emulating-cloud-attacks-with-stratus-red-team
Fail
Audited by Snyk on Aug 3, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This is a dual-use red-team project that intentionally implements and documents offensive cloud techniques (credential access, exfiltration, persistence and automation to "detonate" them) — capable of deliberate malicious actions if misused or run in unauthorized environments.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The docker run example in SKILL.md pulls and executes the remote container image ghcr.io/datadog/stratus-red-team at runtime, which downloads and runs remote code (a container) and therefore is a runtime external dependency that can execute code.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata