AWS Penetration Testing
Audited by Socket on Feb 16, 2026
1 alert found:
Malware[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Instruction to copy/paste content into terminal detected (CI012) [AITech 9.1.4] The skill presents a comprehensive but dangerous offensive playbook for AWS environments, including credential harvesting, privilege escalation, persistence, and cover-tracks. It is not suitable for safe, responsible supply-chain security tooling in its current form and should be restricted, gated, or removed from public distribution. Any legitimate use must be tightly scoped, authorized, and auditable to mitigate abuse risk. LLM verification: This SKILL.md is an explicit offensive playbook for compromising AWS environments. It contains direct, actionable instructions to harvest credentials (IMDS and container endpoints), escalate privileges (create access keys, attach AdministratorAccess, add user to groups), modify Lambda code to persist or escalate, and exfiltrate S3/Lambda contents. As documentation it is coherent with its stated pentesting purpose, but the capability set is highly dangerous and readily abused. There is no safe-gu