conducting-cloud-penetration-testing

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/agent.py script utilizes subprocess.run to execute various AWS CLI commands for infrastructure enumeration and vulnerability detection.
  • [DATA_EXFILTRATION]: The skill includes functionality to scan Lambda environment variables for sensitive keywords such as passwords and API keys, and checks for publicly accessible S3 buckets for the purpose of exposure reporting.
  • [COMMAND_EXECUTION]: The instructions in SKILL.md guide the agent to perform actions such as creating backdoor IAM users and disabling CloudTrail logging to test organizational detection capabilities, which are documented as authorized security testing procedures.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 09:41 AM