfuscation, persistence, or data exfiltration. It poses a significant availability risk if executed against unintended or production resources, especially because target selection uses ALL and the experiment performs both database failover and subnet network disruption.

Confidence: 99%Severity: 78%
AnomalyLOW
references/fis-templates/redis-connection-failure/redis-connection-failure-experiment-template.json

The fragment is a legitimate-looking AWS resilience-testing configuration that starts an SSM automation to disrupt Redis connectivity on tagged resources. It contains no apparent malware or obfuscation and no credentials. Its main risk is intentional service disruption, amplified by the lack of stop conditions and dependence on an unreviewed external SSM Automation document. It should be restricted to controlled environments and the referenced document and IAM permissions should be reviewed before execution.

Confidence: 96%Severity: 62%
AnomalyLOW
references/fis-templates/database-connection-exhaustion/fis-role-iam-policy.json

This is a legitimate-looking AWS IAM policy for operating an SSM automation and enabling CloudWatch Logs integration. It contains no malware or obfuscation indicators. Security risk is moderate because iam:PassRole is scoped across all AWS accounts by a wildcard account component and CloudWatch Logs resource-policy actions are granted on Resource "*". Replace placeholders and restrict the role ARN to the intended account; review the automation document and passed role permissions before deployment.

Confidence: 97%Severity: 57%
SecurityMEDIUM
references/fis-templates/database-connection-exhaustion/experiment-template.json

This configuration is an intentional database connection-exhaustion chaos or denial-of-service experiment. It does not itself show malware, credential theft, persistence, or exfiltration, but executing it can materially disrupt the specified PostgreSQL database. Authorization, scope, IAM permissions, the referenced SSM document, and emergency stop controls should be reviewed before use; the absence of stop conditions increases operational risk.

Confidence: 99%Severity: 90%
SecurityMEDIUM
references/fis-templates/aurora-global-failover/aurora-global-region-failover-fis-role-iam-policy.js

No malware or obfuscated code is present because this is a static IAM policy. It contains a significant least-privilege and potential privilege-escalation risk: broad SSM automation permissions combined with wildcard iam:PassRole over roles named with "SSM". Restrict resources and add an iam:PassedToService condition before deployment.

Confidence: 98%Severity: 78%
AnomalyLOW
references/fis-templates/redis-connection-failure/redis-connection-failure-ssm-role-iam-policy.json

The document is a legitimate-looking AWS IAM policy for discovering ElastiCache and security groups and modifying security-group ingress. It contains no evidence of malware or intentional obfuscation. However, unrestricted ec2:AuthorizeSecurityGroupIngress and ec2:RevokeSecurityGroupIngress permissions on all resources present a meaningful least-privilege and network-exposure risk and should be constrained with resource, condition, or source-range controls where supported.

Confidence: 99%Severity: 62%
Audit Metadata
Analyzed At
Sep 21, 2026, 08:15 PM
Package URL
pkg:socket/skills-sh/aws-samples%2Fsample-aws-resilience-skill%2Fchaos-engineering-on-aws%2F@789e121836df6e70c596fc94ec1d9ba4ec5f691e0f52ea5de94cd374f3080d9d