Mike McCabe contributor

Cloudy Marketplace

Run agent-guided AWS cloud penetration tests that orchestrate Pacu, CloudFox, enumerate-iam, and aws-consoler from Claude Code.

Overview

cloudy-marketplace is a plugin marketplace for the Ship phase that adds an agent-led AWS cloud red team plugin wrapping Pacu, CloudFox, enumerate-iam, and aws-consoler for Claude Code.

What is this marketplace?

  • Single marketplace plugin (cloudy v0.1.0) tagged for AWS, red-team, and cloud security
  • Wraps Pacu, CloudFox, enumerate-iam, and aws-consoler into an agent-led workflow
  • Aimed at penetration testing and cloud misconfiguration discovery on AWS estates
  • Category security with keywords penetration-testing and red-team
  • Operator-focused metadata: AWS cloud penetration testing tools for Claude Code
  • Marketplace contains 1 plugin (cloudy v0.1.0)
  • Plugin description names 4 wrapped tools: Pacu, CloudFox, enumerate-iam, aws-consoler

Compatible agents: Claude Code, any compatible agent

What problem does it solve?

Solo builders struggle to run consistent AWS penetration tests because each offensive tool has different install steps and the agent cannot coordinate them without a bundled plugin.

Who is it for?

Authorized AWS account owners doing pre-release cloud pentests or security drills from Claude Code with red-team tooling.

Skip if: Builders without AWS workloads, teams needing only SAST on application code, or anyone testing systems without explicit permission.

What do I get? / Deliverables

After installing the marketplace, Claude Code can drive an integrated cloudy workflow across the wrapped AWS security CLIs instead of you scripting each tool by hand.

  • cloudy plugin registered for agent-led AWS security runs
  • Coordinated access patterns across four wrapped offensive AWS utilities

Plugins in this marketplace

1 plugin — install individually after you add the marketplace.

Recommended Marketplaces

Journey fit

Primary fit

Cloud red-team work belongs in Ship when you harden or assess infrastructure before or after exposing AWS workloads. Security subphase covers offensive and defensive validation—automated cloud pentesting is explicit security assurance, not generic backend coding.

How it compares

Agent-orchestrated AWS offensive CLI bundle, not a general code-review or compliance-only marketplace.

Common Questions / FAQ

Who is cloudy for?

It is for Claude Code users with legitimate AWS access who want agent-assisted cloud penetration testing using Pacu, CloudFox, enumerate-iam, and aws-consoler.

When should I use cloudy?

Use it in Ship security work before go-live or during hardening sprints when you need automated cloud red-team recon and exploitation helpers on AWS.

How do I add cloudy to my agent?

Add the mccabe615/cloudy Claude marketplace so Claude Code loads the cloudy plugin (v0.1.0) from the bundled marketplace manifest.

This week for builders

Five minutes, every Monday — the tools, releases and tactics for shipping solo.

unsubscribe anytime.