Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Multi-cloud security assessment and penetration testing capabilities. Execute Prowler/ScoutSuite assessments, analyze IAM policies, identify cloud misconfigurations, test permissions, and enumerate cloud resources across AWS/GCP/Azure.
.claude/skills/a5c-ai-cloud-security-testing/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-02 | ✗→✓ | ▲ Improved | 82% | 0% |
| case-13 | ✗→✓ | ▲ Improved | 81% | 0% |
| case-19 | ✗→✓ | ▲ Improved | 103% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 153% | 0% |
| case-06 | ✓→✓ | = Same ✓ | 67% | 0% |
You are cloud-security-testing - a specialized skill for multi-cloud security assessment and authorized penetration testing across AWS, GCP, and Azure environments.
This skill enables AI-powered cloud security operations including:
This skill is designed for authorized security research and penetration testing contexts only. All operations must:
Execute comprehensive security assessments using Prowler:
bash# AWS Security Assessment prowler aws --output-formats json,html -M csv # Specific compliance framework prowler aws --compliance cis_2.0_aws # Scan specific services prowler aws --services s3,iam,ec2,rds # Azure Assessment prowler azure --subscription-ids <subscription-id> # GCP Assessment prowler gcp --project-id <project-id>
Run ScoutSuite for comprehensive cloud auditing:
bash# AWS Scout Assessment scout aws --report-dir ./scout-report # Azure Scout Assessment scout azure --cli --report-dir ./scout-report # GCP Scout Assessment scout gcp --user-account --report-dir ./scout-report # All providers with specific rules scout aws --ruleset custom-ruleset.json
Analyze IAM policies for security issues:
bash# List all IAM policies aws iam list-policies --scope Local # Get policy document aws iam get-policy-version --policy-arn <arn> --version-id v1 # Analyze role trust relationships aws iam list-roles --query 'Roles[].AssumeRolePolicyDocument' # Find overly permissive policies aws iam get-account-authorization-details --output json
yamliam_misconfigurations: overly_permissive: - "*:*" actions in policies - Resource "*" without conditions - Missing MFA requirements privilege_escalation: - iam:CreatePolicy with iam:AttachUserPolicy - iam:CreateLoginProfile for other users - iam:UpdateAssumeRolePolicy - lambda:CreateFunction with iam:PassRole trust_issues: - External account trust without conditions - Wildcard principals in trust policies - Missing ExternalId for cross-account access
Assess S3 bucket security posture:
bash# List all buckets aws s3api list-buckets # Check bucket ACL aws s3api get-bucket-acl --bucket <bucket-name> # Check bucket policy aws s3api get-bucket-policy --bucket <bucket-name> # Check public access block aws s3api get-public-access-block --bucket <bucket-name> # Check encryption aws s3api get-bucket-encryption --bucket <bucket-name> # Test anonymous access (authorized testing only) aws s3 ls s3://<bucket-name> --no-sign-request
Enumerate cloud resources for attack surface analysis:
bash# EC2 Instances aws ec2 describe-instances --query 'Reservations[].Instances[].[InstanceId,PublicIpAddress,State.Name]' # Security Groups aws ec2 describe-security-groups --query 'SecurityGroups[?IpPermissions[?IpRanges[?CidrIp==`0.0.0.0/0`]]]' # RDS Instances aws rds describe-db-instances --query 'DBInstances[].[DBInstanceIdentifier,PubliclyAccessible]' # Lambda Functions aws lambda list-functions --query 'Functions[].[FunctionName,Role]' # Secrets Manager aws secretsmanager list-secrets
For authorized AWS penetration testing:
python# Pacu session management # Import module import_module ec2__enum import_module iam__enum_permissions import_module s3__bucket_finder # Run enumeration run ec2__enum run iam__enum_permissions run s3__bucket_finder # Check for privilege escalation paths run iam__privesc_scan
bash# List subscriptions az account list # Check storage account security az storage account list --query '[].{Name:name,HttpsOnly:enableHttpsTrafficOnly,MinTlsVersion:minimumTlsVersion}' # Network security groups az network nsg list --query '[].{Name:name,Rules:securityRules}' # Key Vault access policies az keyvault list --query '[].{Name:name,EnableSoftDelete:properties.enableSoftDelete}' # Azure AD applications az ad app list --query '[].{DisplayName:displayName,AppId:appId}'
bash# List projects gcloud projects list # IAM policy gcloud projects get-iam-policy <project-id> # Service accounts gcloud iam service-accounts list # Storage bucket IAM gsutil iam get gs://<bucket-name> # Firewall rules gcloud compute firewall-rules list --format=json
This skill can leverage the following MCP servers for enhanced capabilities:
| Server | Description | URL | |--------|-------------|-----| | AWS MCP Server | AWS CLI operations via MCP | https://github.com/alexei-led/aws-mcp-server | | AWS MCP (RafalWilinski) | Talk with AWS using Claude | https://github.com/RafalWilinski/aws-mcp | | Azure MCP-Kubernetes | Azure Kubernetes security | https://github.com/Azure/mcp-kubernetes | | AKS-MCP | Azure Kubernetes Service | https://github.com/Azure/aks-mcp | | AWS Labs MCP | Official AWS MCP collection | https://awslabs.github.io/mcp/ |
yamlcis_benchmarks: identity_access_management: - MFA enabled for root - No root access keys - Password policy compliance - Unused credentials removed logging: - CloudTrail enabled - CloudTrail log validation - S3 bucket logging - VPC flow logs monitoring: - Security group changes - NACL changes - Gateway changes - IAM policy changes networking: - Default VPC not used - Security groups restrict traffic - No unrestricted SSH/RDP - VPC peering routes
This skill integrates with the following processes:
cloud-security-research.js - Cloud security assessment workflowscontainer-security-research.js - Container and Kubernetes securitybug-bounty-workflow.js - Cloud-focused bug bounty programsred-team-operations.js - Cloud attack simulationsWhen executing operations, provide structured output:
json{ "assessment_type": "prowler", "cloud_provider": "aws", "account_id": "123456789012", "scan_timestamp": "2026-01-24T10:30:00Z", "findings": { "critical": 3, "high": 12, "medium": 28, "low": 45 }, "critical_findings": [ { "check_id": "iam_root_access_key", "title": "Root account has active access keys", "risk": "critical", "resource": "root", "remediation": "Delete root access keys and use IAM users" } ], "compliance_status": { "cis_2.0": "78%", "pci_dss": "65%" }, "recommendations": [ "Enable MFA on root account", "Remove unused IAM credentials", "Enable CloudTrail in all regions" ] }
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 18,734 | 18,009 | -4% | 1 | 1 | 0% | 1,088 | 3,474 | +219% | 0 | 0 | — |
case-02 | fail→pass | 17,213 | 18,333 | +7% | 1 | 1 | 0% | 1,988 | 3,611 | +82% | 0 | 0 | — |
case-03 | fail→fail | 17,537 | 19,348 | +10% | 1 | 1 | 0% | 1,248 | 3,786 | +203% | 0 | 0 | — |
case-04 | pass→pass | 10,714 | 3,818 | -64% | 1 | 1 | 0% | 1,052 | 2,660 | +153% | 0 | 0 | — |
case-05 | fail→fail | 15,735 | 8,028 | -49% | 1 | 1 | 0% | 1,885 | 3,638 | +93% | 0 | 0 | — |
case-06 | pass→pass | 12,851 | 2,231 | -83% | 1 | 1 | 0% | 1,500 | 2,509 | +67% | 0 | 0 | — |
case-07 | pass→pass | 5,828 | 7,604 | +30% | 1 | 1 | 0% | 1,011 | 2,563 | +154% | 0 | 0 | — |
case-08 | pass→pass | 7,351 | 7,464 | +2% | 1 | 1 | 0% | 426 | 2,545 | +497% | 0 | 0 | — |
case-09 | pass→pass | 10,877 | 9,479 | -13% | 1 | 1 | 0% | 1,033 | 2,926 | +183% | 0 | 0 | — |
case-10 | pass→pass | 3,084 | 9,439 | +206% | 1 | 1 | 0% | 549 | 2,502 | +356% | 0 | 0 | — |
case-11 | pass→pass | 8,488 | 6,953 | -18% | 1 | 1 | 0% | 652 | 2,457 | +277% | 0 | 0 | — |
case-12 | pass→pass | 16,150 | 7,572 | -53% | 1 | 1 | 0% | 2,112 | 3,655 | +73% | 0 | 0 | — |
case-13 | fail→pass | 10,549 | 10,825 | +3% | 1 | 1 | 0% | 1,796 | 3,250 | +81% | 0 | 0 | — |
case-14 | pass→pass | 8,394 | 7,566 | -10% | 1 | 1 | 0% | 632 | 2,575 | +307% | 0 | 0 | — |
case-15 | pass→pass | 8,530 | 12,616 | +48% | 1 | 1 | 0% | 617 | 3,004 | +387% | 0 | 0 | — |
case-16 | pass→pass | 15,970 | 9,999 | -37% | 1 | 1 | 0% | 2,090 | 2,856 | +37% | 0 | 0 | — |
case-17 | pass→pass | 15,384 | 10,989 | -29% | 1 | 1 | 0% | 1,775 | 3,211 | +81% | 0 | 0 | — |
case-18 | pass→pass | 8,772 | 11,222 | +28% | 1 | 1 | 0% | 1,560 | 3,169 | +103% | 0 | 0 | — |
case-19 | fail→pass | 12,762 | 4,453 | -65% | 1 | 1 | 0% | 1,421 | 2,878 | +103% | 0 | 0 | — |
case-20 | pass→pass | 16,059 | 8,640 | -46% | 1 | 1 | 0% | 2,077 | 3,729 | +80% | 0 | 0 | — |
case-21 | pass→pass | 8,908 | 4,701 | -47% | 1 | 1 | 0% | 735 | 2,942 | +300% | 0 | 0 | — |
case-22 | pass→pass | 8,548 | 5,426 | -37% | 1 | 1 | 0% | 601 | 3,141 | +423% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +14 percentage points is the difference between those two pass rates over the 22 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.