What problem does it solve?
This Skill eliminates the manual, time-consuming process of identifying hard-to-detect cloud and infrastructure misconfigurations across AWS, GCP, and Azure that could lead to sensitive data leaks, unauthorized access, or full cloud account takeover, which are often missed by automated vulnerability scanners.
Core Features & Use Cases
- Multi-cloud misconfig detection: Covers public S3/GCS/Azure Blob storage, permissive bucket policies, exposed serverless functions (Lambda, Cloud Run, Azure Function Apps), public managed services (RDS snapshots), and IAM credentials leaked in client-side JavaScript bundles.
- SSRF-enabled metadata exploitation: Detects and validates access to cloud instance metadata endpoints (such as AWS IMDS) via SSRF vulnerabilities to extract temporary IAM credentials for further enumeration.
- Validated reporting support: Includes local testing integration with LocalStack, a severity rubric for findings, and a pre-report validation checklist to ensure only legitimate, high-impact issues are disclosed.
Use case: A penetration tester assessing a client's cloud environment can use this Skill to quickly identify public S3 buckets containing sensitive user data, extract overpermissioned IAM roles from exposed CloudWatch RUM snippets, and validate the severity of the finding before submitting a bug bounty report.
Quick Start
Use the hunt-cloud-misconfig skill to scan the target domain for public cloud storage buckets, exposed CloudWatch RUM snippets with overpermissioned IAM roles, and accessible cloud metadata endpoints to identify critical cloud misconfiguration risks.