What problem does it solve? Cloud security assessments often stall because testers lack a disciplined, evidence-gated method for verifying object storage, serverless, and IAM misconfigurations without crossing authorization boundaries or triggering false positives. ## Core Features & Use Cases - Signal-Driven Routing: Triggers on concrete indicators such as bucket references, serverless endpoints, CloudFront markers, metadata proxies, and IAM config leaks. - Safe Validation Protocol: Uses canary objects, anonymous versus authorized read/write comparisons, CORS checks, and presigned URL binding tests instead of account enumeration. - Strict Oracle and Stop Rules: Distinguishes real authorization boundary failures from expected public assets, 403 responses, and expired signed URLs, and halts on IAM/ACL modification or cross-tenant access. - Use Case: During an authorized engagement, you discover a bucket reference in application JavaScript; this Skill guides you to confirm ownership, test a self-owned canary object across identity states, and record reproducible evidence. ## Quick Start Ask the agent to validate whether the in-scope cloud bucket and serverless endpoints from this engagement expose unauthorized access, using canary objects and evidence-gated probes.