pentest-cloud-infrastructure
SKILL.md
Pentest Cloud Infrastructure
Purpose
Assess the security configuration of cloud environments and containerized infrastructure to detect misconfigurations, excessive permissions, and vulnerabilities.
Core Workflow
- Cloud Config Audit: Assess cloud provider configuration (AWS/Azure/GCP) using
prowlerandscoutsuite. - IaC Scanning: Analyze Infrastructure-as-Code (Terraform, CloudFormation) for security flaws using
checkovandterrascan. - Container Security: Scan container images and runtime environments using
trivy,clair, anddockle. - Kubernetes Assessment: Audit K8s clusters for CIS compliance and vulnerabilities using
kube-benchandkube-hunter. - Runtime Monitoring: Analyze runtime behavior and rule violations using
falco.
References
references/tools.mdreferences/workflows.md
Weekly Installs
24
Repository
jd-opensource/joysafeterGitHub Stars
182
First Seen
Feb 18, 2026
Security Audits
Installed on
gemini-cli24
github-copilot24
codex24
amp24
kimi-cli24
cursor24