Skip to main content

aws-penetration-testing

Provides techniques for penetration testing AWS environments, covering IAM enumeration, privilege escalation, and security audits.

Install this skill

or
73/100

Security score

The aws-penetration-testing skill was audited on May 12, 2026 and we found 13 security issues across 2 threat categories, including 1 high-severity. Review the findings below before installing.

Categories Tested

Security Issues

high line 348

Curl to non-GitHub URL

SourceSKILL.md
348| Get metadata | `curl http://169.254.169.254/latest/meta-data/` |
low line 99

External URL reference

SourceSKILL.md
99http://169.254.169.254/latest/meta-data/
low line 102

External URL reference

SourceSKILL.md
102http://169.254.169.254/latest/meta-data/iam/security-credentials/
low line 105

External URL reference

SourceSKILL.md
105http://169.254.169.254/latest/meta-data/iam/security-credentials/ROLE-NAME
low line 121

External URL reference

SourceSKILL.md
121"http://169.254.169.254/latest/api/token")
low line 125

External URL reference

SourceSKILL.md
125"http://169.254.169.254/latest/meta-data/iam/security-credentials/"
low line 136

External URL reference

SourceSKILL.md
136http://169.254.170.2/v2/credentials/CREDENTIAL-PATH
low line 211

External URL reference

SourceSKILL.md
211https://{bucket-name}.s3.amazonaws.com
low line 212

External URL reference

SourceSKILL.md
212https://s3.amazonaws.com/{bucket-name}
low line 231

External URL reference

SourceSKILL.md
231https://buckets.grayhatwarfare.com/
low line 348

External URL reference

SourceSKILL.md
348| Get metadata | `curl http://169.254.169.254/latest/meta-data/` |
low line 377

External URL reference

SourceSKILL.md
377https://app.com/proxy?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/
low line 381

External URL reference

SourceSKILL.md
381https://app.com/proxy?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/AdminRole
Scanned on May 12, 2026
View Security Dashboard
Installation guide →