Home / Claude Code skill packs

aws-security-skills

AWS security skills for Claude Code: account audit, SCP guardrails, blast-radius landing zones, IAM least privilege, Security Hub triage.

Python · MIT · latest v0.2.0

What it is

AWS security skills for Claude Code: account audit, SCP guardrails, blast-radius landing zones, IAM least privilege, Security Hub triage, agent-safe access, incident response runbooks, spend guardrails, sandbox guardrails.

aws-security-skills is a Claude Code plugin marketplace with one plugin, aws-security, holding nine skills. Each skill is a fixed procedure plus a tested Python script (standard library only). The skills tell Claude which read-only aws CLI commands to run and where to save the JSON, or which short spec to write; the scripts then evaluate that saved output, or generate policies and runbooks from the spec, offline, so results are repeatable, reviewable by someone without account access, and produced without the script ever touching AWS.

It is written for cloud and platform engineers who look after one or many AWS accounts, especially multi-account organizations governed by service control policies. It exists because the same questions come up on every account (is root protected, is CloudTrail on, can this role escalate, which SCPs go where, what do we fix first in Security Hub, what may an AI agent do here, what do we do in the first hour of an incident, how do we stop a runaway bill), and a scripted procedure answers them the same way each time.

No network access from the scripts, no telemetry. Nothing in this repository changes an AWS account: every skill proposes fix commands and runs one only after you confirm that exact command.

Install

/plugin marketplace add basitalisandhu/aws-security-skills
/plugin install aws-security@aws-security-skills

From the README; see the full README for every option.

Releases

Topics: agent-skills, aws, aws-organizations, aws-security, claude-code, claude-code-plugin, cloud-security, cspm, devsecops, guardduty, hacktoberfest, iam, landing-zone, least-privilege, python, security-hub, security-tools, service-control-policies