Cloud pentest
An open-source arsenal of reusable skills for AI agents — repo understanding, code review, delivery workflows, security pentests, and plug-and-play integrations with Jira, GitHub, GitLab, Jenkins & more. Drop into Claude Code, Codex, or any skill-aware host.
npx -y skills add yuelenghan/orbit --skill cloud-pentestAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Adapted public skill for authorized cloud penetration testing across AWS, Azure, and GCP environments.
The file declares its own license as Apache-2.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.
SKILL.md
1.4 KB, as published. Nobody here has run it
Cloud Penetration Testing
Adapted from Anthropic-Cybersecurity-Skills/skills/conducting-cloud-penetration-testing/SKILL.md for Orbit.
Use this skill for authorized cloud security testing involving AWS, Azure, or GCP environments, especially where IAM, metadata services, cloud misconfiguration, and cloud attack paths are in scope.
When to Use
- cloud penetration testing
- IAM abuse assessment
- metadata service attack-path review
- cloud misconfiguration validation
- lateral movement risk in cloud environments
Inputs
- confirmed authorization context
- target boundary
- target-specific endpoint, host range, or cloud scope
Safety Boundary
Do not use this skill without explicit authorization from the cloud account owner. Do not test cloud provider infrastructure itself or perform destructive disruption outside approved scope.
Focus Areas
- shared-responsibility-aware scope validation
- IAM privilege escalation paths
- metadata service abuse
- storage and access control exposure
- cloud persistence and detection opportunities
- remediation and reporting
Output Expectations
Provide:
- tested cloud scope
- findings and severity
- proof-of-concept or reproduction steps
- remediation guidance