AWS Penetration Testing
Warn
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [DATA_EXFILTRATION]: The skill provides detailed commands to extract sensitive information, including AWS credentials from EC2 metadata endpoints (IMDSv1/v2) and Fargate environment variables (
/proc/self/environ). It also describes how to extract Active Directory database files (NTDS.dit) from Windows Domain Controllers using EBS snapshots. - [CREDENTIALS_UNSAFE]: Explicit instructions are provided to fetch sensitive data from AWS Secrets Manager (
get-secret-value) and decrypt content using KMS keys (kms decrypt). It also includes API calls known to return credentials (e.g.,sts:assumerole,iam:createaccesskey). - [COMMAND_EXECUTION]: The skill utilizes AWS Systems Manager (SSM)
send-commandto execute arbitrary shell scripts on managed EC2 instances and useslambda update-function-codeto inject and execute custom code within Lambda functions for privilege escalation. - [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and install multiple third-party security frameworks and tools from various GitHub repositories, including Pacu, enumerate-iam, aws_consoler, and CloudMapper. These sources are outside the trusted vendor scope.
- [PERSISTENCE]: The skill includes techniques for maintaining access and evading detection, such as backdooring Lambda functions and disabling or modifying AWS CloudTrail logging (
delete-trail,update-trail) to cover tracks. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from various sources without sanitization or boundary markers.
- Ingestion points: Data enters the context through outputs of AWS CLI commands, metadata endpoint responses, and file contents read from S3 or EBS volumes.
- Boundary markers: None are present to distinguish between instructions and data.
- Capability inventory: The skill possesses extensive capabilities including IAM modification, Lambda code updates, command execution via SSM, and network operations.
- Sanitization: No sanitization or validation of external content is performed before processing.
Audit Metadata