skulk

Home  ›  Posture assessment

Phase 2 · pre-release & on change

Is it actually true?
Checked, with evidence.

A fixed-fee, point-in-time assessment: your repository, your cloud, your stores and your declared intent, read together and compared. 63 checks across the RAG and agent stack — AWS, Google Cloud and self-hosted.

Four surfaces. One comparison.

The serious findings live between surfaces — in the code, in the infrastructure, and in facts only your team knows, like which index holds more than one customer’s data. The assessment reads all four and compares them. Where reality disagrees with what you declared, that disagreement is the finding.

What reads itYour repositoryYour cloudYour storesYour declared intent
SAST / SCA✓———
CNAPP / AI-SPM✓✓◑—
Penetration test◑◑◑◑
Runtime guardrail————
Skulk assessment✓✓✓✓

◑ partial — a CNAPP discovers your stores but does not read the query that reaches them; a pen test sees everything it is given, for a week, and records none of it.

The fourth surface is the one nobody else collects. A continuous scanner has no declaration to compare against, because collecting one takes a scoped conversation with your engineers — a delivery-model difference, not an engineering limitation. That is why the design review and the assessment compose.

How the engagement runs

  1. ScopeA short interview establishes what you have and what it is for — or we start from the design review you already have.
  2. Read-only accessA cross-account role, and optionally a catalog reader for your stores. The exact least-privilege policy and the exact SQL are printed for your review before you create anything.
  3. The assessmentDeterministic and read-only. No agent, no daemon, no sidecar, nothing installed, no traffic to your users, no writes anywhere.
  4. The reportFindings grouped by risk with evidence on each, a coverage ledger, and referrals for what a control-plane assessment cannot verify.
  5. Re-assessSame scope, same scanner. The diff shows what actually changed — or says plainly why a comparison is not valid.

You choose how far it goes

  • Repository alone — no credentials, no configuration. Provider keys by git state, model calls and endpoints, services published with no declared auth, agent tool scope, identity posture.
  • Plus your declared intent — cross-tenant retrieval paths, cache and memory tenancy, agent scope against stated intent, retention and provenance.
  • Plus read-only grants — cloud IAM exfiltration paths (assume-role chains on AWS, service-account impersonation on Google Cloud), resource-policy exposure, row-level security verified from the live catalog, store tenancy read from the store itself.

An engagement can stop at any rung. Nothing below the rung you grant is ever presented as assessed — it is named on the coverage ledger instead.

What the report looks like

The report is the deliverable — not a dashboard, not a subscription. Every finding carries a file and line, a traced graph path, or a named configuration field. If it cannot be shown, it is not reported: there is no “potential issue” category.

In every report

  • Findings grouped by risk theme, each with its evidence
  • Framework mappings, validated when the check loads — a check cannot ship carrying a control ID that does not exist
  • A coverage ledger: files not parsed, agents not declared, stores not granted — counted and named
  • Recommendations and referrals for what a static assessment does not verify

Sample report

An anonymized end-to-end sample — a fictional company, real check output — showing the finding format, the evidence lines and the coverage ledger exactly as they appear in a live engagement.

What it does not do — stated here and in every report

Verified — static and control-plane

  • A guardrail is attached; a filter runs before the search
  • A bind is declared non-loopback; identity rules as declared
  • Configuration and schema, cloud and self-hosted

Not verified — referred out

  • Whether the guardrail blocks anything
  • Whether the filter derives the right predicate
  • Whether a declared bind is reachable through your firewall
  • Row data, documents and vector contents — never read at all

Anything unreadable or out of reach lands on the coverage ledger. Nothing unread is ever presented as clean.

Scoping costs nothing. Tell us what you have shipped and where it runs — we will tell you which rungs are worth granting, and what the report would cover.
support@skulksec.com