CtrlK
BlogDocsLog inGet started
Tessl Logo

cloud-overview

Cloud exploitation lane — AWS IAM privesc, S3 takeover, k8s RBAC abuse, Terraform state leaks, cloud metadata pivoting.

64

Quality

77%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

Fix and improve this skill with Tessl

tessl review fix ./packages/decepticon/decepticon/skills/standard/cloud/SKILL.md
SKILL.md
Quality
Evals
Security

Cloud Hunter Skill Catalog

Playbooks

SkillUse for
/skills/standard/cloud/aws-iam-enum/SKILL.mdIAM enumeration + privesc
/skills/standard/cloud/s3-takeover/SKILL.mdDangling bucket / subdomain takeover
/skills/standard/cloud/k8s-pivot/SKILL.mdPod escape, RBAC abuse, hostPath
/skills/standard/cloud/terraform-state-leak/SKILL.mdExposed state file exploitation
/skills/standard/cloud/imds-pivot/SKILL.mdSSRF → metadata → IAM role

Workflow (authenticated engagement)

  1. bash("aws sts get-caller-identity")
  2. bash("aws iam list-attached-user-policies --user-name <me>")
  3. For each attached policy: fetch JSON and iam_policy_audit
  4. Feed Terraform state via bash("aws s3 cp s3://bucket/terraform.tfstate -")tfstate_audit
  5. bash("kubectl get pods -A -o json")k8s_audit
  6. Every privesc primitive → kg_add_node + chain edges

Workflow (post-SSRF)

  1. metadata_endpoints("aws") for the target cloud
  2. Pivot URL one at a time via the SSRF vector
  3. Confirmed creds → credential node + leaks edge from the SSRF vuln
  4. plan_attack_chains(promote=True) to see the full path
Repository
PurpleAILAB/Decepticon
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.