Cloud Attacker — DevOps & Infrastructure agent for Claude Code
Cloud penetration testing specialist for AWS, Azure, and GCP.
How to install Cloud Attacker
Installs to ~/.claude/agents/mukul975-threatswarm-cloud-attacker.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mukul975/Threatswarm/HEAD/.claude/agents/cloud-attacker.md -o ~/.claude/agents/mukul975-threatswarm-cloud-attacker.md Restart Claude Code, or start a new session, for it to be picked up.
What Cloud Attacker does
name: cloud-attacker description: Cloud penetration testing specialist for AWS, Azure, and GCP. Handles IAM enumeration, privilege escalation, S3 bucket abuse, metadata SSRF, Pacu framework, container escape to cloud, and cloud-native attack chains. Triggers on: AWS, Azure, GCP, cloud, IAM, S3, storage bucket, metadata endpoint, Pacu, cloud privesc, service account, managed identity. tools: Bash, Read, Write model: sonnet
Cybersecurity Skills (Invoke First)
Before starting cloud tes
Alternatives in DevOps & Infrastructure
- Deploy Agent — Handles deployment, distribution, and release management for all platforms 38.1k ★
- Kubernetes Architect — You are a Kubernetes architect specializing in cloud-native infrastructure, modern GitOps workflows 31.9k ★
- Cloud Architect — Cloud architect for AWS/Azure/GCP infrastructure, IaC, FinOps, and multi-cloud strategies 2.8k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Cloud Recon
Cloud misconfiguration scanner. Use for S3 bucket enumeration, Azure blob discovery, GCP storage checks, expos
Container Breakout
Delegates to this agent when the user asks about container escape, Docker breakout, Kubernetes pod escape, run
AWS Privilege Escalation
Map the paths from each AWS IAM principal to administrative control, naming the calls that walk each one.
AWS Behavior Anomalies
Find the CloudTrail escalation and enumeration sequences that depart from what the principal running them norm
AWS Architect
AWS solutions architect: Well-Architected reviews, multi-account landing zones with AWS Organizations and Cont
Infra Reviewer
Reviews a diff through the INFRA lens only (deploy/rollback safety, CI/CD config, container/IaC least-privileg
Related Skills
AWS Security Skills
Claude Code skills for AWS security: a plugin with five skills for a read-only account audit, SCP guardrail bu
Talon
Penetration Testing MCP for Claude Code. AI-assisted security testing with automated recon, service enumeratio
Pentest
Run an AI-powered penetration test against a target URL + source code repo. Usage: /pentest [--config ] --ski