cloud-penetration-testing

Warn

Audited by Socket on Aug 10, 2026

1 alert found:

Security
SecurityMEDIUM
references/advanced-cloud-scripts.md

This code fragment is not benign infrastructure automation; it is an offensive cloud pentesting toolkit that includes direct credential-access (password spraying with persistence of valid credentials), token acquisition (OAuth device-code and IMDS managed-identity token retrieval), and a tenant privilege-escalation workflow (Graph role assignment). It also performs broad sensitive configuration/data harvesting into local files. Even without obfuscation, its operational capabilities present a high security risk and strong misuse potential.

Confidence: 74%Severity: 85%
Audit Metadata
Analyzed At
Aug 10, 2026, 09:31 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fagentic-awesome-skills%2Fcloud-penetration-testing%2F@fe4334db62bc2cbc3038e3e06b9a3b84e11a02e1d2e361e97ba411a6b8edc481
Security Audit — socket — cloud-penetration-testing