Pentest cloud auditor
Skill 0x-Professor/Agent-Skills-Hub/skills/pentest-cloud-auditor
Public skill pack for AI coding/automation/penetration-testing agents.
npx -y skills add 0x-Professor/Agent-Skills-Hub --skill pentest-cloud-auditorAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 10 stars10 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Assess AWS, Azure, and GCP controls for IAM escalation and cloud service exposure.
SKILL.md
1.3 KB, as published. Nobody here has run it
Pentest Cloud Auditor
Stage
- PTES: 5-6
- MITRE: TA0007
Objective
Identify cloud privilege escalation and exposure misconfiguration pathways.
Required Workflow
- Validate scope before any active action and reject out-of-scope targets.
- Run only authorized checks aligned to PTES, OWASP WSTG, NIST SP 800-115, and MITRE ATT&CK.
- Write findings in canonical finding_schema format with reproducible PoC notes.
- Honor dry-run mode and require explicit --i-have-authorization for live execution.
- Export deterministic artifacts for downstream skill consumption.
Execution
python skills/pentest-cloud-auditor/scripts/cloud_auditor.py --scope scope.json --target <target> --input <path> --output <path> --format json --dry-run
Outputs
cloud-misconfigs.jsoncloud-privesc-paths.jsoncloud-report.json
References
references/tools.mdskills/autonomous-pentester/shared/scope_schema.jsonskills/autonomous-pentester/shared/finding_schema.json
Legal and Ethical Notice
WARNING AUTHORIZED USE ONLY
This skill executes real security testing tools against live targets.
Use only with written authorization.