Skill 审计报告
cloud-iam-deep 审计报告.
Cloud IAM red-team attack chain across AWS, Azure, GCP — focused on EXTERNAL exploitation paths and post-credential-discovery privilege analysis. Covers IAM enumeration (aws iam, az role, gcloud iam), STS/AssumeRole chaining, Azure Managed Identity abuse (via SSRF/leak), GCP service account JSON abuse, IMDSv1/v2 attacks via SSRF, K8s ServiceAccount token privilege analysis once held (token discovery / cluster exposure is owned by hunt-k8s), role-trust-policy confused-deputy, cross-account assume-role enumeration, IAM privilege escalation patterns (24+ AWS, 8+ Azure, 6+ GCP), and AWS Cognito Identity Pool unauthenticated-role attack chain (GetId → GetCredentialsForIdentity → IAM role abuse). Built for the case where recon yields a credential (key, JSON, token) and you need to know what it grants and how to escalate. Use when an AWS key / Azure secret / GCP service account JSON / K8s SA token surfaces from a code repo, JS bundle, APK, breach corpus, or SSRF chain.
OpenAgentSkill 信任评分
OpenAgentSkill 信任评分
Trust Score 帮助 Agent 在安装前判断一个 Skill 是否足以进入候选清单。
GitHub 采用度
通过86
4.1K 个 GitHub Stars
Star/Fork 活跃度
通过83
4.1K 个 Star,633 个 Fork; 当前元数据中没有议题活跃度信息
近期维护
通过88
距上次推送 1 个月
许可证清晰度
通过86
MIT
README/SKILL.md 完整度
信息76
公开元数据需要更完整的 README/SKILL.md 上下文
依赖与运行时风险
失败28
command execution surface, credential or environment access
安装可用性
通过92
npx skills add elementalsouls/Claude-BugHunter --skill cloud-iam-deep
安装命令安全性
通过92
标准软件包或运行时安装路径
权限范围
失败18
secrets or environment access, shell or command execution
仓库证据
通过86
https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/cloud-iam-deep
审查状态
信息66
可用 AI 审查数据
Agent 验证结果
信息54
暂未有 Agent 结果数据
检查项
安装与采用审查
安装路径
92
npx skills add elementalsouls/Claude-BugHunter --skill cloud-iam-deep
仓库
88
https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/cloud-iam-deep
许可证
86
MIT
维护
88
距上次推送 1 个月
AI 审查
55
The skill does not include explicit authorization or legal-use warnings, which could lead to misuse if deployed without proper oversight.
README/SKILL.md 完整度
84
Usable description available
依赖风险
28
command execution surface, credential or environment access
安装命令安全性
92
标准软件包或运行时安装路径
权限范围
18
secrets or environment access, shell or command execution
Star/Fork 活跃度
83
4.1K 个 Star,633 个 Fork; 当前元数据中没有议题活跃度信息
采用度
88
4.1K 个 GitHub Stars
警告
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- Potential broker, wallet, exchange, or real-money execution surface; sandbox and explicit approval are required
- The skill does not include explicit authorization or legal-use warnings, which could lead to misuse if deployed without proper oversight.
- The SKILL.md excerpt does not include a setup section or environment requirements, though this may be covered in the full repository.
- This skill may touch real-money trading, broker, wallet, or exchange operations; use only in a sandbox with explicit approval.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
方法
本报告综合公开元数据、AI 审查输出、仓库活跃度、安装就绪度、OpenAgentSkill 事件、质量评分、信任检查和 Agent 安全门槛;它不是完整的源代码安全审计。
对比相近选项
下一步可审计的相关 Skill
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16K Stars · 审计报告
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
33K Stars · 审计报告
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29K Stars · 审计报告