Agent skill

Cloud Bucket Exposure Finder

by forefy in forefy/.context

Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.

MITAuto-check passedSecurity

Install Cloud Bucket Exposure Finder

skills CLI
$ npx skills add forefy/.context --skill cloud-bucket-brute -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install forefy/.context cloud-bucket-brute --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/forefy/.context.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/cloud-bucket-brute .claude/skills/cloud-bucket-brute && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloud-bucket-brute
GitHub stars
152
Token cost
~1.5k tokens
SKILL.md length
459 words
Files
2 (incl. references)
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only.

  • Works in 4 steps: Reduce the domain to its registrable… → If the root contains -, split into name… → For each "common company word" that… → …
  • Checking whether a company you are engaged to test has publicly readable storage buckets
  • SKILL.md covers Contents, Scope & authorization, Name permutation scheme and Probe logic, plus 2 more sections
  • Calls curl and python3; reaches googleapis.com

What it does

The skill takes the target's domains and builds candidate bucket names from them. It reduces each domain to its root label, splits hyphenated names and adds initials, strips common company words such as group, tech or services, and expands every variation through naming templates with a suffix word list. Each candidate is probed against AWS S3, Google Cloud, DigitalOcean, Alibaba, Oracle and Vultr, and any name that resolves to an anonymously reachable object store is reported.

The text says to run it only against organizations you own or are contractually engaged to test. It labels the check aggressive toward third parties: the target's own infrastructure is not touched, but many requests go to the cloud providers, so rate limiting and provider-side logging are expected and the candidate list should stay within scope. Endpoint templates, failure indications, region lists and the suffix list sit in references/cloud-storage-endpoints.md. The excerpt is cut off before the probe logic.

When your agent uses it

  • Checking whether a company you are engaged to test has publicly readable storage buckets
  • Generating likely bucket names from a set of in-scope domains
  • Checking your own organization for storage left open to anonymous readers

Example prompts

  • “Check whether example-corp.com has any publicly readable buckets; we have a signed testing engagement.”
  • “Generate the bucket name permutations for acme-labs.io and probe S3 and Google Cloud only.”
  • “List which candidate names for our own domain resolve to anonymously reachable storage.”

Requirements

  • Authorization to test the target organization
  • Network access to the cloud providers' storage endpoints

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Reduce the domain to its registrable root label (tldextract(...).domain, e.g. foo-bar.co.uk -> foo-bar) and seed the variation set with…
  2. If the root contains -, split into name + second_name, and also add the initials name[0]+second_name[0].
  3. For each "common company word" that appears inside the root (company, group, tech, solutions, international, services, world, global, ai…
  4. Expand every variation through the permutation templates against the suffix wordlist. Bare {name} is always tried; multi-word templates…

What it can do on your machine

Read from SKILL.md and the folder at commit c8ff161. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • googleapis.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloud Bucket Exposure Finder loads about 1.5k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 54 tokens; SKILL.md has 459 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from forefy/.context at commit c8ff161, republished under its MIT licence (© forefy). 459 words, ~1,504 tokens.

Download SKILL.mdSave it as .claude/skills/cloud-bucket-brute/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
cloud-bucket-brute
description
Discover publicly readable cloud storage by permuting a company name into likely bucket names and probing AWS S3, Google Cloud, DigitalOcean, Alibaba, Oracle, and Vultr. Use to find exposed buckets.

Contents

  • Scope & authorization
  • Name permutation scheme
  • Probe logic
  • Runnable snippets
  • Output
  • Reference file: references/cloud-storage-endpoints.md

Scope & authorization

Run only against organizations you own or are contractually engaged to test. This is an aggressive-3rdparty check: it does not touch the target's own infrastructure, but it fires a high volume of requests at third-party cloud providers (AWS/GCP/DigitalOcean/Alibaba/Oracle/Vultr) about the target. Expect provider-side rate-limiting and logging. Keep the candidate list scoped to the org actually in scope.

Input is the set of the target's domains. Output is any bucket name that resolves to an anonymously reachable object store.

Name permutation scheme

Turn each in-scope domain into candidate bucket names (this is the valuable part - carry it exactly):

  1. Reduce the domain to its registrable root label (tldextract(...).domain, e.g. foo-bar.co.uk -> foo-bar) and seed the variation set with the raw name.
  2. If the root contains -, split into name + second_name, and also add the initials name[0]+second_name[0].
  3. For each "common company word" that appears inside the root (company, group, tech, solutions, international, services, world, global, ai, io, team, inc, ask, digital, data, bits, bit, open, edu, educaiton, learning, auto, stack), add the name with that word stripped out, plus the initials of the two parts around it. (So bugcrowd yields bugcrowd, bug/crowd fragments, bc, etc.)
  4. Expand every variation through the permutation templates against the suffix wordlist. Bare {name} is always tried; multi-word templates ({name}_{word}, {word}-{name}, {word}_{name}, {name}{word}, {name}{second_name}, {name}{second_name}-{word}, {name}{second_name}_{word}, {name}-{second_name}-{word}, {name}_{second_name}_{word}, {name}{second_name}{word}) are only applied to non-domain-looking single/two-part variations.

The full provider endpoint templates, per-provider fail indications, region lists, the 40-word suffix list, and the permutation templates are in references/cloud-storage-endpoints.md.

Show full SKILL.md (193 more words)Show less

Probe logic

For each candidate: GET the endpoint (5s timeout). Parse the body as XML/JSON/text by Content-Type. By default pick one random region per region-templated endpoint (set an "iterate all regions" flag only for a deep, much slower pass). Discard any response containing that provider's fail indications (e.g. AWS AccessDenied, NoSuchBucket, IllegalLocationConstraintException, AllAccessDisabled, PermanentRedirect; GCP The specified bucket does not exist / Anonymous caller does not have storage.buckets.get; Oracle AnonymousUserSubject; Vultr/DO NoSuchBucket), and discard any body containing Burp Suite Professional (interception artifact).

Report a finding when: an endpoint returns a body with none of its fail indications - the bucket exists and is anonymously reachable. Severity: Information Disclosure (verify listability/read of objects before rating impact).

Runnable snippets

bash
# single candidate, AWS virtual-host + GCP JSON API
NAME=acme-backups
curl -s "https://$NAME.s3.amazonaws.com" | grep -qiE 'AccessDenied|NoSuchBucket|IllegalLocationConstraint|AllAccessDisabled' \
  && echo "aws: not public" || echo "aws: PUBLIC/exists -> https://$NAME.s3.amazonaws.com"
curl -s "https://www.googleapis.com/storage/v1/b/$NAME" | grep -qiE 'does not exist|does not have storage.buckets.get' \
  && echo "gcp: not public" || echo "gcp: PUBLIC/exists"
bash
# generate candidate names (permutation scheme) for a domain
python3 - <<'PY'
import tldextract
words=["archive","artifacts","assets","backup","bin","bucket","data","dev","dev-data","dev_data","devops","files","git","it","logs","media","mediauploads","onboarding","ops","proj","project","prod","prod-data","prod_data","prod-files","prod_files","reports","scripts","stage","staging","static","storage","temp","terraform","tf","tf-files","tf_files","terraformbinaries","test","tmp","user-files","user_files","uploads"]
common={"company","group","tech","solutions","international","services","world","global","ai","io","team","inc","ask","digital","data","bits","bit","open","edu","educaiton","learning","auto","stack"}
name=tldextract.extract("acme-corp.com").domain
variations=[(name,)]
if "-" in name:
    a,b=name.split("-",1); variations+=[(a,b),(a[0]+b[0],)]
for w in common:
    if w in name:
        variations+=[(name.replace(w,""),)]
tmpl_base=["{name}"]
tmpl_multi=["{name}_{word}","{word}-{name}","{word}_{name}","{name}{word}","{name}{second_name}","{name}{second_name}-{word}","{name}{second_name}_{word}","{name}-{second_name}-{word}","{name}_{second_name}_{word}","{name}{second_name}{word}"]
out=[]
for v in variations:
    tmpls=tmpl_base+(tmpl_multi if len(v)<=2 else [])
    for w in words:
        for t in tmpls:
            if "{second_name}" in t and len(v)!=2: continue
            s=t.replace("{name}",v[0]).replace("{word}",w)
            if len(v)==2: s=s.replace("{second_name}",v[1])
            if s not in out: out.append(s)
print("\n".join(out))
PY

Output

Finish with a candidate / provider / reachable? ledger (or just the confirmed hits when the candidate list is large), then a verdict:

  • Clean - candidates generated and probed across all six providers, nothing anonymously reachable.
  • Exposed - list each public bucket URL, its provider, and whether objects are listable/readable. Fix: make buckets private, require authentication, and audit bucket-policy/ACL for anonymous grants.

Report whether the sweep was rate-limited or partial (e.g. one-region-only), so an incomplete run is not reported as clean.

© forefy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/cloud/cloud-bucket-brute of forefy/.context.

  • SKILL.md
  • references/cloud-storage-endpoints.md

Open the folder on GitHubat commit c8ff161

Compare with similar skills

Cloud Bucket Exposure Finder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloud Bucket Exposure Finder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloud Bucket Exposure Finder this skillforefy/.context152—~1.5kAutomated safety check: PassMIT
Cloud Auditbriiirussell/cybersecurity-skills413—~1.3kAutomated safety check: NotesMIT
Cloud AuditCommonHuman-Lab/nyxstrike157—~1.1kAutomated safety check: PassCustom licence
Google Cloud PAM Helpergoogle/skills21k—~3.2kAutomated safety check: PassApache-2.0
Security ReviewerAratKruglik/claude-laravel1551 repos~1.1kAutomated safety check: NotesNone
Performing Cloud Incident Containment Proceduresmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0

Similar skills

  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Cloud Audit

    CommonHuman-Lab/nyxstrike

    Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images

    157 GitHub stars~1.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated today
    SecurityAuto-check passed
  • Security Reviewer

    AratKruglik/claude-laravel

    A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.

    155 GitHub starsUsed in 1 repo~1.1k tokens
    SecurityAuto-check: notes
  • Performing Cloud Incident Containment Procedures

    mukul975/Anthropic-Cybersecurity-Skills

    Execute cloud-native incident containment across AWS, Azure, and GCP using platform CLIs to revoke or disable compromised IAM credentials, isolate resources with security groups and network ACLs…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Auditing Cloud With Cis Benchmarks

    mukul975/Anthropic-Cybersecurity-Skills

    Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from forefy/.context

All 20 skills in this repo
  • Builds and formats security audit reports in Google Docs through the Docs API, with fixes for index drift, code styling and cross-reference links.

    152 GitHub stars~951 tokensUpdated 3 days ago
    Auto-check passed
  • Audits the Safe multisig wallets of DeFi protocols for governance misconfigurations, scoring each against a finding library and producing a severity-ranked report.

    152 GitHub stars~1.4k tokensUpdated 3 days ago
    Auto-check passed
  • Audit Scope

    forefy/.context

    Draft a security-audit scope from GitHub repos or API access, with a protocol narrative and a sizing table.

    152 GitHub stars~2.3k tokensUpdated 3 days ago
    Auto-check passed
  • External Enumeration

    forefy/.context

    Passively map a company's domains, subdomains, DNS ownership, tech stack, and CDNs.

    152 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed
  • Smart Contract Audit

    forefy/.context

    Comprehensive smart contract security audit framework with multi-expert analysis.

    152 GitHub starsUsed in 1 repo~5.1k tokens
    Auto-check passed
  • Infrastructure Audit

    forefy/.context

    Comprehensive infrastructure security audit framework for IaC, Docker, Kubernetes, and cloud configurations.

    152 GitHub stars~3.7k tokensUpdated 3 days ago
    Auto-check: notes

Categories

Questions about Cloud Bucket Exposure Finder

What does Cloud Bucket Exposure Finder do?

Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only. The skill takes the target's domains and builds candidate bucket names from them. It reduces each domain to its root label, splits hyphenated names and adds initials, strips common company words such as group, tech or services, and expands every variation through naming templates with a suffix word list.

When should I use Cloud Bucket Exposure Finder?

Cloud Bucket Exposure Finder fits situations like: checking whether a company you are engaged to test has publicly readable storage buckets; generating likely bucket names from a set of in-scope domains; checking your own organization for storage left open to anonymous readers.

How do I install Cloud Bucket Exposure Finder in Claude Code?

Run `npx skills add forefy/.context --skill cloud-bucket-brute -a claude-code`. Or copy the skill folder (skills/cloud/cloud-bucket-brute in forefy/.context) into .claude/skills/cloud-bucket-brute in your project. Claude Code loads it when a task matches its description.

How do I install Cloud Bucket Exposure Finder in Codex?

Run `npx skills add forefy/.context --skill cloud-bucket-brute -a codex`. Or copy the skill folder (skills/cloud/cloud-bucket-brute in forefy/.context) into .agents/skills/cloud-bucket-brute in your project. Codex loads it when a task matches its description.

Can I use Cloud Bucket Exposure Finder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add forefy/.context --skill cloud-bucket-brute -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-bucket-brute, .gemini/skills/cloud-bucket-brute, .github/skills/cloud-bucket-brute and .opencode/skills/cloud-bucket-brute in your project.

What does Cloud Bucket Exposure Finder need to run?

Going by SKILL.md and its folder, Cloud Bucket Exposure Finder needs the command-line tools its instructions call (curl and python3). Our summary lists: Authorization to test the target organization; Network access to the cloud providers' storage endpoints.

Does Cloud Bucket Exposure Finder access the network?

SKILL.md names 1 domain. In commands or code: googleapis.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Cloud Bucket Exposure Finder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloud Bucket Exposure Finder use?

Cloud Bucket Exposure Finder is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloud Bucket Exposure Finder use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.

What are the alternatives to Cloud Bucket Exposure Finder?

Skills that share tags, products or a category with Cloud Bucket Exposure Finder: Cloud Audit (briiirussell/cybersecurity-skills, 413 stars), Cloud Audit (CommonHuman-Lab/nyxstrike, 157 stars), Google Cloud PAM Helper (google/skills, 21k stars) and Security Reviewer (AratKruglik/claude-laravel, 155 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloud Bucket Exposure Finder?

forefy (a GitHub user) maintains it in forefy/.context, which has 152 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 4, 2026.

Source: forefy/.context on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.