cloud-penetration-testing
Assess Cloud Security Posture
Cloud teams need a structured way to test AWS, Azure, and GCP exposure. This skill organizes authorized cloud assessment steps, resource enumeration, and remediation-focused reporting.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "cloud-penetration-testing" from https://skillstore.io/skills/sickn33-cloud-penetration-testing.md and its manifest at https://skillstore.io/api/skills/sickn33-cloud-penetration-testing/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "cloud-penetration-testing". Plan an authorized AWS, Azure, and GCP cloud security assessment.
Expected outcome:
- Scope and authorization checklist.
- Provider-specific enumeration plan.
- Evidence handling and logging notes.
- Report structure with remediation sections.
Using "cloud-penetration-testing". Summarize findings from a cloud IAM review.
Expected outcome:
- High-risk administrator paths and exposed service accounts.
- Medium-risk excessive permissions and stale credentials.
- Recommended least-privilege changes and owner assignments.
Using "cloud-penetration-testing". Turn cloud storage observations into report-ready findings.
Expected outcome:
- Affected buckets and data sensitivity summary.
- Access control issue description.
- Business impact statement.
- Remediation steps and validation plan.
Security Audit
CriticalSections are framed as authorized cloud testing, but they include actionable credential harvesting, metadata token retrieval, password spraying, and persistence workflows. I confirmed findings tied to those workflows and dismissed syntax-only Markdown, benign URL, and encryption-status false positives. No prompt injection evidence was found in the reviewed files.
Confirmed security concerns (24)
Show all 24 confirmed findings
Capability review items (67)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โ๏ธ External commands (50)
๐ Network access (48)
๐ Filesystem access (4)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/sickn33-cloud-penetration-testing/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/sickn33-cloud-penetration-testing?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/sickn33-cloud-penetration-testing?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/sickn33-cloud-penetration-testing/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/sickn33-cloud-penetration-testing.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
sickn33. (2026). cloud-penetration-testing security audit report (audit version 5) [Author version 1.1]. Skillstore. https://skillstore.io/skills/sickn33-cloud-penetration-testing/audits/5BibTeX citation
@techreport{sickn33-sickn33-cloud-penetration-testing-2026,
author = {sickn33},
title = {cloud-penetration-testing security audit report (audit version 5)},
institution = {Skillstore},
year = {2026},
number = {5},
url = {https://skillstore.io/skills/sickn33-cloud-penetration-testing/audits/5},
note = {Author version 1.1}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "cloud-penetration-testing security audit report (audit version 5)"
version: "1.1"
type: report
authors:
- name: "sickn33"
date-released: "2026-07-09"
url: "https://skillstore.io/skills/sickn33-cloud-penetration-testing/audits/5"
identifiers:
- type: other
value: "skillstore:sickn33-cloud-penetration-testing:audit:5"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Prepare an Authorized Cloud Audit
Define scope, prerequisites, target platforms, expected deliverables, and evidence collection for a cloud assessment.
Review Cloud IAM Exposure
Enumerate identities, roles, policies, subscriptions, projects, and service principals to find risky access paths.
Document Misconfiguration Findings
Turn resource enumeration and secret exposure checks into clear findings with risk ratings and remediation actions.
Try These Prompts
Create an authorized cloud security assessment plan for AWS, Azure, and GCP. Include prerequisites, scope controls, deliverables, and evidence handling.
Build a safe enumeration checklist for an approved cloud account. Cover IAM, compute, storage, databases, networking, and logging.
Review these authorized cloud assessment notes and group findings by severity, affected service, business impact, and remediation priority.
Draft a cloud penetration test report for an authorized engagement. Include executive summary, technical findings, evidence summaries, and remediation steps.
Best Practices
- Confirm written authorization, scope, and rules of engagement before any testing step.
- Use least-privileged test accounts and record all commands, timestamps, and affected resources.
- Prefer read-only validation and sanitized evidence over copying secrets or customer data.
Avoid
- Using the skill against accounts, tenants, projects, or users outside the approved scope.
- Running persistence, credential extraction, or password spraying steps in production without explicit approval.
- Saving tokens, secrets, or customer data in local files without encryption and retention limits.
Frequently Asked Questions
Is this skill for authorized testing only?
Which cloud providers does it cover?
Does it install tools automatically?
Can it replace a professional cloud audit?
What evidence should users collect?
What makes this skill high risk?
Developer Details
Author
sickn33License
MIT
Author version
v1.1
Skillstore revision
r1
Version notice
The author-declared version is not valid SemVer.
Repository
https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/cloud-penetration-testingRef
3e4b6c31a74a3bd1a291c98cf585d720cb9fbc88
Maintenance freshness
7/18/2026
Usage
7 downloads ยท 210 views
File structure