cloud-hunter
Warn
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides numerous shell commands for cloud resource discovery and enumeration using tools such as curl, the AWS CLI, and Docker.
- [CREDENTIALS_UNSAFE]: Includes specific instructions and commands to retrieve temporary IAM security credentials, access tokens, and identity information from the Instance Metadata Services (IMDS) of major cloud providers.
- [DATA_EXFILTRATION]: Provides methodologies for locating and accessing sensitive files within misconfigured cloud storage buckets, specifically targeting environment variables (.env), database backups (.sql), and configuration files.
- [EXTERNAL_DOWNLOADS]: References and identifies multiple third-party security auditing tools including Pacu, ScoutSuite, S3Scanner, and kube-hunter.
- [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection by using variables like BUCKET and ROLE_NAME that interpolate untrusted user input directly into shell commands.
- Ingestion points: SKILL.md (via variable placeholders such as BUCKET and ROLE_NAME in bash snippets).
- Boundary markers: Absent.
- Capability inventory: Shell command execution (curl, aws cli, docker).
- Sanitization: Absent.
Audit Metadata