hunt-cloud-misconfig

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains numerous shell command examples using curl, aws-cli, and docker. These are provided as standardized auditing templates for identifying public S3 buckets, testing Firebase rules, and interacting with local simulation environments (LocalStack).
  • [DATA_EXFILTRATION]: The skill documents how misconfigured AWS CloudWatch RUM endpoints could theoretically be used for data exfiltration by attackers, but the skill itself does not perform any unauthorized data transfers. It describes the risk of over-permissioned guest roles.
  • [CREDENTIALS_UNSAFE]: While the skill mentions credential extraction techniques (e.g., Cognito Identity Pool exploitation), it does so to teach detection and validation for security auditing purposes. No actual credentials or secrets are hardcoded in the skill; it uses placeholders like 'TARGET-NAME' or 'abcd1234-'.
  • [REMOTE_CODE_EXECUTION]: The skill mentions RCE in the context of validating high-severity findings (e.g., through Lambda invocation), but does not contain any functional RCE payloads or automated remote execution patterns targeting the user's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 11:02 PM
Security Audit — agent-trust-hub — hunt-cloud-misconfig