cloud-penetration-testing
Audited by Socket on Sep 22, 2026
3 alerts found:
Securityx3SUSPICIOUS/HIGH-RISK skill. The instructions are internally consistent with a cloud penetration-testing purpose, but that purpose is inherently offensive: it teaches credential access, metadata harvesting, persistence, and data extraction across cloud providers. Install sources are mostly official, which lowers malware confidence, yet the overall skill remains high security risk because it equips an AI agent to perform real exploit actions with significant potential for misuse even with an authorization gate.
This is a plain-text cloud penetration-testing guide with substantial dual-use content and multiple explicit offensive and persistence procedures. It is not itself executable malware, but its instructions facilitate credential harvesting, secret extraction, data access, privilege escalation, remote command execution, and durable cloud backdoors. Use should be restricted to documented, authorized assessments with strong safeguards and removal of persistence artifacts after testing.
This code fragment is not benign infrastructure automation; it is an offensive cloud pentesting toolkit that includes direct credential-access (password spraying with persistence of valid credentials), token acquisition (OAuth device-code and IMDS managed-identity token retrieval), and a tenant privilege-escalation workflow (Graph role assignment). It also performs broad sensitive configuration/data harvesting into local files. Even without obfuscation, its operational capabilities present a high security risk and strong misuse potential.