cloud-and-infra

Identify exposed cloud, container, CI/CD, and TLS weaknesses during authorized reconnaissance.

4|Updated Apr 29, 2026
One-click install
npx skills add https://github.com/Ap6pack/outrider-recon --skill cloud-and-infra
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cloud-and-infra
Source: https://github.com/Ap6pack/outrider-recon/tree/main/skills/cloud-and-infra
Command: npx skills add https://github.com/Ap6pack/outrider-recon --skill cloud-and-infra

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps authorized security teams identify and prioritize exposed cloud services, container infrastructure, CI/CD platforms, and weak TLS configurations without turning reconnaissance into exploitation.

Core Features & Use Cases

  • Cloud-Native Fingerprinting: Classify AWS, Google Cloud, Azure, and modern application-platform endpoints and assess public versus authenticated access.
  • Infrastructure Exposure Checks: Review Kubernetes, Docker, etcd, container registries, and CI/CD platforms for dangerous anonymous or misconfigured access.
  • TLS and Favicon Analysis: Perform deep TLS configuration audits and use favicon hashes to pivot toward related infrastructure.
  • Evidence-Based Triage: Produce severity-ranked infrastructure findings with provider, service type, authentication posture, detectability, and evidence requirements.
  • Use Case: An authorized bug bounty team can review discovered subdomains for public cloud functions, exposed Kubernetes services, CI/CD consoles, weak TLS, and target-owned container images before handing prioritized leads to validation workflows.

Quick Start

Use the cloud-and-infra skill to audit the authorized target’s cloud services, container and Kubernetes exposure, CI/CD platforms, TLS posture, and favicon pivots, then return evidence-backed prioritized findings.

Frequently Asked Questions about cloud-and-infra

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check for exposed Kubernetes and Docker services during cloud reconnaissance?

You can check for exposed Kubernetes and Docker services by performing infrastructure exposure checks for anonymous access, misconfigured container registries, and public etcd endpoints to identify authentication posture weaknesses during reconnaissance.

What is the best way to audit TLS configuration weaknesses on discovered subdomains?

To audit TLS configuration weaknesses, perform deep TLS configuration auditing on discovered subdomains and IPs to identify weak protocols and cipher suites without turning reconnaissance into active exploitation.

Can I fingerprint AWS, Google Cloud, and Azure endpoints to assess public versus authenticated access?

Yes, you can fingerprint AWS, Google Cloud, and Azure endpoints using cloud-native fingerprinting to classify modern application-platform endpoints and assess whether they allow public or authenticated access.

How do I use favicon hashes to pivot toward related infrastructure?

You use favicon hashes to pivot toward related infrastructure by calculating favicon hashes from discovered subdomains and IPs to identify visually similar applications and map connected infrastructure assets.

Does this CI/CD posture assessment approach work for reviewing public container registries?

Yes, CI/CD posture assessment includes reviewing public container registries and CI/CD platforms for dangerous anonymous or misconfigured access to identify target-owned container images and exposed deployment consoles.

What severity and detectability classification is applied to cloud infrastructure findings?

Cloud infrastructure findings receive severity-ranked classification with provider, service type, authentication posture, detectability, and evidence requirements to produce evidence-backed prioritized leads for validation workflows.