skills/ transilienceai/communitytools

cloud-containers

Cloud and container security testing - AWS, Azure, GCP, Docker, and Kubernetes misconfigurations and exploitation.

0
Installs
—
Rating
—
Success rate
13
Files scanned
Flaggeddevops
Source on GitHub

Do not let an agent install this unattended

The scanner found high-risk patterns. Review the findings and the source with a human first.

Security scan

Flagged

High-risk patterns found. A human should read the source before any agent installs this.

13 files scannedscanner v1.2.0Oct 11, 20261 critical2 medium
  • criticalReads credentials and sends them over the network

    reference/scenarios/aws/moto-mock-aws-quirks.md:179

    curl -sk "http://<VHOST>/restapis/<api_id>/<stage>/_user_request_/<route>?&.json"    --data-urlencode "cmd=({})[__import__('os').environ['AWS_SECRET_ACCESS_K…

    Combines access to secrets (SSH keys, cloud creds, tokens, .env) with a network call on the same line.

  • mediumSkips hooks, TLS checks or browser sandbox

    reference/scenarios/kubernetes/recon-and-rbac.md:80

    curl -k https://kubernetes-api:6443/api/v1/namespaces

    Sometimes needed (CI containers, local certs) but each one turns off a check that exists for a reason.

  • mediumSkips hooks, TLS checks or browser sandbox

    reference/scenarios/kubernetes/recon-and-rbac.md:84

    curl -k -H "Authorization: Bearer $TOKEN"    https://kubernetes.default.svc/api/v1/namespaces

    Sometimes needed (CI containers, local certs) but each one turns off a check that exists for a reason.

Not scanned (too large or unreadable): skills/cloud-containers/reference/posture/catalog/cis-oci-foundations-v3.1.1.json, skills/cloud-containers/reference/posture/catalog/mcsb-azure-foundations-v1.json, skills/cloud-containers/reference/posture/catalog/nsa-cisa-k8s-hardening-1.2.json

Content sha256 68404f0260686bbc… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Cloud & Containers

Test cloud infrastructure and container environments for security misconfigurations and exploitation paths.

Techniques

PlatformKey Vectors
AWSS3 bucket exposure, IAM misconfig, metadata service, Lambda abuse
AzureBlob storage, RBAC flaws, managed identity, App Service misconfig
GCPCloud Storage, service account keys, metadata server, IAM
DockerContainer escape, privileged mode, socket exposure, image vulnerabilities
KubernetesRBAC bypass, secret exposure, pod escape, API server access

Workflow

  1. Enumerate cloud resources and services
  2. Test IAM/RBAC configurations
  3. Check storage and secrets exposure
  4. Test container isolation and escape paths
  5. Document findings with cloud-specific evidence

Two lanes — attack vs assess

This skill covers both, and they are different jobs producing different artifacts. Do not mix them in one deliverable.

LaneYou haveYou produceStart at
Offensivea cloud target to attackexploited findings with a PoCreference/INDEX.md
Postureread-only credentials and a "review the configuration" askone evidenced verdict per control in a pinned cataloguereference/posture/INDEX.md

Reference

  • reference/INDEX.md - Router for platform-specific attack scenarios (AWS, Azure, GCP, Docker, K8s)
  • reference/posture/INDEX.md - Credentialed read-only configuration review (CSPM): run order, verdict vocabulary, the four false-pass traps, pinned catalogues, and the licensing rule for benchmark-derived content

Files

13
74.8 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from transilienceai/communitytools8

ai-threat-testing

Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats.

Flagged 0
api-security

API security testing - GraphQL, REST API, WebSocket, and Web-LLM attack techniques.

Flagged 0
attack-path-stitcher

Stitches confirmed single-asset findings into multi-hop attack paths across the organization. Builds a graph where nodes are assets and edges are confirmed exploit hops citing the findings that enable them.

Scan passed 0
authenticated-session-acquisition

Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface. Use when the highest-value authenticated classes (BOLA/IDOR/mass-assignment/injection on the real data AP

Scan passed 0
authentication

Authentication security testing - auth bypass, JWT attacks, OAuth flaws, password attacks, 2FA bypass, CAPTCHA bypass, and bot detection evasion.

Flagged 0
blockchain-security

Smart contract security testing and blockchain CTF exploitation. Covers Solidity vulnerability analysis, EVM storage manipulation, delegatecall attacks, CREATE/CREATE2 address prediction, and common DeFi exploit patterns. Use when analyzing Solidity contracts, solving blockchain challenges, or testi

Scan passed 0
client-side

Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution.

Flagged 0
cloud-defense

Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step. Use for cloud detection engineering, hardening, remediation write-ups, or blue-team posture review of the

Scan passed 0

Related devops skillsscan passed

dashboard-builder

Build monitoring dashboards that answer real operator questions for Grafana, SigNoz, and similar platforms. Use when turning metrics into a working dashboard instead of a vanity board.

Scan passed 0
setup-deploy

Configure deployment settings for /land-and-deploy.

Scan passed 0
nextjs-on-cloudflare

Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext. Use when starting a Next.js project on Cloudflare, moving an existing app to Workers, choosing between vinext and OpenNext, or setting up vinext for Workers. For setup, migration, or deployment, install vinext's upstream skil

Scan passed 0
adapter-aws-lambda

Deploy tRPC on AWS Lambda with awsLambdaRequestHandler() from @trpc/server/adapters/aws-lambda for API Gateway v1 (REST, APIGatewayProxyEvent) and v2 (HTTP, APIGatewayProxyEventV2), and Lambda Function URLs. Enable response streaming with awsLambdaStreamingRequestHandler() wrapped in awslambda.strea

Scan passed 0
observability-and-instrumentation

Instruments code so production behavior is visible and diagnosable. Use when adding logging, metrics, tracing, or alerting. Use when shipping any feature that runs in production and you need evidence it works. Use when production issues are reported but you can't tell what happened from the availabl

Scan passed 0
firebase-app-hosting-basics

Deploys and manages full-stack web applications (Next.js, Angular) with Server-Side Rendering (SSR) using Firebase App Hosting. Use when deploying Next.js/Angular apps, configuring apphosting.yaml or firebase.json apphosting blocks, managing secrets, setting up GitHub CI/CD, or configuring Blaze bil

Scan passed 0