cloud-pentest

Installation
SKILL.md

What this skill does

Performs a structured cloud security assessment across AWS, Azure, and GCP. Runs automated multi-cloud audits with ScoutSuite and Prowler, then performs deep manual analysis of IAM privilege escalation paths, storage exposure, network posture, and serverless configurations. Produces a findings report with CIS benchmark violations, attack narratives, and IaC remediation examples.

When to use

  • When performing a cloud security posture assessment (CSPM) against an authorized environment
  • When auditing IAM roles and policies for overpermissive grants or privilege escalation paths
  • When checking storage buckets/blobs for public exposure or weak access controls
  • When reviewing network security groups, NACLs, and VPC endpoint configurations
  • When mapping serverless function attack surfaces (Lambda, Azure Functions, Cloud Functions)

Prerequisites

Installs
5
GitHub Stars
21
First Seen
May 9, 2026
cloud-pentest — woohyun212/security-skill