Cloud Penetration Testing
Audited by Socket on Jul 28, 2026
2 alerts found:
MalwareSecuritySUSPICIOUS/HIGH-RISK skill. Its capabilities are coherent with its stated purpose, but that purpose is to equip an AI agent with offensive cloud penetration, credential access, secret extraction, and persistence techniques. Official installers reduce malware certainty, yet the overall security risk is very high because the skill meaningfully enables exploitation and persistent account changes in real cloud environments.
This code fragment is not benign infrastructure automation; it is an offensive cloud pentesting toolkit that includes direct credential-access (password spraying with persistence of valid credentials), token acquisition (OAuth device-code and IMDS managed-identity token retrieval), and a tenant privilege-escalation workflow (Graph role assignment). It also performs broad sensitive configuration/data harvesting into local files. Even without obfuscation, its operational capabilities present a high security risk and strong misuse potential.