Agent skill

Cloud Audit

by CommonHuman-Lab in CommonHuman-Lab/nyxstrike

Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images

Custom licenceAuto-check passedDevOps & Cloud

Install Cloud Audit

skills CLI
$ npx skills add CommonHuman-Lab/nyxstrike --skill cloud-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install CommonHuman-Lab/nyxstrike cloud-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/CommonHuman-Lab/nyxstrike.git skills-src && mkdir -p .claude/skills && cp -r skills-src/AI/skills/cloud-audit .claude/skills/cloud-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloud-audit
GitHub stars
156
Token cost
~1.1k tokens
SKILL.md length
329 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
Custom licence

At a glance

Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images

  • Tasks that involve Containers
  • SKILL.md covers Workflow, Cloud security priorities by…, Typical engagement flow and Tips, plus 1 more section
  • Calls aws and az
  • Tasks that involve Container orchestration

What it does

Cloud Audit is an agent skill from CommonHuman-Lab/nyxstrike. Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers, Container orchestration and Cloud security. It works with Docker, Kubernetes, Amazon Web Services and Trivy. The repository describes itself as: AI Powered penetration testing Platform for offensive security research.

When your agent uses it

  • Tasks that involve Containers
  • Tasks that involve Container orchestration
  • Tasks that involve Cloud security

Example prompts

  • “/cloud-audit”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 3ac7449. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws
    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws and az, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloud Audit loads about 1.1k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 329 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 329 words (~1,101 tokens).

“Cloud and container security auditing workflow for NyxStrike. Use this skill when a user wants to audit AWS/Azure/GCP configurations, scan container images for CVEs, assess a Kubernetes cluster, or check Docker host security.”

— opening of SKILL.md by CommonHuman-Lab, Custom licence
name
cloud-audit

Read the full SKILL.md on GitHub

Files

Just SKILL.md in AI/skills/cloud-audit of CommonHuman-Lab/nyxstrike.

Open the folder on GitHubat commit 3ac7449

Compare with similar skills

Cloud Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloud Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloud Audit this skillCommonHuman-Lab/nyxstrike156—~1.1kAutomated safety check: PassCustom licence
Agent Bom Scan InfraLeoYeAI/openclaw-master-skills2.2k—~1.5kAutomated safety check: PassApache-2.0
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Logfire Infrastructurepydantic/skills140—~1.8kAutomated safety check: PassMIT
Aspire DeploymentCommunityToolkit/Aspire629—~4.5kAutomated safety check: NotesMIT
Container Securityhardw00t/ai-security-arsenal104—~2.8kAutomated safety check: PassNone

Similar skills

  • Agent Bom Scan Infra

    LeoYeAI/openclaw-master-skills

    Scan infrastructure-as-code, cloud configurations, and find secrets.

    2.2k GitHub stars~1.5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Logfire Infrastructure

    pydantic/skills

    Official

    Monitor hosts, Docker containers, Kubernetes clusters, database/queue/cache servers, and cloud-provider metrics with Pydantic Logfire — no application code required.

    140 GitHub stars~1.8k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Aspire Deployment

    CommunityToolkit/Aspire

    WORKFLOW SKILL — Deploy Aspire apps from AppHost models to Docker Compose, Kubernetes, Azure, AWS, or preview Radius.

    629 GitHub stars~4.5k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Discover Infra

    rand/cc-polymath

    Automatically discover cloud, infrastructure, deployment, and container skills when working with AWS, GCP, Azure, Docker, Kubernetes, Terraform, Netlify, Heroku, serverless, or IaC

    181 GitHub stars~783 tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed

More from CommonHuman-Lab/nyxstrike

  • Nmap Recon

    CommonHuman-Lab/nyxstrike

    Network reconnaissance workflow using nmap, masscan, and rustscan via NyxStrike tools

    156 GitHub stars~639 tokensUpdated today
    Auto-check passed
  • Subdomain Enum

    CommonHuman-Lab/nyxstrike

    Subdomain and DNS enumeration workflow using subfinder, amass, dnsenum, fierce, theharvester, gau, and waybackurls

    156 GitHub stars~858 tokensUpdated today
    Auto-check passed
  • Web Recon

    CommonHuman-Lab/nyxstrike

    Web content discovery and technology fingerprinting using gobuster, ffuf, feroxbuster, katana, httpx, and wafw00f

    156 GitHub stars~907 tokensUpdated today
    Auto-check passed
  • Web Vuln

    CommonHuman-Lab/nyxstrike

    Web vulnerability scanning workflow covering SQLi, XSS, template injection, and generic CVE detection using nuclei, sqlmap, dalfox, nikto, and jaeles

    156 GitHub stars~896 tokensUpdated today
    Auto-check passed

Questions about Cloud Audit

What does Cloud Audit do?

Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images. Cloud Audit is an agent skill from CommonHuman-Lab/nyxstrike.

When should I use Cloud Audit?

Cloud Audit fits situations like: tasks that involve Containers; tasks that involve Container orchestration; tasks that involve Cloud security.

How do I install Cloud Audit in Claude Code?

Run `npx skills add CommonHuman-Lab/nyxstrike --skill cloud-audit -a claude-code`. Or copy the skill folder (AI/skills/cloud-audit in CommonHuman-Lab/nyxstrike) into .claude/skills/cloud-audit in your project. Claude Code loads it when a task matches its description.

How do I install Cloud Audit in Codex?

Run `npx skills add CommonHuman-Lab/nyxstrike --skill cloud-audit -a codex`. Or copy the skill folder (AI/skills/cloud-audit in CommonHuman-Lab/nyxstrike) into .agents/skills/cloud-audit in your project. Codex loads it when a task matches its description.

Can I use Cloud Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add CommonHuman-Lab/nyxstrike --skill cloud-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-audit, .gemini/skills/cloud-audit, .github/skills/cloud-audit and .opencode/skills/cloud-audit in your project.

What does Cloud Audit need to run?

Going by SKILL.md and its folder, Cloud Audit needs the command-line tools its instructions call (aws and az). Our summary lists: Docker.

Does Cloud Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cloud Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloud Audit use?

Cloud Audit has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Cloud Audit use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cloud Audit?

Skills that share tags, products or a category with Cloud Audit: Agent Bom Scan Infra (LeoYeAI/openclaw-master-skills, 2.2k stars), Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Logfire Infrastructure (pydantic/skills, 140 stars) and Aspire Deployment (CommunityToolkit/Aspire, 629 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloud Audit?

CommonHuman-Lab (a GitHub user) maintains it in CommonHuman-Lab/nyxstrike, which has 156 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 7, 2026.

Source: CommonHuman-Lab/nyxstrike on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.