Cloud Audit
briiirussell/cybersecurity-skills
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.
$ npx skills add forefy/.context --skill cloud-bucket-brute -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install forefy/.context cloud-bucket-brute --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/cloud-bucket-brute .claude/skills/cloud-bucket-brute && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cloud-bucket-brute" agent skill from https://github.com/forefy/.context/tree/main/skills/cloud/cloud-bucket-brute into .claude/skills/cloud-bucket-brute/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-bucket-brute", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/forefy/.context/tree/main/skills/cloud/cloud-bucket-bruteType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add forefy/.context --skill cloud-bucket-brute -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install forefy/.context cloud-bucket-brute --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cloud/cloud-bucket-brute .agents/skills/cloud-bucket-brute && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cloud-bucket-brute" agent skill from https://github.com/forefy/.context/tree/main/skills/cloud/cloud-bucket-brute into .agents/skills/cloud-bucket-brute/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-bucket-brute", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forefy/.context --skill cloud-bucket-brute -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install forefy/.context cloud-bucket-brute --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cloud/cloud-bucket-brute .cursor/skills/cloud-bucket-brute && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cloud-bucket-brute" agent skill from https://github.com/forefy/.context/tree/main/skills/cloud/cloud-bucket-brute into .cursor/skills/cloud-bucket-brute/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-bucket-brute", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/forefy/.context.git --path skills/cloud/cloud-bucket-brute--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add forefy/.context --skill cloud-bucket-brute -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install forefy/.context cloud-bucket-brute --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cloud/cloud-bucket-brute .gemini/skills/cloud-bucket-brute && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cloud-bucket-brute" agent skill from https://github.com/forefy/.context/tree/main/skills/cloud/cloud-bucket-brute into .gemini/skills/cloud-bucket-brute/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-bucket-brute", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install forefy/.context cloud-bucket-bruteInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add forefy/.context --skill cloud-bucket-brute -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cloud/cloud-bucket-brute .github/skills/cloud-bucket-brute && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cloud-bucket-brute" agent skill from https://github.com/forefy/.context/tree/main/skills/cloud/cloud-bucket-brute into .github/skills/cloud-bucket-brute/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-bucket-brute", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add forefy/.context --skill cloud-bucket-brute -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install forefy/.context cloud-bucket-brute --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cloud/cloud-bucket-brute .opencode/skills/cloud-bucket-brute && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cloud-bucket-brute" agent skill from https://github.com/forefy/.context/tree/main/skills/cloud/cloud-bucket-brute into .opencode/skills/cloud-bucket-brute/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloud-bucket-brute", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cloud-bucket-bruteTurns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.
The skill takes the target's domains and builds candidate bucket names from them. It reduces each domain to its root label, splits hyphenated names and adds initials, strips common company words such as group, tech or services, and expands every variation through naming templates with a suffix word list. Each candidate is probed against AWS S3, Google Cloud, DigitalOcean, Alibaba, Oracle and Vultr, and any name that resolves to an anonymously reachable object store is reported.
The text says to run it only against organizations you own or are contractually engaged to test. It labels the check aggressive toward third parties: the target's own infrastructure is not touched, but many requests go to the cloud providers, so rate limiting and provider-side logging are expected and the candidate list should stay within scope. Endpoint templates, failure indications, region lists and the suffix list sit in references/cloud-storage-endpoints.md. The excerpt is cut off before the probe logic.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit c8ff161. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlpython3From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
googleapis.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Cloud Bucket Exposure Finder loads about 1.5k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 54 tokens; SKILL.md has 459 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from forefy/.context at commit c8ff161, republished under its MIT licence (© forefy). 459 words, ~1,504 tokens.
.claude/skills/cloud-bucket-brute/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.references/cloud-storage-endpoints.mdRun only against organizations you own or are contractually engaged to test. This is an aggressive-3rdparty check: it does not touch the target's own infrastructure, but it fires a high volume of requests at third-party cloud providers (AWS/GCP/DigitalOcean/Alibaba/Oracle/Vultr) about the target. Expect provider-side rate-limiting and logging. Keep the candidate list scoped to the org actually in scope.
Input is the set of the target's domains. Output is any bucket name that resolves to an anonymously reachable object store.
Turn each in-scope domain into candidate bucket names (this is the valuable part - carry it exactly):
tldextract(...).domain, e.g. foo-bar.co.uk -> foo-bar) and seed the variation set with the raw name.-, split into name + second_name, and also add the initials name[0]+second_name[0].company, group, tech, solutions, international, services, world, global, ai, io, team, inc, ask, digital, data, bits, bit, open, edu, educaiton, learning, auto, stack), add the name with that word stripped out, plus the initials of the two parts around it. (So bugcrowd yields bugcrowd, bug/crowd fragments, bc, etc.){name} is always tried; multi-word templates ({name}_{word}, {word}-{name}, {word}_{name}, {name}{word}, {name}{second_name}, {name}{second_name}-{word}, {name}{second_name}_{word}, {name}-{second_name}-{word}, {name}_{second_name}_{word}, {name}{second_name}{word}) are only applied to non-domain-looking single/two-part variations.The full provider endpoint templates, per-provider fail indications, region lists, the 40-word suffix list, and the permutation templates are in references/cloud-storage-endpoints.md.
For each candidate: GET the endpoint (5s timeout). Parse the body as XML/JSON/text by Content-Type. By default pick one random region per region-templated endpoint (set an "iterate all regions" flag only for a deep, much slower pass). Discard any response containing that provider's fail indications (e.g. AWS AccessDenied, NoSuchBucket, IllegalLocationConstraintException, AllAccessDisabled, PermanentRedirect; GCP The specified bucket does not exist / Anonymous caller does not have storage.buckets.get; Oracle AnonymousUserSubject; Vultr/DO NoSuchBucket), and discard any body containing Burp Suite Professional (interception artifact).
Report a finding when: an endpoint returns a body with none of its fail indications - the bucket exists and is anonymously reachable. Severity: Information Disclosure (verify listability/read of objects before rating impact).
# single candidate, AWS virtual-host + GCP JSON API
NAME=acme-backups
curl -s "https://$NAME.s3.amazonaws.com" | grep -qiE 'AccessDenied|NoSuchBucket|IllegalLocationConstraint|AllAccessDisabled' \
&& echo "aws: not public" || echo "aws: PUBLIC/exists -> https://$NAME.s3.amazonaws.com"
curl -s "https://www.googleapis.com/storage/v1/b/$NAME" | grep -qiE 'does not exist|does not have storage.buckets.get' \
&& echo "gcp: not public" || echo "gcp: PUBLIC/exists"# generate candidate names (permutation scheme) for a domain
python3 - <<'PY'
import tldextract
words=["archive","artifacts","assets","backup","bin","bucket","data","dev","dev-data","dev_data","devops","files","git","it","logs","media","mediauploads","onboarding","ops","proj","project","prod","prod-data","prod_data","prod-files","prod_files","reports","scripts","stage","staging","static","storage","temp","terraform","tf","tf-files","tf_files","terraformbinaries","test","tmp","user-files","user_files","uploads"]
common={"company","group","tech","solutions","international","services","world","global","ai","io","team","inc","ask","digital","data","bits","bit","open","edu","educaiton","learning","auto","stack"}
name=tldextract.extract("acme-corp.com").domain
variations=[(name,)]
if "-" in name:
a,b=name.split("-",1); variations+=[(a,b),(a[0]+b[0],)]
for w in common:
if w in name:
variations+=[(name.replace(w,""),)]
tmpl_base=["{name}"]
tmpl_multi=["{name}_{word}","{word}-{name}","{word}_{name}","{name}{word}","{name}{second_name}","{name}{second_name}-{word}","{name}{second_name}_{word}","{name}-{second_name}-{word}","{name}_{second_name}_{word}","{name}{second_name}{word}"]
out=[]
for v in variations:
tmpls=tmpl_base+(tmpl_multi if len(v)<=2 else [])
for w in words:
for t in tmpls:
if "{second_name}" in t and len(v)!=2: continue
s=t.replace("{name}",v[0]).replace("{word}",w)
if len(v)==2: s=s.replace("{second_name}",v[1])
if s not in out: out.append(s)
print("\n".join(out))
PYFinish with a candidate / provider / reachable? ledger (or just the confirmed hits when the candidate list is large), then a verdict:
Report whether the sweep was rate-limited or partial (e.g. one-region-only), so an incomplete run is not reported as clean.
© forefy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/cloud/cloud-bucket-brute of forefy/.context.
Open the folder on GitHubat commit c8ff161
Cloud Bucket Exposure Finder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cloud Bucket Exposure Finder this skillforefy/.context | 152 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Cloud Auditbriiirussell/cybersecurity-skills | 413 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Cloud AuditCommonHuman-Lab/nyxstrike | 157 | — | ~1.1k | Automated safety check: Pass | Custom licence | |
| Google Cloud PAM Helpergoogle/skills | 21k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| Security ReviewerAratKruglik/claude-laravel | 155 | 1 repos | ~1.1k | Automated safety check: Notes | None | |
| Performing Cloud Incident Containment Proceduresmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 |
briiirussell/cybersecurity-skills
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
CommonHuman-Lab/nyxstrike
Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images
google/skills
Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.
AratKruglik/claude-laravel
A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.
mukul975/Anthropic-Cybersecurity-Skills
Execute cloud-native incident containment across AWS, Azure, and GCP using platform CLIs to revoke or disable compromised IAM credentials, isolate resources with security groups and network ACLs…
mukul975/Anthropic-Cybersecurity-Skills
Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…
forefy/.context
Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links.
forefy/.context
Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report.
forefy/.context
Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.
forefy/.context
Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.
forefy/.context
Comprehensive smart contract security audit framework with multi-expert analysis.
forefy/.context
Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations.
Works with
Categories
Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only. The skill takes the target's domains and builds candidate bucket names from them. It reduces each domain to its root label, splits hyphenated names and adds initials, strips common company words such as group, tech or services, and expands every variation through naming templates with a suffix word list.
Cloud Bucket Exposure Finder fits situations like: checking whether a company you are engaged to test has publicly readable storage buckets; generating likely bucket names from a set of in-scope domains; checking your own organization for storage left open to anonymous readers.
Run `npx skills add forefy/.context --skill cloud-bucket-brute -a claude-code`. Or copy the skill folder (skills/cloud/cloud-bucket-brute in forefy/.context) into .claude/skills/cloud-bucket-brute in your project. Claude Code loads it when a task matches its description.
Run `npx skills add forefy/.context --skill cloud-bucket-brute -a codex`. Or copy the skill folder (skills/cloud/cloud-bucket-brute in forefy/.context) into .agents/skills/cloud-bucket-brute in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forefy/.context --skill cloud-bucket-brute -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-bucket-brute, .gemini/skills/cloud-bucket-brute, .github/skills/cloud-bucket-brute and .opencode/skills/cloud-bucket-brute in your project.
Going by SKILL.md and its folder, Cloud Bucket Exposure Finder needs the command-line tools its instructions call (curl and python3). Our summary lists: Authorization to test the target organization; Network access to the cloud providers' storage endpoints.
SKILL.md names 1 domain. In commands or code: googleapis.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Cloud Bucket Exposure Finder is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Cloud Bucket Exposure Finder: Cloud Audit (briiirussell/cybersecurity-skills, 413 stars), Cloud Audit (CommonHuman-Lab/nyxstrike, 157 stars), Google Cloud PAM Helper (google/skills, 21k stars) and Security Reviewer (AratKruglik/claude-laravel, 155 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
forefy (a GitHub user) maintains it in forefy/.context, which has 152 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 4, 2026.
Source: forefy/.context on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.