AWS Penetration Testing

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: Provides specific techniques to gain administrative control over AWS accounts. This includes instructions for iam:CreateAccessKey for other users, iam:AttachUserPolicy to grant oneself AdministratorAccess, and Lambda code injection to programmatically escalate privileges at runtime.
  • [PERSISTENCE]: Explicitly details methods for maintaining long-term access to a compromised environment. Methods include creating new IAM login profiles, establishing Lambda backdoors, and launching EC2 instances with high-privilege roles.
  • [DATA_EXFILTRATION]: Contains instructions for exfiltrating sensitive data, such as using aws s3 sync to clone entire bucket contents to local storage and exploiting SSRF vulnerabilities to extract temporary security credentials from the EC2 Instance Metadata Service (IMDS).
  • [PROMPT_INJECTION]: Includes instructions to bypass security controls and monitoring systems. Specifically, it provides commands to delete or disable CloudTrail logs (aws cloudtrail delete-trail) and recommends using specific tools to modify User-Agents to evade GuardDuty detection alerts.
  • [CREDENTIALS_UNSAFE]: Focuses on the discovery and harvesting of AWS Access Keys, Secret Keys, and Session Tokens from environmental variables, metadata endpoints, and configuration files.
  • [COMMAND_EXECUTION]: Utilizes the AWS Systems Manager (SSM) to execute arbitrary shell commands on managed EC2 instances via aws ssm send-command.
  • [EXTERNAL_DOWNLOADS]: Fetches various security assessment and exploitation tools from public GitHub repositories, including Pacu, CloudMapper, and Enumerate-IAM.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted external data from cloud environment responses.
  • Ingestion points: Reads and processes output from AWS CLI commands and specialized security tools mentioned in SKILL.md and references/advanced-aws-pentesting.md.
  • Boundary markers: None identified; instructions do not include delimiters or warnings to ignore embedded content in tool outputs.
  • Capability inventory: Full shell access via aws CLI, package installation through pip, and network capabilities via curl and wget.
  • Sanitization: No evidence of data validation or output sanitization before processing environment metadata.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 07:18 AM
Security Audit — agent-trust-hub — AWS Penetration Testing