AWS Penetration Testing
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: Provides specific techniques to gain administrative control over AWS accounts. This includes instructions for
iam:CreateAccessKeyfor other users,iam:AttachUserPolicyto grant oneselfAdministratorAccess, and Lambda code injection to programmatically escalate privileges at runtime. - [PERSISTENCE]: Explicitly details methods for maintaining long-term access to a compromised environment. Methods include creating new IAM login profiles, establishing Lambda backdoors, and launching EC2 instances with high-privilege roles.
- [DATA_EXFILTRATION]: Contains instructions for exfiltrating sensitive data, such as using
aws s3 syncto clone entire bucket contents to local storage and exploiting SSRF vulnerabilities to extract temporary security credentials from the EC2 Instance Metadata Service (IMDS). - [PROMPT_INJECTION]: Includes instructions to bypass security controls and monitoring systems. Specifically, it provides commands to delete or disable CloudTrail logs (
aws cloudtrail delete-trail) and recommends using specific tools to modify User-Agents to evade GuardDuty detection alerts. - [CREDENTIALS_UNSAFE]: Focuses on the discovery and harvesting of AWS Access Keys, Secret Keys, and Session Tokens from environmental variables, metadata endpoints, and configuration files.
- [COMMAND_EXECUTION]: Utilizes the AWS Systems Manager (SSM) to execute arbitrary shell commands on managed EC2 instances via
aws ssm send-command. - [EXTERNAL_DOWNLOADS]: Fetches various security assessment and exploitation tools from public GitHub repositories, including Pacu, CloudMapper, and Enumerate-IAM.
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted external data from cloud environment responses.
- Ingestion points: Reads and processes output from AWS CLI commands and specialized security tools mentioned in
SKILL.mdandreferences/advanced-aws-pentesting.md. - Boundary markers: None identified; instructions do not include delimiters or warnings to ignore embedded content in tool outputs.
- Capability inventory: Full shell access via
awsCLI, package installation throughpip, and network capabilities viacurlandwget. - Sanitization: No evidence of data validation or output sanitization before processing environment metadata.
Recommendations
- AI detected serious security threats
Audit Metadata