exploiting-cloud-platforms
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a library of command-line snippets for interacting with cloud provider APIs via official CLI tools (aws, az, gcloud) to query account configurations and service states.
- [PRIVILEGE_ESCALATION]: Outlines techniques for exploiting cloud IAM roles and policies to gain elevated access, reflecting common security research into cloud identity misconfigurations.
- [DATA_EXFILTRATION]: Includes instructions for retrieving data from storage buckets and accessing cloud metadata services (IMDS) to obtain credentials or configuration details.
- [EXTERNAL_DOWNLOADS]: References established security auditing frameworks and knowledge bases, such as Pacu, ScoutSuite, and the HackTricks technical wiki, which are standard resources for cloud security testers.
- [CREDENTIALS_UNSAFE]: Contains standard example access keys (
AKIAIOSFODNN7EXAMPLE) used for illustrative purposes. These are non-functional placeholders commonly found in technical documentation.
Recommendations
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata