exploiting-aws-with-pacu
Audited by Socket on Aug 4, 2026
2 alerts found:
SecurityAnomalyHigh-risk offensive security skill. Its capabilities are internally consistent with its stated purpose, and install sources are mostly official, but it gives an AI agent instructions to ingest AWS credentials, enumerate accounts, escalate privileges, establish persistence, and extract cloud data. This is not confirmed malware, but it is a dangerous agent capability set with substantial real-world impact.
This snippet is documentation describing an offensive AWS exploitation framework with modules for IAM persistence/backdoors, EC2 startup-script injection, and S3/secrets data access likely suitable for exfiltration. No executable implementation is present here, so hidden malware, obfuscation, concrete network/filesystem effects, and exact source-to-sink flows cannot be verified from this fragment alone. Risk remains elevated due to the explicit hostile-capability descriptions, but malware cannot be conclusively confirmed without the actual code that implements these modules.