Cloud Penetration Testing
Audited by Socket on Sep 14, 2026
2 alerts found:
Securityx2SUSPICIOUS/HIGH-RISK. The skill’s capabilities align with its stated purpose, but that purpose is an offensive cloud exploitation playbook for an AI agent: it includes password spraying, stolen-token use, secret extraction, and persistence across cloud accounts. Install sources are mostly legitimate, so the main risk is not supply-chain deception but the autonomous offensive capability and credential/secret access the skill operationalizes.
The fragment is a cloud penetration-testing cheatsheet with substantial dual-use and offensive capability. It contains explicit credential acquisition, password spraying, sensitive data extraction, service-principal takeover steps, account creation, and Global Administrator assignment. These actions are dangerous without documented authorization and can expose credentials in plaintext, but the code shows no clear hidden malware, obfuscation, persistence, or covert exfiltration mechanism. It should be treated as high-risk operational security tooling and used only in controlled, authorized environments.