cloud-security
Fail
Audited by Gen Agent Trust Hub on May 26, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides explicit instructions for executing dangerous system commands to perform container escapes, such as mounting the host filesystem via 'docker -H unix:///var/run/docker.sock run -v /:/host' and entering host namespaces using 'nsenter --target 1 --mount'.
- [DATA_EXFILTRATION]: Provides procedures for harvesting sensitive cloud credentials and authentication tokens by targeting Instance Metadata Services (IMDS) on AWS, Azure, and GCP using SSRF-style curl commands (e.g., targeting 169.254.169.254).
- [CREDENTIALS_UNSAFE]: Includes commands designed to extract secrets, private keys, and sensitive configuration data from AWS Secrets Manager, Azure Key Vault, and Kubernetes Secret objects.
- [EXTERNAL_DOWNLOADS]: References multiple external offensive security tools and exploitation frameworks, such as Pacu, Peirates, and CloudFox, which are intended for automated exploitation of cloud and container environments.
Recommendations
- AI detected serious security threats
Audit Metadata