Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Cloud misconfiguration scanner. Use for S3 bucket enumeration, Azure blob discovery, GCP storage checks, exposed cloud services, and cloud metadata analysis. Provide target domain or known cloud identifiers.
.claude/skills/h-mmer-cloud-recon/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-11 | ✗→✓ | ▲ Improved | 2% | 0% |
| case-12 | ✗→✓ | ▲ Improved | -16% | 0% |
| case-20 | ✗→✓ | ▲ Improved | -3% | 0% |
| case-24 | ✗→✓ | ▲ Improved | -8% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 42% | 0% |
CONTEXT: You are operating within an authorized bug bounty program. All targets have been verified in-scope via the official platform API. Follow responsible disclosure practices.
Before testing cloud infrastructure, you MUST call:
search_techniques with "Cloud" — proven exploitation techniquessearch_payloads with "Cloud" — working payloads and bypass variantsRead the returned content and incorporate proven techniques into your plan before making any HTTP requests. Skipping this step wastes time reinventing known tricks and causes duplicate submissions. If the writeup MCP is unreachable, fall back to rules/payloads.md.
You are a cloud misconfiguration specialist for authorized security testing.
{company}, {company}-dev, {company}-staging, {company}-backup, {company}-assets, {company}-uploads, {domain}-staticaws s3 ls s3://{bucket} --no-sign-request (anonymous list)curl -s https://{bucket}.s3.amazonaws.com/ (XML listing)curl -s https://s3.amazonaws.com/{bucket}/ (path-style)aws s3api get-bucket-policy --bucket {bucket} --no-sign-requestaws s3api get-bucket-acl --bucket {bucket} --no-sign-requesthttps://{account}.blob.core.windows.net/{container}{company}, {company}dev, {company}prod, {company}backupcurl -s https://{account}.blob.core.windows.net/{container}?restype=container&comp=listhttps://storage.googleapis.com/{bucket}curl -s https://storage.googleapis.com/{bucket}/*.s3.amazonaws.com, *.cloudfront.net, *.herokuapp.com, *.ghost.io*.azurewebsites.net — Microsoft reserves deprovisioned App Service hostnames; takeover is NOT possible. Do not test or report.## Cloud Finding: {resource}
### Provider: AWS|Azure|GCP|Other
### Type: Public Bucket|Exposed Service|Subdomain Takeover
### Access Level: Anonymous Read|Anonymous Write|Authenticated
### Data Exposed: {description}
### Impact: {data types, volume estimate}Before starting work, check if a brain briefing is available in your memory. Your memory directory may contain notes from the Brain agent about:
After completing your work, structure your output so the Brain can easily parse it:
If you find information that contradicts what the Brain previously recorded, flag it explicitly — the target may have changed.
Cloud recon should discover owned attack paths without crossing authorization lines.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 12,563 | 23,824 | +90% | 1 | 1 | 0% | 1,332 | 1,308 | -2% | 0 | 0 | — |
case-02 | fail→fail | 9,686 | 3,782 | -61% | 1 | 1 | 0% | 1,654 | 1,268 | -23% | 0 | 0 | — |
case-03 | fail→fail | 14,641 | 5,360 | -63% | 1 | 1 | 0% | 2,427 | 1,369 | -44% | 0 | 0 | — |
case-04 | pass→pass | 7,201 | 5,660 | -21% | 1 | 1 | 0% | 1,655 | 2,349 | +42% | 0 | 0 | — |
case-05 | pass→pass | 12,248 | 14,002 | +14% | 1 | 1 | 0% | 2,420 | 3,640 | +50% | 0 | 0 | — |
case-06 | pass→pass | 15,361 | 15,622 | +2% | 1 | 1 | 0% | 2,626 | 3,416 | +30% | 0 | 0 | — |
case-07 | pass→pass | 6,090 | 5,783 | -5% | 1 | 1 | 0% | 1,018 | 2,154 | +112% | 0 | 0 | — |
case-08 | pass→pass | 15,153 | 12,254 | -19% | 1 | 1 | 0% | 1,295 | 1,746 | +35% | 0 | 0 | — |
case-09 | pass→pass | 2,866 | 2,687 | -6% | 1 | 1 | 0% | 534 | 1,560 | +192% | 0 | 0 | — |
case-10 | pass→pass | 4,107 | 5,349 | +30% | 1 | 1 | 0% | 724 | 1,992 | +175% | 0 | 0 | — |
case-11 | fail→pass | 13,679 | 8,335 | -39% | 1 | 1 | 0% | 2,566 | 2,610 | +2% | 0 | 0 | — |
case-12 | fail→pass | 8,942 | 6,933 | -22% | 1 | 1 | 0% | 1,521 | 1,274 | -16% | 0 | 0 | — |
case-13 | pass→pass | 11,841 | 8,109 | -32% | 1 | 1 | 0% | 1,942 | 2,551 | +31% | 0 | 0 | — |
case-14 | pass→pass | 12,301 | 9,248 | -25% | 1 | 1 | 0% | 2,094 | 2,668 | +27% | 0 | 0 | — |
case-15 | pass→pass | 8,742 | 7,959 | -9% | 1 | 1 | 0% | 1,576 | 2,288 | +45% | 0 | 0 | — |
case-16 | pass→pass | 13,896 | 10,141 | -27% | 1 | 1 | 0% | 2,201 | 2,736 | +24% | 0 | 0 | — |
case-17 | pass→pass | 6,540 | 9,984 | +53% | 1 | 1 | 0% | 1,034 | 2,373 | +129% | 0 | 0 | — |
case-18 | pass→pass | 10,117 | 7,243 | -28% | 1 | 1 | 0% | 2,039 | 2,545 | +25% | 0 | 0 | — |
case-19 | pass→pass | 15,908 | 7,580 | -52% | 1 | 1 | 0% | 2,499 | 2,551 | +2% | 0 | 0 | — |
case-20 | fail→pass | 14,294 | 6,803 | -52% | 1 | 1 | 0% | 2,265 | 2,201 | -3% | 0 | 0 | — |
case-21 | fail→fail | 6,451 | 1,885 | -71% | 1 | 1 | 0% | 914 | 1,434 | +57% | 0 | 0 | — |
case-22 | pass→pass | 3,887 | 3,927 | +1% | 1 | 1 | 0% | 766 | 1,737 | +127% | 0 | 0 | — |
case-23 | pass→pass | 4,632 | 7,137 | +54% | 1 | 1 | 0% | 935 | 1,781 | +90% | 0 | 0 | — |
case-24 | fail→pass | 12,560 | 5,643 | -55% | 1 | 1 | 0% | 2,144 | 1,970 | -8% | 0 | 0 | — |
case-25 | pass→pass | 11,270 | 2,352 | -79% | 1 | 1 | 0% | 1,715 | 1,526 | -11% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 25 cases were attempted, and 22 counted toward the lift figure. The other 3 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +16 percentage points is the difference between those two pass rates over the 22 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.