Cloud Penetration Testing

Plan and execute authorized cloud security assessments across Azure, AWS, and GCP.

Updated Jan 12, 2026
One-click install
npx skills add https://github.com/jcastillotx/vibe-skeleton-app --skill cloud-penetration-testing-jcastillotx
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: Cloud Penetration Testing
Source: https://github.com/jcastillotx/vibe-skeleton-app/tree/main/setup/skills/cloud-penetration-testing
Command: npx skills add https://github.com/jcastillotx/vibe-skeleton-app --skill cloud-penetration-testing-jcastillotx

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This skill helps security teams plan and execute authorized cloud security assessments across Azure, AWS, and GCP, enabling systematic discovery of misconfigurations, IAM weaknesses, and exposure risks.

Core Features & Use Cases

  • Reconnaissance Across Cloud Platforms: Identify assets, misconfigurations, and exposed resources across Azure, AWS, and GCP.
  • IAM & Authentication Testing: Assess identities, access controls, and credential exposure risks.
  • Resource Enumeration & Data Discovery: Enumerate compute, storage, networking, and service configurations to build an asset inventory.
  • Deliverables & Remediation Guidance: Generate findings with risk ratings and concrete hardening recommendations.

Quick Start

Start a guided, authorized cloud security assessment by specifying the target cloud provider (Azure, AWS, or GCP), the target account or project, and the engagement scope in a single instruction to the Skill.

Frequently Asked Questions about Cloud Penetration Testing

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I conduct a cloud security assessment across AWS, Azure, and GCP?

To conduct cloud penetration testing, you systematically discover misconfigurations, IAM weaknesses, and exposure risks across AWS, Azure, and GCP through reconnaissance, resource enumeration, and authentication testing.

What do I need to start penetration testing on cloud providers like AWS or Azure?

You need to install and configure the Azure CLI, AWS CLI, and gcloud, establish a clearly defined engagement scope, and obtain written authorization before executing authorized cloud security assessments.

How does cloud reconnaissance identify exposed resources and IAM weaknesses?

Cloud reconnaissance identifies exposed resources and IAM weaknesses by enumerating compute, storage, networking, and service configurations across AWS, Azure, and GCP to build a complete asset inventory.

Can I test for privilege escalation and data extraction during cloud security assessments?

Yes, authorized cloud security assessments include testing for privilege escalation, data extraction, and persistence techniques to comprehensively evaluate identities, access controls, and credential exposure risks.

What deliverables should I expect from a cloud penetration testing engagement?

Cloud penetration testing engagements generate deliverables containing detailed findings with risk ratings and concrete hardening recommendations to remediate discovered misconfigurations and IAM weaknesses.

When should I not use automated cloud penetration testing techniques?

You should not use cloud penetration testing techniques without a clearly defined scope and written authorization, as compliant engagements require strict boundaries to prevent unauthorized access.