Install the "cloud-audit" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/cloud-audit into .claude/skills/cloud-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-audit", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill cloud-audit -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "cloud-audit" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/cloud-audit into .agents/skills/cloud-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-audit", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill cloud-audit -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "cloud-audit" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/cloud-audit into .cursor/skills/cloud-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-audit", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill cloud-audit -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "cloud-audit" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/cloud-audit into .gemini/skills/cloud-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-audit", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill cloud-audit -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "cloud-audit" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/cloud-audit into .github/skills/cloud-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-audit", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill cloud-audit -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "cloud-audit" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/cloud-audit into .opencode/skills/cloud-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-audit", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
cloud-audit
GitHub stars
413
Token cost
~1.3k tokens
SKILL.md length
446 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT
At a glance
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
Works in 3 steps: Cloud provider(s) and account(s) → Regions in use → Whether CLI tools are available (aws,…
The user mentions cloud security
SKILL.md covers Scope the Audit, Audit Categories, Output Format and Boundaries, plus 1 more section
Calls aws, gcloud and az
What it does
Cloud Audit is an agent skill from briiirussell/cybersecurity-skills. Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps. Use when the user mentions 'cloud security,' 'cloud audit,' 'AWS security,' 'GCP security,' 'Azure security,' 'IAM audit,' 'S3 bucket,' 'cloud misconfiguration,' 'cloud hardening,' or needs to review cloud infrastructure security.
Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Cloud security. It works with Google Cloud, Amazon Web Services, Microsoft Azure and Amazon S3. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
1Cloud provider(s) and account(s)
2Regions in use
3Whether CLI tools are available (aws, gcloud, az) or reviewing IaC files (Terraform, CloudFormation, Pulumi)
What it can do on your machine
Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves these tools, so the agent can use them without asking each time:
Bash
Read
Write
Grep
Glob
WebSearch
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
aws
gcloud
az
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md. Its commands use aws, gcloud and az, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Cloud Audit loads about 1.3k tokens when it runs. Until then it costs about 88 tokens; SKILL.md has 446 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~88
When it runs· the whole SKILL.md, loaded when a task matches
~1.3k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check: notes
The automated check noted patterns worth knowing about, such as sudo or a known installer.
NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Audit cloud infrastructure configurations for misconfigurations, excessive permissions, public exposure, and compliance gaps. Covers AWS, GCP, and Azure.
Cross-references: iam-audit for the consultant-style IAM deep-dive (design / audit / migrate across identity providers and federation patterns) — this skill includes an IAM section but stays at the cloud-posture level; for role design, JIT access, workload identity federation, and migration plans, invoke iam-audit. container-audit for Kubernetes-specific posture sitting on top of cloud. secrets-audit for secrets-manager hygiene and rotation.
Findings should use the three-disposition rule (Fixed / Deferred / Accepted Risk) per owasp-audit's Report Format.
Scope the Audit
Identify:
Cloud provider(s) and account(s)
Regions in use
Whether CLI tools are available (aws, gcloud, az) or reviewing IaC files (Terraform, CloudFormation, Pulumi)
Audit Categories
Identity and Access Management
AWS:
bash
aws iam get-account-summary
aws iam list-users
aws iam generate-credential-report && aws iam get-credential-report --output text --query Content | base64 -d
Cloud Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Cloud Audit compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Cloud Audit this skillbriiirussell/cybersecurity-skills
Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…
Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.
Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…
Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps. Cloud Audit is an agent skill from briiirussell/cybersecurity-skills. Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
When should I use Cloud Audit?
Cloud Audit fits situations like: the user mentions cloud security; cloud misconfiguration; cloud hardening; needs to review cloud infrastructure security.
How do I install Cloud Audit in Claude Code?
Run `npx skills add briiirussell/cybersecurity-skills --skill cloud-audit -a claude-code`. Or copy the skill folder (skills/cloud-audit in briiirussell/cybersecurity-skills) into .claude/skills/cloud-audit in your project. Claude Code loads it when a task matches its description.
How do I install Cloud Audit in Codex?
Run `npx skills add briiirussell/cybersecurity-skills --skill cloud-audit -a codex`. Or copy the skill folder (skills/cloud-audit in briiirussell/cybersecurity-skills) into .agents/skills/cloud-audit in your project. Codex loads it when a task matches its description.
Can I use Cloud Audit in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill cloud-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-audit, .gemini/skills/cloud-audit, .github/skills/cloud-audit and .opencode/skills/cloud-audit in your project.
What does Cloud Audit need to run?
Going by SKILL.md and its folder, Cloud Audit needs the command-line tools its instructions call (aws, gcloud and az). Its frontmatter pre-approves these tools: Bash, Read, Write, Grep, Glob, WebSearch.
Does Cloud Audit access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Cloud Audit safe to install?
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
What licence does Cloud Audit use?
Cloud Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Cloud Audit use?
About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Cloud Audit?
Skills that share tags, products or a category with Cloud Audit: Auditing Cloud With Cis Benchmarks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Configuring Firewalls (ancoleman/ai-design-components, 525 stars) and Hardening Cloud Posture (trilwu/secskills, 157 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Cloud Audit?
briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.