Search
Security · Amazon Web Services
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | Detect unusual API call patterns in AWS CloudTrail logs using boto3, statistical baselining, and behavioral analysis to identify credential compromise, privilege escalation, and unauthorized… | mukul975/ | 34k | — | ~751 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 50 | Detect AWS IAM privilege escalation paths using boto3 and Cloudsplaining policy analysis to identify overly permissive policies, dangerous permission combinations, and least-privilege violations | mukul975/ | 34k | — | ~609 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 51 | Creates and manages secrets in AWS Secrets Manager following security best practices. | aws/ | 2.8k | 1 repo | ~461 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 52 | IAM policy review, hardening, and least privilege implementation | aiskillstore/ | 433 | 4 repos | ~2.6k | Automated safety check: Pass | No licence | yesterday |
| 53 | Comprehensive AWS security posture assessment using AWS CLI and security best practices | aiskillstore/ | 433 | 4 repos | ~2.6k | Automated safety check: Pass | No licence | yesterday |
| 54 | 54.Credentials Centralized API key management from Access.txt. An agent skill from alinaqi/maggy. | alinaqi/ | 707 | — | ~2.4k | Automated safety check: Notes | MIT | 17 days ago |
| 55 | Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails. | borghei/ | 891 | — | ~3.5k | Automated safety check: Pass | MIT | 4 days ago |
| 56 | Runs the Pacu AWS exploitation framework end-to-end — session and credential setup, IAM enumeration, automated privilege-escalation scanning via iamprivescscan, and persistence/backdooring modules… | mukul975/ | 34k | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 57 | Deploys canary tokens and honeytokens (fake AWS credentials, DNS canaries, document beacons, database records) that trigger alerts when accessed by attackers. | mukul975/ | 34k | — | ~593 | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 58 | Manage AWS accounts, organizations, IAM, and billing. An agent skill from hoodini/ai-agents-skills. | hoodini/ | 282 | — | ~3.5k | Automated safety check: Pass | No licence | 3 mo ago |
| 59 | Run a fast AWS Security Agent diff scan on only the changed code since a git ref. | aws/ | 2.8k | — | ~1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 60 | Pull AWS Security Agent findings (penetration tests and code reviews) and drive remediation. | aws/ | 2.8k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 61 | Run an AWS Security Agent scan on the workspace — uploads the source to AWS, scans it with the managed Security Agent service, and returns ranked, verified findings with code locations and… | aws/ | 2.8k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 62 | Run an AWS Security Agent threat model review on spec/design documents. | aws/ | 2.8k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 63 | Diagnoses and resolves Amazon EFS issues including mount failures, NFS timeouts, permission errors, throughput problems, and burst credit exhaustion. | aws/ | 2.8k | — | ~1.6k | Automated safety check: Notes | Apache-2.0 | yesterday |
| 64 | Detect and break the cloud post-compromise attack chain (AWS / Azure / GCP) — per-stage CloudTrail / Activity-Log / Audit-Log detection signals and the preventive controls that close each step. | transilienceai/ | 563 | — | ~476 | Automated safety check: Pass | MIT | 2 mo ago |
| 65 | Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage… | trilwu/ | 157 | — | ~1.9k | Automated safety check: Pass | MIT | 1 mo ago |
| 66 | Investigate security incidents in Amazon Web Services -- reconstruct attacker activity from CloudTrail, VPC Flow Logs, and GuardDuty, anchor the investigation on the compromised principal (access… | trilwu/ | 157 | — | ~4.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 67 | Investigate a security incident in Google Cloud — establishing what audit logging exists before trusting a gap, reconstructing activity from Cloud Audit Logs, triaging service-account and OAuth… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 68 | Provisions, connects, migrates, and operates Amazon RDS for Db2. | aws/ | 2.8k | — | ~6.9k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 69 | A skill your agent uses when standing up the core AWS surface a small product needs: hardening a fresh account, a private S3 bucket, encrypted RDS Postgres, ECS Fargate vs EC2, CloudFront + OAC, or… | ericrisco/ | 180 | — | ~2.9k | Automated safety check: Notes | MIT | 2 days ago |
| 70 | Provides AWS Key Management Service (KMS) patterns using AWS SDK for Java 2.x. | giuseppe-trisciuoglio/ | 357 | — | ~3.6k | Automated safety check: Notes | MIT | 1 mo ago |
| 71 | Provides AWS CloudFormation patterns for security infrastructure including KMS encryption, Secrets Manager, IAM security, VPC security, ACM certificates, parameter security, outputs, and secure… | giuseppe-trisciuoglio/ | 357 | — | ~2.8k | Automated safety check: Notes | MIT | 1 mo ago |
| 72 | Operate Prowler, Cloudsplaining, cloud CLIs, policy documents, and resource evidence for advanced AWS, Azure, GCP, and Kubernetes-adjacent posture assessment. | cyberful/ | 135 | — | ~907 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 73 | 73.Agent Bom Open security platform for agentic infrastructure — broad scanning plus MCP discovery, CVEs, blast radius, SBOMs, CIS benchmarks (AWS, Azure, GCP, Snowflake), OWASP/NIST/MITRE compliance, AISVS… | LeoYeAI/ | 2.2k | — | ~4.4k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 74 | Provisions, scales, and operates Amazon EC2 virtual-machine workloads: instance-type selection (Graviton/Arm64, burstable T credits, GPU, instance store vs EBS), launch templates, Auto Scaling… | aws/ | 2.8k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 75 | Installs, configures, and troubleshoots Network Flow Monitor agents on EC2 instances to monitor network path health. | aws/ | 2.8k | — | ~858 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 76 | AWS security service suitability, coverage and cost recommendations: WAF/origin overlap, AWS Network Firewall inspection coverage and policy review, VPC endpoint, Transit Gateway/Cloud WAN… | aws/ | 2.8k | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 77 | Create iam policy creator operations. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~546 | Automated safety check: Pass | MIT | yesterday |
| 78 | Automatically load this skill when investigating application outages, service degradation, or errors that could have security-related root causes — including unexplained downtime, authentication or… | aws/ | 103 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 79 | AWS VPC networking audit covering CIDR architecture, Security Group and NACL rule analysis, Transit Gateway connectivity, VPC Flow Log forensics, Route Table validation, and ENI/EIP resource… | LeoYeAI/ | 2.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 80 | Cross-cloud security posture assessment covering IAM analysis, encryption audit, and public exposure detection across AWS, Azure, and GCP using [AWS]/[Azure]/[GCP] inline labels for… | LeoYeAI/ | 2.2k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 81 | 81.AWS Advisor AWS Advisor workflow skill. An agent skill from diegosouzapw/awesome-omni-skills. | diegosouzapw/ | 159 | — | ~4.3k | Automated safety check: Pass | MIT | 3 mo ago |
| 82 | Guidance for Microsoft Defender for Cloud — cloud security posture management (CSPM) and cloud workload protection (CWPP) across Azure, AWS, and GCP. | vinayaklatthe/ | 175 | — | ~1.9k | Automated safety check: Pass | MIT | 3 mo ago |