Home / aws-security
AWS Security
AWS security skills for Claude Code: read-only account audit, SCP guardrail builder and linter, landing zone blast-radius design, IAM least-privilege review, Security Hub and GuardDuty triage, least-privilege access for AI agents with a kill switch, incident response runbooks, spend guardrails and a sandbox OU guardrail pack. Scripts are standard-library Python and work offline on specs and saved aws CLI output.
Install
In Claude Code, add the marketplace and install the plugin:
/plugin marketplace add basitalisandhu/claude-skills
/plugin install aws-security@claude-skills
Or copy the skill files into ~/.claude/skills/ from a clone:
git clone https://github.com/basitalisandhu/claude-skills
cd claude-skills
python3 install.py --user --only aws-security
Skills
| Skill | What it does | Scripts |
|---|---|---|
| agent-safe-aws-access | Set up least-privilege, auditable AWS access for an AI coding agent, or review an existing agent role. | yes |
| aws-account-audit | Read-only security audit of one AWS account. | yes |
| aws-incident-response-runbook | Produce a step-by-step AWS incident response runbook in Markdown for one of six scenarios (leaked access key, compromised EC2 instance, public S3 bucket exposure, suspicious IAM activity, ransomware against S3 or EBS, crypto-mining), filled in with the account, region and resource identifiers. | yes |
| aws-spend-guardrails | Generate AWS spend guardrails and check exported cost data against them. | yes |
| iam-least-privilege-review | Review AWS IAM policy documents offline for over-broad permissions and privilege-escalation paths. | yes |
| landing-zone-blast-radius | Design an AWS Organizations landing zone with one account per workload and environment, and show the blast radius of each account. | yes |
| sandbox-account-guardrail-pack | Generate a complete guardrail pack for an AWS sandbox OU where engineers and AI agents experiment. | yes |
| scp-guardrails | Generate and lint AWS Organizations service control policies (SCPs). | yes |
| security-hub-triage | Triage exported AWS Security Hub (ASFF) and GuardDuty findings offline into an owner-assigned next-actions list. | yes |
Plugin README
Nine AWS security skills for Claude Code: a read-only account audit, an SCP guardrail builder and linter, a landing zone blast-radius designer, an IAM least-privilege reviewer, a Security Hub and GuardDuty triage tool, least-privilege access for AI agents with a kill switch, incident response runbooks, spend guardrails, and a sandbox OU guardrail pack.
Install
/plugin marketplace add basitalisandhu/aws-security-skills
/plugin install aws-security@aws-security-skills
Skills then appear as /aws-security:<skill>. Scripts need Python 3.11 or newer on PATH as python3; they use the standard library only and make no network calls. The AWS CLI is used only in the collection steps the skills describe, with read-only credentials.
Skills
| Skill | Triggers on | Produces |
|---|---|---|
aws-account-audit | audit, baseline or health-check one AWS account | audit_account.py findings (17 checks) with severity, evidence and a fix command to review |
scp-guardrails | write, review or debug service control policies | scp_builder.py SCP documents under 5120 characters; scp_lint.py findings |
landing-zone-blast-radius | design an AWS organization, place a workload | blast_radius.py OU tree, account names, SCP map, blast-radius table |
iam-least-privilege-review | review or tighten an IAM policy, check escalation | iam_review.py ranked findings and a tightened policy template |
security-hub-triage | Security Hub or GuardDuty backlog, weekly review | triage_findings.py grouped findings and an owner-assigned action list |
agent-safe-aws-access | AWS access for an AI agent, agent role review, kill switch | agent_access.py trust, permission, boundary and SCP documents plus commands; role review findings |
aws-incident-response-runbook | an AWS security incident or a GuardDuty finding that needs a response | ir_runbook.py Markdown runbook for one of six scenarios, picked from GuardDuty findings or by name |
aws-spend-guardrails | budget alerts, anomaly detection, sandbox spend limits, cost spikes | spend_guardrails.py Budgets and anomaly JSON, spend-deny SCPs, cost review with anomaly flags |
sandbox-account-guardrail-pack | create or tighten a sandbox OU | sandbox_pack.py SCPs, baseline checklist, auto-expiry design, budget files and a user README |