CtrlK
BlogDocsLog inGet started
Tessl Logo

cloud-attack-methods

云攻击:元数据API,S3/K8s,AWS/Azure/GCP身份提权,MinIO矩阵,阿里云FC,ChengZi SDK解密。Use when attacking cloud metadata, IAM, K8s, MinIO, Aliyun FC, or cloud post-ex.

61

Quality

73%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./skills/cloud-attack-methods/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

72%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A maximally dense, highly actionable cloud attack cheat sheet: concrete endpoints, requests, and CVEs with no wasted tokens. Its weaknesses are structural — everything lives in one undifferentiated code block with no per-surface sections, no workflows/sequences, and no validation checkpoints for the risky operations it describes.

Suggestions

Break the single code block into per-surface sections (AWS, Azure/Entra, GCP, K8s, MinIO, Aliyun FC, ChengZi) or split each into a reference file, keeping SKILL.md as an index with pointers.

For each attack path add a minimal verify step (e.g., confirm anonymous access with 'GET /bucket-name/ → 200 ListBucket' before attempting writes) so the destructive/batch operations have checkpoints.

Convert tool-name hints (enumerate-iam, cloudfox, roadrecon) into the actual runnable commands so every entry is copy-paste executable.

DimensionReasoningScore

Conciseness

The body is pure telegraphic reference notes with zero concept explanations and zero padding ("kubelet 10250未授权(/pods列举,/exec进任意容器)"). Every token carries information Claude does not already have, matching the lean-and-efficient anchor.

5 / 5

Actionability

Many entries are copy-paste ready ("POST http://IP:9001/api/v1/login body={\"accessKey\":\"minioadmin\",\"secretKey\":\"minioadmin\"}", "CVE-2023-28432: POST /minio/health/cluster?verify") with exact endpoints, responses, and CVE paths. It falls short of anchor 5 because some entries only name tools or intent ("enumerate-iam/cloudfox/ScoutSuite枚举权限", "服务主体加凭据") without the actual commands.

4 / 5

Workflow Clarity

Content is grouped by attack surface with 🚨 markers and an implied 指纹→利用 ordering, but there are no explicit step sequences, decision points, or validation/verification checkpoints. The destructive/batch cap applies: attack workflows without validation cannot exceed 3.

3 / 5

Progressive Disclosure

No bundle files exist; everything is inline under a single header in one code block. The block is internally grouped (AWS/Azure/GCP, K8s, MinIO matrix, Aliyun FC, ChengZi), so there is some structure, but it is not the 'well-organized sections' the under-50-line exception rewards, and per-platform content clearly could be split into reference files.

3 / 5

Total

15

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A distinct, niche-scoped description with a good explicit trigger clause, but the capability half is a compressed bilingual topic dump rather than a clear statement of concrete actions. Trigger coverage is good though missing a few common synonyms.

Suggestions

Rewrite the 'what' half as a short list of concrete actions in one language (e.g., 'Enumerate cloud metadata endpoints, escalate AWS/Azure/GCP identities, exploit MinIO and Aliyun FC misconfigurations, decrypt ChengZi SDK responses') instead of comma-separated topic nouns.

Add common synonyms and full names to the trigger clause (Kubernetes, object storage/S3, post-exploitation) so users phrasing the need differently still match.

Keep the description in third person and avoid mixed-language telegraphic style, which makes the capability statement harder to parse.

DimensionReasoningScore

Specificity

The description names the domains ("元数据API,S3/K8s,AWS/Azure/GCP身份提权,MinIO矩阵,阿里云FC,ChengZi SDK解密") but only a couple of action verbs (提权/privesc, 解密/decrypt); it is a topic enumeration rather than a list of concrete actions. Anchor 3 fits best — domain named with 1-2 concrete actions — and it does not reach anchor 4 because no several executable capabilities are stated.

3 / 5

Completeness

Both a 'what' (the topic list) and an explicit 'when' ("Use when attacking...") are present. It is not the anchor-5 case because the 'what' half is a telegraphic comma-separated topic list rather than a clearly stated set of capabilities.

4 / 5

Trigger Term Quality

The "Use when attacking cloud metadata, IAM, K8s, MinIO, Aliyun FC, or cloud post-ex" clause covers natural terms a user would say, including the niche ones. It stays at anchor 4 rather than 5 because common synonyms and variations (e.g., Kubernetes/object storage/S3) are absent.

4 / 5

Distinctiveness Conflict Risk

"MinIO矩阵,阿里云FC,ChengZi SDK解密" are highly distinct niche triggers unlikely to collide with other skills. Minor breadth from "IAM"/"cloud metadata" is not enough to drop below anchor 5.

5 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
AIPentest/CyberStrikeAI
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.