cloud-security

Assesses AWS, Azure, and GCP infrastructure for misconfigurations, exposure, and compliance gaps.

13|1|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/0x0pointer/skills --skill cloud-security-0x0pointer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cloud-security
Source: https://github.com/0x0pointer/skills/tree/main/cloud-security
Command: npx skills add https://github.com/0x0pointer/skills --skill cloud-security-0x0pointer

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Organizations need a unified, automated way to evaluate the security posture of their cloud environments across AWS, Azure, and GCP, identifying misconfigurations, exposure, privilege‑escalation paths, and compliance gaps without manually stitching together multiple tools.

Core Features & Use Cases

  • Conducts both authenticated and external assessments, covering IAM, storage, networking, serverless functions, databases, logging, and container registries.
  • Integrates nuclei templates, Prowler, ScoutSuite, and cloud‑provider CLIs to produce architecture diagrams, attack‑path maps, and compliance mappings (SOC 2, PCI DSS 4.0, HIPAA, CIS).
  • Generates actionable findings, PoCs, and can chain into downstream skills such as issue export or threat‑model generation.
  • Ideal for red‑team engagements, compliance audits, and continuous cloud‑security monitoring.

Quick Start

Run the cloud-security skill with the target, provider, and desired depth to generate a comprehensive security report.

Frequently Asked Questions about cloud-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess multi-cloud security posture across AWS, Azure, and GCP?

Cloud security posture assessment identifies misconfigurations, exposure, and compliance gaps across AWS, Azure, and GCP infrastructure. It scans IAM, storage, networking, and serverless components in authenticated or external modes to map privilege-escalation paths and architecture risks.

Can I map cloud security findings to compliance frameworks like SOC 2 and PCI DSS?

Yes, you can map cloud security findings to compliance frameworks like SOC 2, PCI DSS 4.0, HIPAA, and CIS. The assessment generates compliance mappings by evaluating IAM, storage, and networking configurations against these specific regulatory requirements.

What is the best way to automate AWS, Azure, and GCP misconfiguration scanning?

The best way to automate AWS, Azure, and GCP misconfiguration scanning is using a unified tool that executes Prowler, ScoutSuite, nuclei, and provider CLIs. This approach evaluates cloud environments end-to-end to produce architecture diagrams, findings, and attack-path maps.

Does cloud security assessment work for both authenticated and external modes?

Yes, cloud security assessment works for both authenticated and external modes. Authenticated scans evaluate IAM, databases, and container registries internally, while external scans identify exposure and attack surfaces from an outside perspective.

How do I identify privilege-escalation paths in cloud infrastructure?

To identify privilege-escalation paths in cloud infrastructure, perform an authenticated security assessment using tools like Prowler and ScoutSuite. This evaluates IAM roles and policies to detect misconfigurations and map potential attack vectors across providers.

What tools are used for continuous cloud security monitoring and compliance audits?

Continuous cloud security monitoring and compliance audits use tools like nuclei, Prowler, ScoutSuite, and provider CLIs. They evaluate IAM, networking, and serverless configurations to generate actionable findings, PoCs, and compliance mappings for ongoing assessments.