Home / aws-security

AWS Security

AWS security skills for Claude Code: read-only account audit, SCP guardrail builder and linter, landing zone blast-radius design, IAM least-privilege review, Security Hub and GuardDuty triage, least-privilege access for AI agents with a kill switch, incident response runbooks, spend guardrails and a sandbox OU guardrail pack. Scripts are standard-library Python and work offline on specs and saved aws CLI output.

Plugin aws-security, version 0.2.0, 9 skills, MIT licence. Source: aws-security-skills. Synced .

Install

In Claude Code, add the marketplace and install the plugin:

/plugin marketplace add basitalisandhu/claude-skills
/plugin install aws-security@claude-skills

Or copy the skill files into ~/.claude/skills/ from a clone:

git clone https://github.com/basitalisandhu/claude-skills
cd claude-skills
python3 install.py --user --only aws-security

Skills

SkillWhat it doesScripts
agent-safe-aws-accessSet up least-privilege, auditable AWS access for an AI coding agent, or review an existing agent role.yes
aws-account-auditRead-only security audit of one AWS account.yes
aws-incident-response-runbookProduce a step-by-step AWS incident response runbook in Markdown for one of six scenarios (leaked access key, compromised EC2 instance, public S3 bucket exposure, suspicious IAM activity, ransomware against S3 or EBS, crypto-mining), filled in with the account, region and resource identifiers.yes
aws-spend-guardrailsGenerate AWS spend guardrails and check exported cost data against them.yes
iam-least-privilege-reviewReview AWS IAM policy documents offline for over-broad permissions and privilege-escalation paths.yes
landing-zone-blast-radiusDesign an AWS Organizations landing zone with one account per workload and environment, and show the blast radius of each account.yes
sandbox-account-guardrail-packGenerate a complete guardrail pack for an AWS sandbox OU where engineers and AI agents experiment.yes
scp-guardrailsGenerate and lint AWS Organizations service control policies (SCPs).yes
security-hub-triageTriage exported AWS Security Hub (ASFF) and GuardDuty findings offline into an owner-assigned next-actions list.yes

Plugin README

Nine AWS security skills for Claude Code: a read-only account audit, an SCP guardrail builder and linter, a landing zone blast-radius designer, an IAM least-privilege reviewer, a Security Hub and GuardDuty triage tool, least-privilege access for AI agents with a kill switch, incident response runbooks, spend guardrails, and a sandbox OU guardrail pack.

Install

/plugin marketplace add basitalisandhu/aws-security-skills
/plugin install aws-security@aws-security-skills

Skills then appear as /aws-security:<skill>. Scripts need Python 3.11 or newer on PATH as python3; they use the standard library only and make no network calls. The AWS CLI is used only in the collection steps the skills describe, with read-only credentials.

Skills

SkillTriggers onProduces
aws-account-auditaudit, baseline or health-check one AWS accountaudit_account.py findings (17 checks) with severity, evidence and a fix command to review
scp-guardrailswrite, review or debug service control policiesscp_builder.py SCP documents under 5120 characters; scp_lint.py findings
landing-zone-blast-radiusdesign an AWS organization, place a workloadblast_radius.py OU tree, account names, SCP map, blast-radius table
iam-least-privilege-reviewreview or tighten an IAM policy, check escalationiam_review.py ranked findings and a tightened policy template
security-hub-triageSecurity Hub or GuardDuty backlog, weekly reviewtriage_findings.py grouped findings and an owner-assigned action list
agent-safe-aws-accessAWS access for an AI agent, agent role review, kill switchagent_access.py trust, permission, boundary and SCP documents plus commands; role review findings
aws-incident-response-runbookan AWS security incident or a GuardDuty finding that needs a responseir_runbook.py Markdown runbook for one of six scenarios, picked from GuardDuty findings or by name
aws-spend-guardrailsbudget alerts, anomaly detection, sandbox spend limits, cost spikesspend_guardrails.py Budgets and anomaly JSON, spend-deny SCPs, cost review with anomaly flags
sandbox-account-guardrail-packcreate or tighten a sandbox OUsandbox_pack.py SCPs, baseline checklist, auto-expiry design, budget files and a user README