hunt-cloud-misconfig
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses Docker to pull and run the
localstack/localstack:3.0image. LocalStack is a well-known and widely used service for simulating AWS environments locally for development and testing. - [COMMAND_EXECUTION]: Multiple shell commands utilizing
curl,aws cli, anddockerare provided for cloud reconnaissance and exploitation testing. Examples include listing S3 buckets, probing Firebase RTDB instances, and accessing cloud metadata endpoints via SSRF. - [DATA_EXFILTRATION]: The skill documents a functional technique for exfiltrating data by embedding payloads into AWS CloudWatch RUM telemetry events using the
aws rum put-rum-eventscommand. This is presented as a method to bypass egress filtering by utilizing legitimate, allowlisted AWS domains.
Audit Metadata