cloud-containers
Cloud and container security testing - AWS, Azure, GCP, Docker, and Kubernetes misconfigurations and exploitation.
How do I install this agent skill?
npx skills add https://github.com/transilienceai/communitytools --skill cloud-containersIs this agent skill safe to install?
- Gen Agent Trust Hubwarn
This skill provides comprehensive techniques for cloud and container security testing, including offensive exploitation strategies. It contains commands for privilege escalation, data exfiltration from storage services, and remote command execution on cloud instances and containers. While these instructions are intended for security auditing and red teaming, they represent high-privilege capabilities that could be misused. The skill also facilitates the installation of various external security tools and guides users in hunting for credentials within system configuration files.
- Socketfail
8 alerts: gptSecurity, gptMalware
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Cloud & Containers
Test cloud infrastructure and container environments for security misconfigurations and exploitation paths.
Techniques
| Platform | Key Vectors |
|---|---|
| AWS | S3 bucket exposure, IAM misconfig, metadata service, Lambda abuse |
| Azure | Blob storage, RBAC flaws, managed identity, App Service misconfig |
| GCP | Cloud Storage, service account keys, metadata server, IAM |
| Docker | Container escape, privileged mode, socket exposure, image vulnerabilities |
| Kubernetes | RBAC bypass, secret exposure, pod escape, API server access |
Workflow
- Enumerate cloud resources and services
- Test IAM/RBAC configurations
- Check storage and secrets exposure
- Test container isolation and escape paths
- Document findings with cloud-specific evidence
Two lanes — attack vs assess
This skill covers both, and they are different jobs producing different artifacts. Do not mix them in one deliverable.
| Lane | You have | You produce | Start at |
|---|---|---|---|
| Offensive | a cloud target to attack | exploited findings with a PoC | reference/INDEX.md |
| Posture | read-only credentials and a "review the configuration" ask | one evidenced verdict per control in a pinned catalogue | reference/posture/INDEX.md |
Reference
reference/INDEX.md- Router for platform-specific attack scenarios (AWS, Azure, GCP, Docker, K8s)reference/posture/INDEX.md- Credentialed read-only configuration review (CSPM): run order, verdict vocabulary, the four false-pass traps, pinned catalogues, and the licensing rule for benchmark-derived content
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/transilienceai/communitytools/cloud-containers">View cloud-containers on skillZs</a>