cloud

Identifies and exploits cloud attack surfaces in authorized bug bounty programs.

Updated Aug 23, 2026
One-click install
npx skills add https://github.com/AshtonVaughan/bountyhound --skill cloud-ashtonvaughan
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cloud
Source: https://github.com/AshtonVaughan/bountyhound/tree/main/bountyhound/skills/cloud
Command: npx skills add https://github.com/AshtonVaughan/bountyhound --skill cloud-ashtonvaughan

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill enables security professionals to systematically identify and evaluate cloud attack surfaces across major providers within authorized bug bounty scopes, transforming manual reconnaissance into repeatable, auditable methodology.

Core Features & Use Cases

  • Provider-aware attack trees for AWS, GCP, and Azure that guide you through surface discovery, misconfigurations, and credential leakage paths.
  • SSRF and metadata access workflows to assess exposure of instance metadata services and cloud service endpoints.
  • Evidence-driven validation with gates and documentation to ensure findings include HTTP evidence and reproducible steps.

Quick Start

Provide a clearly scoped cloud target and issue the skill to map provider-specific attack trees and surface findings.

Frequently Asked Questions about cloud

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I systematically exploit cloud attack surfaces in AWS, GCP, or Azure?

You can exploit cloud attack surfaces by applying provider-aware attack trees to map discovery, misconfigurations, and IAM credential leakage paths across AWS, GCP, and Azure. The methodology uses validation gates to ensure evidence-based findings.

What is the best way to test for SSRF and IMDS vulnerabilities in cloud environments?

The best way to test for SSRF and IMDS vulnerabilities is using dedicated workflows that assess instance metadata service exposure and cloud endpoint accessibility. This maps credential leakage paths within authorized testing constraints.

Can I use this methodology for targets outside of authorized bug bounty programs?

No, this methodology is strictly for targets within authorized bug bounty programs. It requires a clearly defined scope and safe testing constraints to systematically execute attack trees and validate cloud misconfigurations.

How do I validate and document IAM credential leakage during a cloud pentest?

You validate IAM credential leakage by applying evidence-driven validation gates that capture HTTP evidence and reproducible steps. This ensures all findings regarding exposed buckets, services, or functions are fully auditable.

Does this approach support discovering misconfigurations across serverless functions and storage buckets?

Yes, the approach supports discovering misconfigurations across serverless functions and storage buckets by mapping provider-specific attack trees. It systematically evaluates IAM credential leakage scenarios across these exposed cloud services.