What problem does it solve?
This Skill helps authorized security teams determine the scope and impact of validated credentials without immediately modifying systems, creating resources, or sending messages.
Core Features & Use Cases
- Provider-Specific Enumeration: Assess AWS IAM, GitHub PAT, Slack, Postman, Anthropic, OpenAI, and other credential scopes through read-only workflows.
- JWT Triage: Decode claims, identify privilege indicators, and assess algorithm-related risks under explicit authorization.
- Evidence-Backed Reporting: Record account identity, permissions, accessible resources, detectability, and timestamps for downstream severity analysis.
- Safety Gates: Require validator confirmation and explicit Rules of Engagement authorization before authenticated enumeration begins.
- Use Case: After a validator confirms a GitHub token is live, use this Skill to document its scopes, accessible repositories, organization memberships, and workflow-secret metadata without retrieving secret values.
Quick Start
Ask the post-discovery skill to enumerate the authorized scope of a validator-confirmed credential and produce an evidence-backed report.