hunt-cloud-misconfig

Scan AWS, GCP, Azure, and Kubernetes for cloud misconfigurations.

Updated Jun 18, 2026
One-click install
npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill hunt-cloud-misconfig-kisilev13
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hunt-cloud-misconfig
Source: https://github.com/Kisilev13/Hermes-Agent-Workspace/tree/main/skills/hunt-cloud-misconfig
Command: npx skills add https://github.com/Kisilev13/Hermes-Agent-Workspace --skill hunt-cloud-misconfig-kisilev13

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires , and includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides a comprehensive scan for cloud infrastructure misconfigurations, identifying vulnerabilities that can be exploited in various cloud environments.

Core Features & Use Cases

  • Cloud Environment Scanning: Checks for common misconfigurations across AWS, GCP, Azure, and Kubernetes environments.
  • Vulnerability Detection: Identifies vulnerabilities like public S3 buckets, exposed services, and IAM credential leaks.
  • Detection Tools: Utilizes targeted dorking, certificate transparency, and port scanning.
  • Local-verification Toolchain: Offers a local AWS simulator for testing findings before affecting real cloud environments.
  • Validation Checklists: Provides detailed checklists for validating misconfiguration findings before reporting them.
  • Use Case: Ideal for security professionals and bug bounty hunters to assess the security posture of cloud environments.

Quick Start

Use the hunt-cloud-misconfig skill to scan for cloud misconfigurations in your target AWS environment by providing the appropriate bucket names and other relevant details.

Frequently Asked Questions about hunt-cloud-misconfig

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I scan AWS for misconfigurations like public S3 buckets?

You scan for cloud misconfigurations by providing target bucket names and relevant environment details. The skill then applies dorking, certificate transparency, and port scanning techniques to detect exposed services across AWS, GCP, Azure, and Kubernetes.

What techniques are used for detecting exposed services and IAM credential leaks?

Cloud misconfiguration detection applies targeted dorking, certificate transparency, and port scanning techniques to identify vulnerabilities. This approach effectively finds exposed public buckets, exposed services, and IAM credential leaks.

Can I test cloud misconfiguration findings locally before affecting real environments?

Yes, you can validate findings locally using the built-in AWS simulator. This toolchain tests discovered misconfigurations in a local environment before affecting real cloud infrastructure, ensuring safe verification.

Does this cloud security scan support Kubernetes, GCP, and Azure environments?

Yes, the cloud security misconfiguration scan fully supports AWS, GCP, Azure, and Kubernetes environments. It checks for common vulnerabilities like public buckets, exposed services, and IAM credential leaks across these platforms.

How do I validate cloud misconfiguration findings before reporting them?

You validate cloud misconfiguration findings using detailed validation checklists provided by the skill. A local AWS simulator is also available to test findings locally before reporting them, ensuring accurate vulnerability detection.

What is the best way to check cloud infrastructure for public buckets and exposed services?

The best way to check cloud infrastructure for public buckets and exposed services is by applying dorking, certificate transparency, and port scanning techniques. This skill detects these vulnerabilities across AWS, GCP, Azure, and Kubernetes.

Related Skills