スキル監査レポート

cloud-iam-deep 監査レポート.

Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-discovery privilege analysis. Covers IAM enumeration (aws iam, az role, gcloud iam), STS/AssumeRole chaining, Azure Managed Identity abuse (via SSRF/leak), GCP service account JSON abuse, IMDSv1/v2 attacks via SSRF, K8s ServiceAccount token privilege analysis once held (token discovery / cluster exposure is owned by hunt-k8s), role-trust-policy confused-deputy, cross-account assume-role enumeration, IAM privilege escalation patterns (24+ AWS, 8+ Azure, 6+ GCP), and AWS Cognito Identity Pool unauthenticated-role attack chain (GetId → GetCredentialsForIdentity → IAM role abuse). Built for the case where recon yields a credential (key, JSON, token) and you need to know what it grants and how to escalate. Use when an AWS key / Azure secret / GCP service account JSON / K8s SA token surfaces from a code repo, JS bundle, APK, breach corpus, or SSRF chain.

ブロック済み · ブロック高リスク生成日 2026年10月11日ヒューリスティックなメタデータ監査
76
監査
66
信頼
80
品質
68
セキュリティ
88
保守
92
インストール

OpenAgentSkill Trust Score

66
手動レビュー

OpenAgentSkill Trust Score

Trust Score は、インストール前に候補に入れる安全性を Agent が判断する助けになります。

GitHub 採用度

合格

86

GitHub スター 4.1K

スター/フォーク活動

合格

83

スター 4.1K、フォーク 633; 現在のメタデータでは Issue 活動を利用できません

最近のメンテナンス

合格

88

最終プッシュから 1 か月

ライセンスの明確さ

合格

86

MIT

README/SKILL.md の完全性

情報

76

公開メタデータにはより十分な README/SKILL.md の文脈が必要です

依存関係/ランタイムのリスク

失敗

28

command execution surface, credential or environment access

インストール可否

合格

92

npx skills add elementalsouls/Claude-BugHunter --skill cloud-iam-deep

インストールコマンドの安全性

合格

92

標準パッケージまたはランタイムのインストールパス

権限範囲

失敗

18

secrets or environment access, shell or command execution

リポジトリ根拠

合格

86

https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/cloud-iam-deep

レビュー状況

情報

66

AI レビューデータを利用できます

Agent 検証結果

情報

54

Agent の成果データはまだありません

チェック

インストールと採用のレビュー

8 合格 · 13 要レビュー

インストール経路

92

合格

npx skills add elementalsouls/Claude-BugHunter --skill cloud-iam-deep

リポジトリ

88

合格

https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/cloud-iam-deep

ライセンス

86

合格

MIT

メンテナンス

88

合格

最終プッシュから 1 か月

AI レビュー

55

確認

The skill does not include explicit authorization or legal-use warnings, which could lead to misuse if deployed without proper oversight.

README/SKILL.md の完全性

84

合格

Usable description available

依存関係リスク

28

修正

command execution surface, credential or environment access

インストールコマンドの安全性

92

合格

標準パッケージまたはランタイムのインストールパス

権限範囲

18

修正

secrets or environment access, shell or command execution

スター/フォーク活動

83

合格

スター 4.1K、フォーク 633; 現在のメタデータでは Issue 活動を利用できません

採用度

88

合格

GitHub スター 4.1K

警告

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • Potential broker, wallet, exchange, or real-money execution surface; sandbox and explicit approval are required
  • The skill does not include explicit authorization or legal-use warnings, which could lead to misuse if deployed without proper oversight.
  • The SKILL.md excerpt does not include a setup section or environment requirements, though this may be covered in the full repository.
  • This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution

方法

このレポートは公開メタデータ、AI レビュー、リポジトリの鮮度、インストール準備、OpenAgentSkill イベント、品質スコア、信頼チェック、Agent セーフティゲートを統合します。完全なソースコード監査ではありません。

近い選択肢を比較

次に監査する関連スキル