cloud-containers
Cloud and container security testing - AWS, Azure, GCP, Docker, and Kubernetes misconfigurations and exploitation.
- 0
- Installs
- —
- Rating
- —
- Success rate
- 13
- Files scanned
Do not let an agent install this unattended
Security scan
FlaggedHigh-risk patterns found. A human should read the source before any agent installs this.
- criticalReads credentials and sends them over the network
reference/scenarios/aws/moto-mock-aws-quirks.md:179
curl -sk "http://<VHOST>/restapis/<api_id>/<stage>/_user_request_/<route>?&.json" --data-urlencode "cmd=({})[__import__('os').environ['AWS_SECRET_ACCESS_K…Combines access to secrets (SSH keys, cloud creds, tokens, .env) with a network call on the same line.
- mediumSkips hooks, TLS checks or browser sandbox
reference/scenarios/kubernetes/recon-and-rbac.md:80
curl -k https://kubernetes-api:6443/api/v1/namespaces
Sometimes needed (CI containers, local certs) but each one turns off a check that exists for a reason.
- mediumSkips hooks, TLS checks or browser sandbox
reference/scenarios/kubernetes/recon-and-rbac.md:84
curl -k -H "Authorization: Bearer $TOKEN" https://kubernetes.default.svc/api/v1/namespaces
Sometimes needed (CI containers, local certs) but each one turns off a check that exists for a reason.
Not scanned (too large or unreadable): skills/cloud-containers/reference/posture/catalog/cis-oci-foundations-v3.1.1.json, skills/cloud-containers/reference/posture/catalog/mcsb-azure-foundations-v1.json, skills/cloud-containers/reference/posture/catalog/nsa-cisa-k8s-hardening-1.2.json
Content sha256 68404f0260686bbc… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Cloud & Containers
Test cloud infrastructure and container environments for security misconfigurations and exploitation paths.
Techniques
| Platform | Key Vectors |
|---|---|
| AWS | S3 bucket exposure, IAM misconfig, metadata service, Lambda abuse |
| Azure | Blob storage, RBAC flaws, managed identity, App Service misconfig |
| GCP | Cloud Storage, service account keys, metadata server, IAM |
| Docker | Container escape, privileged mode, socket exposure, image vulnerabilities |
| Kubernetes | RBAC bypass, secret exposure, pod escape, API server access |
Workflow
- Enumerate cloud resources and services
- Test IAM/RBAC configurations
- Check storage and secrets exposure
- Test container isolation and escape paths
- Document findings with cloud-specific evidence
Two lanes — attack vs assess
This skill covers both, and they are different jobs producing different artifacts. Do not mix them in one deliverable.
| Lane | You have | You produce | Start at |
|---|---|---|---|
| Offensive | a cloud target to attack | exploited findings with a PoC | reference/INDEX.md |
| Posture | read-only credentials and a "review the configuration" ask | one evidenced verdict per control in a pinned catalogue | reference/posture/INDEX.md |
Reference
reference/INDEX.md- Router for platform-specific attack scenarios (AWS, Azure, GCP, Docker, K8s)reference/posture/INDEX.md- Credentialed read-only configuration review (CSPM): run order, verdict vocabulary, the four false-pass traps, pinned catalogues, and the licensing rule for benchmark-derived content
Files
13- SKILL.md
8a232fb35e1.9 KB - reference/INDEX.md
650b738c591.6 KB - reference/cloud-containers-principles.md
3ed998b4d74.0 KB - reference/posture/INDEX.md
9dc4ab24c37.2 KB - reference/posture/posture-collect.md
def97a6a565.3 KB - reference/scenarios/aws/minio-self-hosted-s3.md
d905a561f13.4 KB - reference/scenarios/aws/moto-mock-aws-quirks.md
a9d7ba2ac410.7 KB - reference/scenarios/aws/recon-and-iam-privesc.md
75fea84e5911.2 KB - reference/scenarios/aws/serverless-and-saas.md
61078cb4c95.0 KB - reference/scenarios/azure/recon-and-storage.md
09c78ff4157.1 KB - reference/scenarios/docker/container-recon-and-escape.md
88a31ba5924.8 KB - reference/scenarios/gcp/recon-and-iam.md
958f8d3c0b4.9 KB - reference/scenarios/kubernetes/recon-and-rbac.md
185d3952137.6 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from transilienceai/communitytools8
Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats.
API security testing - GraphQL, REST API, WebSocket, and Web-LLM attack techniques.
Stitches confirmed single-asset findings into multi-hop attack paths across the organization. Builds a graph where nodes are assets and edges are confirmed exploit hops citing the findings that enable them.
Acquire an authenticated session THROUGH MFA/OTP on an in-scope target and emit a reusable session artifact (Playwright storageState + Bearer) so executors can test the post-auth attack surface. Use when the highest-value authenticated classes (BOLA/IDOR/mass-assignment/injection on the real data AP
Authentication security testing - auth bypass, JWT attacks, OAuth flaws, password attacks, 2FA bypass, CAPTCHA bypass, and bot detection evasion.
Smart contract security testing and blockchain CTF exploitation. Covers Solidity vulnerability analysis, EVM storage manipulation, delegatecall attacks, CREATE/CREATE2 address prediction, and common DeFi exploit patterns. Use when analyzing Solidity contracts, solving blockchain challenges, or testi
Client-side vulnerability testing - XSS (reflected/stored/DOM), CSRF, CORS misconfiguration, Clickjacking, DOM-based attacks, and Prototype Pollution.
Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step. Use for cloud detection engineering, hardening, remediation write-ups, or blue-team posture review of the
Related devops skillsscan passed
Build monitoring dashboards that answer real operator questions for Grafana, SigNoz, and similar platforms. Use when turning metrics into a working dashboard instead of a vanity board.
Configure deployment settings for /land-and-deploy.
Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext. Use when starting a Next.js project on Cloudflare, moving an existing app to Workers, choosing between vinext and OpenNext, or setting up vinext for Workers. For setup, migration, or deployment, install vinext's upstream skil
Deploy tRPC on AWS Lambda with awsLambdaRequestHandler() from @trpc/server/adapters/aws-lambda for API Gateway v1 (REST, APIGatewayProxyEvent) and v2 (HTTP, APIGatewayProxyEventV2), and Lambda Function URLs. Enable response streaming with awsLambdaStreamingRequestHandler() wrapped in awslambda.strea
Instruments code so production behavior is visible and diagnosable. Use when adding logging, metrics, tracing, or alerting. Use when shipping any feature that runs in production and you need evidence it works. Use when production issues are reported but you can't tell what happened from the availabl
Deploys and manages full-stack web applications (Next.js, Angular) with Server-Side Rendering (SSR) using Firebase App Hosting. Use when deploying Next.js/Angular apps, configuring apphosting.yaml or firebase.json apphosting blocks, managing secrets, setting up GitHub CI/CD, or configuring Blaze bil