Skill 审计报告

cloud-iam-deep 审计报告.

Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-discovery privilege analysis. Covers IAM enumeration (aws iam, az role, gcloud iam), STS/AssumeRole chaining, Azure Managed Identity abuse (via SSRF/leak), GCP service account JSON abuse, IMDSv1/v2 attacks via SSRF, K8s ServiceAccount token privilege analysis once held (token discovery / cluster exposure is owned by hunt-k8s), role-trust-policy confused-deputy, cross-account assume-role enumeration, IAM privilege escalation patterns (24+ AWS, 8+ Azure, 6+ GCP), and AWS Cognito Identity Pool unauthenticated-role attack chain (GetId → GetCredentialsForIdentity → IAM role abuse). Built for the case where recon yields a credential (key, JSON, token) and you need to know what it grants and how to escalate. Use when an AWS key / Azure secret / GCP service account JSON / K8s SA token surfaces from a code repo, JS bundle, APK, breach corpus, or SSRF chain.

已阻止 · 阻止高风险生成于 2026年10月11日启发式元数据审计
76
审计
66
信任
80
质量
68
安全性
88
维护
92
安装

OpenAgentSkill 信任评分

66
人工审查

OpenAgentSkill 信任评分

Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。

GitHub 采用度

通过

86

4.1K 个 GitHub Stars

Star/Fork 活跃度

通过

83

4.1K 个 Star,633 个 Fork; 当前元数据中没有议题活跃度信息

近期维护

通过

88

距上次推送 1 个月

许可证清晰度

通过

86

MIT

README/SKILL.md 完整度

信息

76

公开元数据需要更完整的 README/SKILL.md 上下文

依赖与运行时风险

失败

28

command execution surface, credential or environment access

安装可用性

通过

92

npx skills add elementalsouls/Claude-BugHunter --skill cloud-iam-deep

安装命令安全性

通过

92

标准软件包或运行时安装路径

权限范围

失败

18

secrets or environment access, shell or command execution

仓库证据

通过

86

https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/cloud-iam-deep

审查状态

信息

66

可用 AI 审查数据

Agent 验证结果

信息

54

暂未有 Agent 结果数据

检查项

安装与采用审查

8 通过 · 13 需审查

安装路径

92

通过

npx skills add elementalsouls/Claude-BugHunter --skill cloud-iam-deep

仓库

88

通过

https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/cloud-iam-deep

许可证

86

通过

MIT

维护

88

通过

距上次推送 1 个月

AI 审查

55

检查

The skill does not include explicit authorization or legal-use warnings, which could lead to misuse if deployed without proper oversight.

README/SKILL.md 完整度

84

通过

Usable description available

依赖风险

28

修复

command execution surface, credential or environment access

安装命令安全性

92

通过

标准软件包或运行时安装路径

权限范围

18

修复

secrets or environment access, shell or command execution

Star/Fork 活跃度

83

通过

4.1K 个 Star,633 个 Fork; 当前元数据中没有议题活跃度信息

采用度

88

通过

4.1K 个 GitHub Stars

警告

  • Dependency or permission surface needs review
  • Permission surface may require sandboxing
  • Potential broker, wallet, exchange, or real-money execution surface; sandbox and explicit approval are required
  • The skill does not include explicit authorization or legal-use warnings, which could lead to misuse if deployed without proper oversight.
  • The SKILL.md excerpt does not include a setup section or environment requirements, though this may be covered in the full repository.
  • This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, shell or command execution
  • Dependency/runtime risk: command execution surface, credential or environment access
  • Permission surface: secrets or environment access, shell or command execution

方法

本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。

对比相近选项

下一步可审计的相关 Skill