hunt-cloud-misconfig

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses Docker to pull and run the localstack/localstack:3.0 image. LocalStack is a well-known and widely used service for simulating AWS environments locally for development and testing.
  • [COMMAND_EXECUTION]: Multiple shell commands utilizing curl, aws cli, and docker are provided for cloud reconnaissance and exploitation testing. Examples include listing S3 buckets, probing Firebase RTDB instances, and accessing cloud metadata endpoints via SSRF.
  • [DATA_EXFILTRATION]: The skill documents a functional technique for exfiltrating data by embedding payloads into AWS CloudWatch RUM telemetry events using the aws rum put-rum-events command. This is presented as a method to bypass egress filtering by utilizing legitimate, allowlisted AWS domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:47 PM
Security Audit — agent-trust-hub — hunt-cloud-misconfig