Borrowing it
Nothing to install: this file belongs to zhaji2333/CkSKILLS. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/zhaji2333/CkSKILLS/main/.agents/skills/cloud-infra-supply-chain/SKILL.mdgit clone --depth 1 https://github.com/zhaji2333/CkSKILLSWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/zhaji2333/ckskills/cloud-infra-supply-chain)<a href="https://agentmods.dev/skills/zhaji2333/ckskills/cloud-infra-supply-chain"><img src="https://agentmods.dev/badge/skills/zhaji2333/ckskills/cloud-infra-supply-chain/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/zhaji2333/ckskills/cloud-infra-supply-chain"><img src="https://agentmods.dev/badge/skills/zhaji2333/ckskills/cloud-infra-supply-chain.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00111 | $0.01603 |
| Opus 5 | $0.00056 | $0.00801 |
| Sonnet 5 | $0.00022 | $0.00321 |
| Haiku 4.5 | $0.00011 | $0.00160 |
Grade C, and why
cloud-infra-supply-chain scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Cloud metadata endpointhighServer-side request forgery
One request to 169.254.169.254 can return temporary IAM credentials.
- AWS: http://169.254.169.254/latest/meta-data/ How it starts
The opening of the file, as written. The whole thing — 115 lines — stays where its author put it; the contents beside it link to each section on GitHub.
cloud-infra-supply-chain — 云/基础设施/供应链专项深度挖掘
何时调用(触发条件)
- 云资产:对象存储、云主机、Serverless、云元数据
- 容器/K8s:Docker API、K8s Dashboard、ServiceAccount
- 运维面板/中间件:宝塔、Grafana、Zabbix、ELK、Jenkins、GitLab、Nacos、Redis、Kafka
- CI/CD 流水线、依赖组件清单(SBOM)
- 第三方集成:支付回调、短信、邮件、CDN、地图 API
- 信息泄露:错误栈、调试接口、备份文件、.map、日志
一、运维/管理类场景表(全景)
| 场景 | 漏洞类型 | 挖掘要点 |
|---|---|---|
| 后台登录 | 弱口令/默认口令/爆破 | admin:admin、无验证码、无锁定 |
| 数据库管理(phpMyAdmin等) | 未授权/弱口令/SQL执行 | 默认路径、弱密码 |
| 服务器面板(宝塔/cPanel) | 未授权/RCE | 默认端口、已知CVE |
| 监控系统(Zabbix/Grafana) | 未授权/SSRF/SQL注入 | 默认凭证、API未鉴权 |
| 日志系统(ELK/Splunk) | 未授权/敏感信息 | Kibana未鉴权、日志含密码 |
| CI/CD(Jenkins/GitLab) | 未授权/RCE/凭证泄露 | 匿名构建、密钥泄露、命令执行 |
| 容器管理(Docker/K8s) | 未授权/逃逸/提权 | Docker API暴露、Dashboard弱口令 |
| 配置中心(Nacos/Apollo) | 未授权/配置泄露 | 默认账号、API未鉴权 |
二、第三方集成类场景表(全景)
| 场景 | 漏洞类型 | 挖掘要点 |
|---|---|---|
| 支付回调(支付宝/微信) | 签名绕过/参数篡改 | 签名校验缺失、notify_url可控 |
| 短信网关 | 短信轰炸/内容可控 | 无频率限制、短信模板可控 |
| 邮件服务 | 邮件头注入/钓鱼 | 收件人可控、内容可控 |
| CDN/OSS | 配置错误/越权访问 | Bucket公开、签名URL泄露 |
| 地图/定位API | 信息泄露/Key泄露 | 泄露内部地址、API密钥硬编码 |
| 消息队列(Kafka/RabbitMQ) | 未授权访问/消息伪造 | 管理接口暴露、消息可注入 |
| 缓存服务(Redis/Memcached) | 未授权访问/数据泄露 | 默认端口无密码 |
| 微服务网关 | 路由绕过/鉴权绕过 | 路径标准化差异、Header注入 |
三、云环境专项(14.4)
云元数据:
- AWS: http://169.254.169.254/latest/meta-data/
- 阿里云: http://100.100.100.200/latest/meta-data/
- 腾讯云: http://metadata.tencentyun.com/latest/meta-data/
Kubernetes:
- ServiceAccount Token泄露
- etcd未授权访问
- Dashboard弱口令
Serverless:
- 函数环境变量泄露
- 临时凭证获取
- 事件注入
对象存储:
- Bucket公开可读/写
- 预签名URL泄露
- ACL配置错误
SSRF 打云元数据的完整手法见
ssrf-internal-network技能。
四、信息泄露专项(K类)
- 错误栈、调试接口、版本信息
- 源码泄漏、
.map文件、配置文件 - 日志泄露、备份文件(.bak/.sql/.zip)
- 对象存储权限(公开桶、预签名 URL)
- Git 历史泄露(.git/目录、commit 中的密钥)
五、供应链安全(L类)
| 类型 | 场景 |
|---|---|
| L1. 组件CVE | SBOM/依赖清单、版本比对 |
| L2. 云/容器错误配置 | 公开存储桶、弱IAM、裸奔Dashboard |
| L3. CI/CD密钥泄露 | 流水线日志、环境变量、仓库历史 |
挖掘方法
- 指纹识别 → 版本比对 → 查 CVE(nuclei 模板、公开漏洞库)
- 组件清单:package.json、requirements.txt、pom.xml、composer.lock
- CI/CD:Jenkins 匿名构建、GitLab 公开仓库、流水线日志中的凭证
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 115 lines · 111 tokens per session scan C ed52ad199b2d
cloud-infra-supply-chain is a skill published in the GitHub repository zhaji2333/CkSKILLS (80 stars, last pushed 11d ago), licensed MIT. It adds 111 tokens to every session and 1,603 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it C with 1 finding (cloud metadata endpoint). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
officecli-word-form
Use this skill to create fillable Word forms (.docx) with real Content Controls (SDT) + legacy FormField checkboxes + MERGEFIELD mail-merge placeholders + document protection. Trigger on: 'fillable form', 'form fields', 'content controls', 'SDT', 'word form', 'fill in', 'only editable fields', 'protect document'…
officecli-data-dashboard
Use this skill to build a multi-element Excel dashboard — Dashboard sheet on open, multiple formula-driven KPI cards, multiple charts, sparklines, and conditional formatting — from CSV or tabular input. Trigger on: 'dashboard', 'KPI dashboard', 'analytics dashboard', 'executive dashboard', 'metrics dashboard', 'CSV to…
A set of instructions for working with PDF files, which are documents designed to preserve their layout across devices.
make_plan
For external plan request scenarios, guides the Agent to request a clear, actionable, step-by-step plan from a stronger Agent via listagents and chatwithagent, emphasizing that the plan is executed by the requester, not by the consulted Agent.
gpt-image-2
A skill for generating or editing images with GPT Image 2 across local, host-provided, or advisory setups.
new
Create a new project to start development quickly.