aws-cognito-abuse
Exploit misconfigurations in AWS Cognito, specifically focusing on unauthorized identity pool access, user pool self-registration issues, and privilege escalation via custom attributes to access broader AWS infrastructure.
Your agent can do more. Find the skill that makes it happen.
Find your next superpower If you are an agent, refer to our llms.txt for full access."..." for exact phrases · Try typography, debugging or spreadsheetExploit misconfigurations in AWS Cognito, specifically focusing on unauthorized identity pool access, user pool self-registration issues, and privilege escalation via custom attributes to access broader AWS infrastructure.
Covers EC2 instance selection, launch templates, Auto Scaling, Spot capacity, AMI lifecycle, placement, and Systems Manager fleet operations. Diagnoses capacity shortages, CPU credits, metadata access, instance health, SSH connectivity, and fleet registration problems.
Covers Kubernetes and ECS configuration, Fargate services, container registries, lifecycle policies, and Elastic Beanstalk platforms. Supports deployment and optimization, including ECS Action Logs for diagnosing control-plane failures.
Guides choosing, comparing, getting started with, and operating AWS databases by routing to specialized skills. Covers relational, key-value, wide-column, document, graph, time-series, and in-memory or caching workloads.
Covers CodePipeline, CodeBuild, CodeDeploy, CodeConnections, and CodeArtifact. Configures triggers, execution modes, build specifications, caching, cross-account access, source connections, and blue/green, canary, or linear deployments.
Covers IAM policy evaluation, trust policies, STS session limits, Organizations, SAML, and MFA. Provides role management and policy generation from source code or Terraform plans, including safe conditions, bucket restrictions, and confused deputy protection.
Identify and exploit misconfigured Identity and Access Management (IAM) permissions within Amazon Web Services (AWS) to escalate privileges. Use this skill to move from a low-privileged compromised IAM user/role (e.g., via SSRF) to full AdministratorAccess by abusing AssumeRole, PassRole, inline policies, or resource attachments.
Exploit Server-Side Request Forgery (SSRF) vulnerabilities to extract AWS IAM credentials from the Instance Metadata Service version 2 (IMDSv2). This skill details how to bypass the token requirement of IMDSv2 by chaining HTTP verbs (PUT then GET) if the SSRF vulnerability allows full control over the request headers and methods.
Develops resilient, long-running applications using Lambda durable functions and their replay model. Covers step operations, waits, callbacks, child contexts, saga error handling, and testing with LocalDurableTestRunner.
Provides Java AWS Lambda integration patterns, including Micronaut and Raw Java approaches. Covers deployment, API Gateway or ALB integration, and optimization targeting cold starts below one second.
Guides Lambda Managed Instances configuration, capacity providers, concurrency, and migration from standard Lambda. Covers cost comparisons, dedicated execution environments, and duration settings for long-running asynchronous and event-source workloads.
Develops, debugs, and operates Firecracker-isolated compute environments for tenant isolation, code sandboxes, build runners, and sessionful services. Covers container-level access, port-listening servers, session-affine routing, and state preservation across inactivity.
A growing collection of real, public skills. Descriptions and instructions indexed 24 Sept 2026.
Skills give your agent reusable instructions for a specific job. Pick one, read what it does, and bring it into your workflow.
A name only tells half the story. Search the full description and instructions to find the right fit.
Read the skill, visit its source, and see exactly what you’re adding to your agent.
Copy the install command from a skill page and run it in your project.
npx skillycli add owner/repo --skill name