What problem does it solve?
Provides a structured, repeatable way to assess cloud security posture across multiple providers, removing manual checklist work and consolidating findings for remediation planning.
Core Features & Use Cases
- Multi-cloud CSPM: Runs ScoutSuite and Prowler to collect CIS and security posture findings for AWS, Azure, and GCP.
- Deep IAM analysis: Enumerates roles, policies, and privilege escalation paths to highlight over-permissive grants.
- Exposure & Network Review: Checks storage/public buckets, NSGs/security groups, NACLs, IMDS settings, and firewall rules; combines automated scans with targeted CLI queries for actionable evidence.
- Reporting & Remediation: Produces a consolidated findings report with attack narratives, CIS violations, and example IaC remediation suggestions.
Quick Start
Run the cloud-pentest skill to perform ScoutSuite and Prowler audits, analyze IAM/storage/network posture, and generate a consolidated findings report for a specified authorized cloud account.