Skip to main content
ClaudeWave
Skill282 repo starsupdated yesterday

pentest-cloud-infrastructure

This skill automates security assessments across multi-cloud environments (AWS, Azure, GCP) and Kubernetes clusters by running configuration audits, scanning Infrastructure-as-Code files, analyzing container images, and monitoring runtime behavior. Use it to identify misconfigurations, excessive permissions, and vulnerabilities in cloud infrastructure and containerized deployments before they pose security risks.

Install in Claude Code
Copy
git clone --depth 1 https://github.com/jd-opensource/JoySafeter /tmp/pentest-cloud-infrastructure && cp -r /tmp/pentest-cloud-infrastructure/skills/pentest-cloud-infrastructure ~/.claude/skills/pentest-cloud-infrastructure
Then start a new Claude Code session; the skill loads automatically.

SKILL.md

# Pentest Cloud Infrastructure

## Purpose
Assess the security configuration of cloud environments and containerized infrastructure to detect misconfigurations, excessive permissions, and vulnerabilities.

## Core Workflow
1. **Cloud Config Audit**: Assess cloud provider configuration (AWS/Azure/GCP) using `prowler` and `scoutsuite`.
2. **IaC Scanning**: Analyze Infrastructure-as-Code (Terraform, CloudFormation) for security flaws using `checkov` and `terrascan`.
3. **Container Security**: Scan container images and runtime environments using `trivy`, `clair`, and `dockle`.
4. **Kubernetes Assessment**: Audit K8s clusters for CIS compliance and vulnerabilities using `kube-bench` and `kube-hunter`.
5. **Runtime Monitoring**: Analyze runtime behavior and rule violations using `falco`.

## References
- `references/tools.md`
- `references/workflows.md`