Cloud Penetration Testing
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPRIVILEGE_ESCALATIONPERSISTENCECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the official Google Cloud SDK and AWS CLI installation packages from their respective official cloud provider domains.
- [COMMAND_EXECUTION]: Executes extensive shell and PowerShell commands to interact with cloud APIs and manage infrastructure across multiple providers.
- [DATA_EXFILTRATION]: Provides automated methods for discovering and extracting sensitive data, such as Key Vault secrets, Lambda environment variables, and authentication tokens, which are stored locally.
- [PRIVILEGE_ESCALATION]: Includes instructions for elevating permissions through the creation of administrative service principals and assigning privileged roles to accounts.
- [PERSISTENCE]: Details techniques for maintaining long-term access, including the generation of persistent authentication keys and the creation of backdoor accounts.
- [CREDENTIALS_UNSAFE]: Uses scripts to scan user metadata and cloud resources for sensitive information and hardcoded passwords.
- [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Ingests data from external cloud storage buckets (S3, GS) and internal metadata services (169.254.169.254).
- Boundary markers: No explicit delimiters or warnings are used when processing content from these external sources.
- Capability inventory: Includes capabilities for remote command execution on virtual machines, network requests, and local file system modifications.
- Sanitization: Does not implement validation or escaping for data retrieved from cloud environments before processing.
Recommendations
- HIGH: Downloads and executes remote code from: https://sdk.cloud.google.com - DO NOT USE without thorough review
Audit Metadata