hunt-cloud-misconfig

Detects cloud misconfigurations including public storage buckets, exposed endpoints, and over-permissioned IAM roles.

13|2|Updated Jun 1, 2026
One-click install
npx skills add https://github.com/pdparchitect/rook --skill hunt-cloud-misconfig-pdparchitect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: hunt-cloud-misconfig
Source: https://github.com/pdparchitect/rook/tree/main/skills/hunt-cloud-misconfig
Command: npx skills add https://github.com/pdparchitect/rook --skill hunt-cloud-misconfig-pdparchitect

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill addresses the critical need for identifying exposed cloud resources and misconfigurations that lead to data breaches, unauthorized access, and privilege escalation.

Core Features & Use Cases

  • Multi-Cloud Auditing: Detects public buckets, exposed services, and leaked credentials across AWS, GCP, Azure, and Kubernetes environments.
  • Attack Surface Mapping: Identifies risky configurations like public S3 buckets, open admin panels, and over-permissioned IAM roles.
  • Use Case: Use this skill to perform a comprehensive security review of your cloud footprint to find and remediate publicly accessible storage or metadata services before they are exploited.

Quick Start

Use the hunt-cloud-misconfig skill to audit the target infrastructure for public buckets and exposed metadata services.

Frequently Asked Questions about hunt-cloud-misconfig

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit my AWS IAM roles for privilege escalation paths and over-permissioned access?

To audit AWS IAM roles for privilege escalation, this skill identifies and validates over-permissioned roles across your cloud infrastructure. It operates across AWS, GCP, Azure, and Kubernetes environments to detect security boundaries and potential privilege escalation paths.

What is the best way to check for public cloud storage buckets and exposed administrative endpoints?

The best way to check for public cloud storage buckets is using automated cloud infrastructure security auditing. This skill identifies and validates misconfigurations including public storage buckets and exposed administrative endpoints across AWS, GCP, Azure, and Kubernetes environments.

Can I perform non-destructive cloud security verification across multiple cloud providers?

Yes, you can perform non-destructive cloud security verification across multiple cloud providers. The skill operates across AWS, GCP, Azure, and Kubernetes environments to perform non-destructive verification of identified misconfigurations and exposed resources.

Do I need network access and cloud CLI tools to map my cloud attack surface?

Yes, mapping your cloud attack surface requires network access to target endpoints and standard cloud CLI tools. The skill uses these to detect public storage, exposed metadata services, and risky configurations like open admin panels and over-permissioned IAM roles.

How does automated cloud misconfiguration detection handle Kubernetes environments?

Automated cloud misconfiguration detection handles Kubernetes environments by identifying exposed services and risky configurations. The skill operates across Kubernetes alongside AWS, GCP, and Azure to detect security boundaries and potential privilege escalation paths.

When should I use automated cloud security auditing instead of manual penetration testing?

You should use automated cloud security auditing when you need to perform a comprehensive security review of your cloud footprint. It automates finding publicly accessible storage and exposed metadata services before they are exploited, complementing manual penetration testing efforts.