cloud-audit

Audit AWS, GCP, and Azure for misconfigurations and exposed credentials.

18|3|Updated Apr 16, 2026
One-click install
npx skills add https://github.com/kalpmodi/akira --skill cloud-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cloud-audit
Source: https://github.com/kalpmodi/akira/tree/main/skills/cloud-audit
Command: npx skills add https://github.com/kalpmodi/akira --skill cloud-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Cloud misconfigurations are a leading cause of data exposure and privilege escalation in modern cloud environments. This playbook provides a structured approach to identify IAM weaknesses, public storage misconfigurations, and insecure metadata exposure across major providers.

Core Features & Use Cases

  • Automated reconnaissance of provider configurations and exposed resources across AWS, GCP, and Azure.
  • Enumeration of metadata service exposure, IAM roles, and storage permissions.
  • Guided privilege escalation and data discovery steps for offensive security assessments.

Quick Start

Identify cloud misconfigurations and credential exposure by running a complete audit across AWS, GCP, and Azure using the playbook.

Frequently Asked Questions about cloud-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit cloud infrastructure for misconfigurations and exposed credentials?

You can audit cloud infrastructure by running structured playbooks that enumerate IAM roles, validate public storage access, and check metadata service exposure across AWS, GCP, and Azure. The playbook automates reconnaissance of provider configurations and exposed resources.

How do I detect SSRF and IMDS exposure in cloud environments?

To detect SSRF and IMDS exposure, the playbook applies functional checks for insecure metadata service exposure and structured discovery steps. It enumerates metadata service endpoints across AWS, GCP, and Azure to identify vulnerable configurations.

What is the best way to analyze IAM privilege escalation paths in AWS, GCP, and Azure?

Analyzing IAM privilege escalation paths requires enumerating roles and permissions across providers. The playbook guides targeted discovery of IAM weaknesses and RBAC misconfigurations, enabling structured privilege escalation analysis during security assessments.

Can I use this for offensive security assessments and pentesting cloud environments?

Yes, the playbook supports offensive security assessments by providing guided privilege escalation and data discovery steps. It applies targeted discovery techniques to identify misconfigurations and credential exposure during cloud engagements.

Does cloud audit work across AWS, GCP, and Azure simultaneously?

Yes, cloud audit works across AWS, GCP, and Azure simultaneously. It performs automated reconnaissance of provider configurations and exposed resources across all three major cloud providers in a complete audit run.

How do I check for RBAC misconfigurations and public bucket access in Kubernetes?

To check for RBAC misconfigurations and public bucket access, the playbook validates storage permissions and analyzes Kubernetes RBAC rules. It applies structured checks to identify insecure permissions and public access configurations.