Cloud Penetration Testing

Fail

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Fetches and executes an installation script for the Google Cloud SDK from its official source.
  • [COMMAND_EXECUTION]: Includes procedures for establishing persistence in cloud environments by creating new administrative users and service principals with 'Owner' or 'Global Admin' privileges.
  • [EXTERNAL_DOWNLOADS]: Downloads the AWS CLI from official infrastructure and installs security-focused Python packages like ScoutSuite and Pacu.
  • [DATA_EXFILTRATION]: Provides commands for extracting sensitive metadata, environment variables, and secrets from cloud storage and compute resources.
  • [CREDENTIALS_UNSAFE]: Details methods for exporting cloud authentication contexts to local storage and using previously obtained access tokens for environment authentication.
Recommendations
  • HIGH: Downloads and executes remote code from: https://sdk.cloud.google.com - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 28, 2026, 05:45 AM
Security Audit — agent-trust-hub — Cloud Penetration Testing