Official agent skill

Eks Security

by aws-samples in aws-samples/appmod-blueprints

A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

OfficialMIT-0Auto-check passedLegal & Compliance

Install Eks Security

skills CLI
$ npx skills add aws-samples/appmod-blueprints --skill eks-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws-samples/appmod-blueprints eks-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws-samples/appmod-blueprints.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.kiro/skills/eks-security .claude/skills/eks-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
eks-security
GitHub stars
113
Token cost
~4.7k tokens
SKILL.md length
1,824 words
Files
13 (incl. references)
Skills in repo
9
Repo updated
First seen
Licence
MIT-0

At a glance

A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…

  • Works in 8 steps: Compliance regime(s)? None / SOC 2 /… → Workload sensitivity? Public / internal… → OS / AMI strategy? Open to AWS defaults… → …
  • Someone needs security
  • SKILL.md covers When to Use This Skill, Discovery First — the Required…, The 7-Layer Security &… and Compliance-Regime Scope…, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Eks Security is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization. Use whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS cluster", "Bottlerocket vs AL2023 vs RHEL/Ubuntu AMI", "EKS Pod Identity vs IRSA", "Access Entries vs aws-auth", "GuardDuty for EKS", "Pod Security Admission / Kyverno / OPA", "NetworkPolicy / Security Groups for Pods", "ECR scanning / image signing (Cosign / Notation)", "EKS audit logging", "etcd / secrets encryption", or…

Its SKILL.md is about 4.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including reference files (for example `references/audit-logging.md`, `references/compliance-accelerators.md` and `references/compliance-regimes.md`).

It sits in Legal & Compliance, covering Healthcare and finance regulation, SOC 2 and security compliance and Privacy and GDPR. It works with Amazon Web Services. The licence is MIT-0.

When your agent uses it

  • Someone needs security
  • Compliance guidance for Amazon EKS — phrased as CIS Benchmark for EKS
  • HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS
  • Harden my EKS cluster

Example prompts

  • “CIS Benchmark for EKS”
  • “HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS”
  • “harden my EKS cluster”
  • “/eks-security”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Compliance regime(s)? None / SOC 2 / HIPAA / PCI-DSS / FedRAMP Moderate / FedRAMP High / GDPR / ISO 27001 / HITRUST / NIST 800-53/171 /…
  2. Workload sensitivity? Public / internal / PII / PHI (HIPAA) / cardholder data (PCI) / federal.
  3. OS / AMI strategy? Open to AWS defaults / Bottlerocket-first / AL2023+CIS custom AMI / Ubuntu mandate / RHEL mandate / custom hardened /…
  4. Audit timeline? None / <3 mo (urgent) / 3-6 mo / 6-12 mo / continuous.
  5. Cluster topology? Single vs multi-cluster, single vs multi-account, multi-region, EKS Anywhere, Hybrid Nodes, GovCloud.
  6. Team K8s/security skill? Low / moderate / high / mixed.
  7. Operational-overhead tolerance? Zero (managed-only) / low / moderate / high.
  8. Current security tooling baseline? None / AWS-native / third-party CNAPP / OSS / hybrid.

What it can do on your machine

Read from SKILL.md and the folder at commit 723cdc0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com
    • aws.amazon.com
    • github.com
    • catalog.us-east-1.prod.workshops.aws

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Eks Security loads about 4.7k tokens when it runs, and up to ~22k if it reads all its reference files. Until then it costs about 255 tokens; SKILL.md has 1,824 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~255
When it runs · the whole SKILL.md, loaded when a task matches
~4.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~22k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws-samples/appmod-blueprints at commit 723cdc0, republished under its MIT-0 licence (© aws-samples). 1,824 words, ~4,688 tokens.

Download SKILL.mdSave it as .claude/skills/eks-security/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.
name
eks-security
description
Use whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS cluster", "Bottlerocket vs AL2023 vs RHEL/Ubuntu AMI", "EKS Pod Identity vs IRSA", "Access Entries vs aws-auth", "GuardDuty for EKS", "Pod Security Admission / Kyverno / OPA", "NetworkPolicy / Security Groups for Pods", "ECR scanning / image signing (Cosign / Notation)", "EKS audit logging", "etcd / secrets encryption", or regulated-workload / audit-prep guidance. Walks the discovery-driven 7-layer security stack (OS/AMI → identity → workload → image → runtime → audit → compliance accelerators), the compliance-regime scope view, the AWS-canonical baseline, and a 30/60/90 hardening roadmap. Trigger even if "compliance" is never said — any EKS hardening, audit-prep, or regulated-workload decision qualifies. Skip for non-EKS (ECS/ROSA), account-level security with no EKS angle, or GenAI-workload security (use eks-genai).

EKS Security & Compliance

End-to-end, opinionated security and compliance guidance for Amazon EKS, structured as a 7-layer stack plus a compliance-regime cross-cutting view. This skill is discovery-driven — the right hardening stack is a function of (compliance regime × OS-standardization mandate × team skill × audit timeline × workload sensitivity × air-gap requirement × scale × operational-overhead tolerance). Skipping the discovery questions makes the recommendation wrong about half the time.

Two AWS-published guides are the canonical foundation and every recommendation must align with one or both: the EKS Best Practices: Compliance guide and the EKS Best Practices: Runtime Security guide. For "how do I run a single cluster well" (non-security) use eks-best-practices; for designing/building the cluster use eks-design / eks-build.

The accuracy bar (non-negotiable for this skill). Compliance is the one domain where customers validate every claim against an auditor. Compliance status changes over time — always defer to the live AWS Services in Scope page before quoting program coverage in any customer-facing document. Never state a cryptographic-module status, FedRAMP boundary, or certification you cannot cite to an AWS-published source. When you can't ground a claim, say so — do not synthesize.

When to Use This Skill

Activate when the user wants to:

  • Harden an EKS cluster or prepare for a first-time compliance audit (HIPAA, PCI-DSS, FedRAMP, SOC 2, ISO 27001, GDPR, HITRUST, NIST 800-53/171)
  • Choose an OS / AMI strategy for security (Bottlerocket vs AL2023-with-CIS vs Ubuntu Pro vs RHEL vs Auto Mode)
  • Decide identity & access (EKS Pod Identity vs IRSA; Access Entries vs aws-auth)
  • Apply workload security (Pod Security Admission, Kyverno/OPA, NetworkPolicy, Security Groups for Pods)
  • Secure the image supply chain (ECR Enhanced Scanning, Cosign/Notation signing, admission verification)
  • Add runtime security (GuardDuty for EKS, Falco) and audit logging (control-plane logs, CloudTrail, SIEM)
  • Wire compliance accelerators (Audit Manager, Config, Security Hub, Artifact)

Don't use this skill for:

  • Non-EKS container platforms — ECS/Fargate-without-EKS (defer to ECS security guidance) or ROSA (Red Hat manages the stack differently)
  • AWS account-level / org-wide security with no EKS-specific angle (IAM org policy, SCPs, SSO, multi-service GuardDuty) → Security guidance, not this skill
  • GenAI/GPU workload security specifically (model-artifact provenance, training-data confidentiality, GPU-node compliance) → eks-genai
  • Generic EKS architecture/cost/upgrade decisions with no security driver → eks-best-practices / eks-design
  • Generating Terraform/Helm (→ eks-build) or auditing a live cluster's operational posture (→ eks-operation-review)

Discovery First — the Required Questions

Do NOT recommend a hardening stack before answering these. The single most common mistake is reflexively saying "use Bottlerocket" or "use AL2023 with CIS hardening" without confirming the customer's context. The first four answers alone determine ~80% of the recommendation.

  1. Compliance regime(s)? None / SOC 2 / HIPAA / PCI-DSS / FedRAMP Moderate / FedRAMP High / GDPR / ISO 27001 / HITRUST / NIST 800-53/171 / CJIS / DISA IL5 — rank primary/secondary if multiple.
  2. Workload sensitivity? Public / internal / PII / PHI (HIPAA) / cardholder data (PCI) / federal.
  3. OS / AMI strategy? Open to AWS defaults / Bottlerocket-first / AL2023+CIS custom AMI / Ubuntu mandate / RHEL mandate / custom hardened / EKS Auto Mode.
  4. Audit timeline? None / <3 mo (urgent) / 3-6 mo / 6-12 mo / continuous.
  5. Cluster topology? Single vs multi-cluster, single vs multi-account, multi-region, EKS Anywhere, Hybrid Nodes, GovCloud.
  6. Team K8s/security skill? Low / moderate / high / mixed.
  7. Operational-overhead tolerance? Zero (managed-only) / low / moderate / high.
  8. Current security tooling baseline? None / AWS-native / third-party CNAPP / OSS / hybrid.

Full required + recommended question set, the 5 adoption-challenge archetypes, and the 8-step response framework: references/engagement-and-response.md.

The 7-Layer Security & Compliance Stack

Walk the layers bottom-up on a first engagement; each layer's controls compound on the previous.

LayerFocusAWS-canonical defaultReference
1 — Compute / OS / AMINode hardeningBottlerocket (immutable, SELinux-enforcing, minimal); else CIS-hardened AL2023 via Image Builder; respect vendor-OS mandates (Ubuntu Pro / RHEL)os-ami-hardening.md
2 — Identity & AccessWho can do whatEKS Pod Identity (workloads) + EKS Access Entries (cluster access)identity-and-access.md
3 — Workload SecurityPod + network posturePSA restricted + Kyverno (or OPA) + VPC CNI NetworkPolicy (default-deny) + Security Groups for Podsworkload-security.md
4 — Image Supply ChainTrust what you runECR Enhanced Scanning (Inspector) + Cosign/Notation signing + Kyverno verifyImages admissionimage-supply-chain.md
5 — Runtime SecurityDetect at runtimeGuardDuty for EKS (EKS Protection + Runtime Monitoring); Falco for OSS/custom rules; findings → Security Hubruntime-security.md
6 — Audit Logging & ForensicsProve what happenedEKS control-plane logs (audit + authenticator minimum) + CloudTrail + VPC Flow Logs + SIEM forwardingaudit-logging.md
7 — Compliance AcceleratorsContinuous evidenceAudit Manager + Config + Security Hub + Artifact (download attestations)compliance-accelerators.md

The AWS-canonical reference stack for a new commercial cluster: Bottlerocket (L1) + Pod Identity + Access Entries (L2) + PSA restricted + Kyverno + VPC CNI NetworkPolicy + Security Groups for Pods (L3) + ECR Enhanced Scanning + Cosign signing (L4) + GuardDuty for EKS (L5) + control-plane audit+authenticator logging + CloudTrail (L6) + Audit Manager + Config + Security Hub (L7). The vendor-OS path applies the same stack with a Layer-1 substitution only.

Cross-cutting concerns (span every layer, aligned to the AWS Best Practices security areas): data encryption & secrets management (default envelope encryption on K8s 1.28+, CMK, Secrets Manager/CSI/ESO) → encryption-and-secrets.md; multi-tenancy & multi-account isolation (soft vs hard, namespaces→cluster-/account-per-tenant) → multi-tenancy.md; incident response & forensics (the runbook when a detection fires) → incident-response-and-forensics.md; and the shared-responsibility model — AWS secures the control plane (control-plane nodes + etcd) and assumes more as you move self-managed → MNG → Fargate; you secure the data plane, node OS, workloads, and the controls in this skill. Each reference includes its per-layer shared-responsibility split.

Compliance-Regime Scope (cross-cutting)

EKS is natively in scope for PCI-DSS L1, HIPAA-eligible (BAA required), SOC 1/2/3, ISO 27001/27017/27018/9001, FedRAMP Moderate (commercial) and High (GovCloud only), HITRUST CSF, IRAP, C5, K-ISMS, ENS High, OSPAR, DISA IL4/IL5 (GovCloud only — commercial reaches IL2). AWS provides alignment / framework support (not independent attestation) for GDPR, NIST SP 800-53/800-171, and CJIS — the customer owns workload-level controls. Per-regime nuance, the scope table, and the worked HIPAA/PCI/FedRAMP/GDPR/Auto-Mode scenarios: references/compliance-regimes.md.

Always include the disclaimer in customer-facing output: "Compliance status changes over time — verify on the live AWS Services in Scope page before quoting program coverage." And precision matters: EKS is HIPAA-eligible (with a signed BAA), not "HIPAA-compliant"; FedRAMP High = GovCloud only, Moderate = commercial regions.

Security Baseline (non-negotiable — every recommendation includes this)

Regardless of regime, every hardening recommendation MUST include:

  • EKS Pod Identity (recommended for new workloads; IRSA is a fully supported alternative — see note) — never static AWS keys
  • EKS Access Entries for cluster access — never the aws-auth ConfigMap on new clusters
  • EKS control-plane logging — audit + authenticator at minimum
  • GuardDuty for EKS — EKS Protection (audit-log) + Runtime Monitoring (agent)
  • ECR Enhanced Scanning on all production repositories
  • Pod Security Admission restricted on production namespaces
  • NetworkPolicy default-deny on production namespaces (VPC CNI native, or Calico/Cilium on self-managed)
  • Encryption at rest — EKS provides default envelope encryption of all Kubernetes API data (KMS provider v2, AWS-owned key) on K8s 1.28+ with no action required; bring a customer-managed KMS key (CMK) for control over rotation/audit, and use CMKs for EBS/S3/EFS under compliance regimes (etcd EBS volumes are also EBS-encrypted independently)
  • Encryption in transit — TLS in-cluster; mTLS via service mesh for high-sensitivity workloads
  • Secrets via Secrets Manager + Secrets Store CSI Driver + ASCP (or External Secrets Operator) — never plain Kubernetes Secrets in production; never baked into images
  • CloudTrail for EKS API audit; private API endpoint (or restricted public CIDR allowlist) for production
  • Preventive governance (multi-account): enforce the above with EKS IAM condition keys in SCPs/IAM (private endpoint, CMK encryption, approved K8s version, deletion protection) so non-compliant clusters can't be created — see identity-and-access.md
Show full SKILL.md (649 more words)Show less

Hardening Roadmap (30 / 60 / 90)

  • Days 1-30 (baseline, non-disruptive): enable control-plane audit+authenticator logging; enable GuardDuty for EKS; enable Security Hub (CIS AWS Foundations + AWS FSBP); enable ECR Enhanced Scanning; run kube-bench for the current CIS posture. Change nothing yet — establish the baseline.
  • Days 31-60 (identity + workload): migrate aws-auth → Access Entries (planned change window, kubectl access pre-validated); migrate/justify IRSA → Pod Identity; enable PSA restricted (start audit mode → enforce); deploy Kyverno/OPA; enforce NetworkPolicy default-deny.
  • Days 61-90 (OS + image + accelerators): migrate to Bottlerocket (or build CIS-hardened AL2023 via Image Builder); enable ECR image signing; deploy Audit Manager with the applicable framework; validate Security Hub against the compliance pack; download attestations from AWS Artifact.
  • Greenfield: deploy the full 7-layer stack at cluster creation, not retrofitted.

Top Guardrails (the high-cost mistakes)

  • Don't recommend a stack before the discovery questions — the #1 mistake.
  • Don't call IRSA "legacy" — AWS docs say Pod Identity is recommended for new workloads while IRSA remains a fully supported alternative (and is the right choice on Fargate, Windows nodes, unsupported SDKs, or cross-account OIDC federation). "Legacy" applies to the aws-auth ConfigMap, not IRSA.
  • Don't use aws-auth ConfigMap on new clusters — it's deprecated; use Access Entries (auditable in CloudTrail).
  • Don't recommend PodSecurityPolicy (PSP) — removed in Kubernetes 1.25+; use PSA + Kyverno/OPA.
  • Don't recommend AWS App Mesh for new work — end of support Sept 30, 2026; use Istio/Linkerd/Cilium mesh or VPC Lattice.
  • Don't recommend EKS Auto Mode when a hard CIS-hardened-custom-AMI requirement exists — Auto Mode doesn't support custom AMIs (as of June 2026); use Bottlerocket on self-managed Karpenter NodePools. Cilium CNI is also not supported on Auto Mode.
  • Don't promise "HIPAA-compliant" — EKS is HIPAA-eligible; a signed BAA is required and the customer owns workload-level controls.
  • Don't conflate FedRAMP Moderate (commercial) with High (GovCloud); FIPS 140-3 (Bottlerocket FIPS AMIs) with 140-2; or CIS AL2 with CIS AL2023 benchmarks (distinct documents).
  • Don't treat a CMK as free of operational risk — once a CMK is the envelope-encryption key, disabling it degrades the cluster (the API server can't boot on restart; ~30-day window to re-enable before forced auto-upgrade) and deleting it makes the cluster unrecoverable. Guard the CMK with least-privilege IAM + a CloudWatch alarm.
  • Don't synthesize compliance claims — cite an AWS-published source or recommend escalation.

Escalation

Create a SpecReq / escalate for: first-time certification on a mission-critical regulated workload; XXL+ segment; FedRAMP High / GovCloud; Top Secret/Secret (out of scope here); EKS Anywhere or Hybrid Nodes inside a FedRAMP boundary; multi-tenant SaaS with cross-tenant PHI/cardholder/federal isolation; customer-vs-auditor disagreement on AWS-managed-control acceptability; or any claim you cannot ground. Full criteria: references/engagement-and-response.md.

How to Use the References

Progressive disclosure — the essentials are above; load a reference only when the task needs that depth:

ReferenceLoad when the task is about…
engagement-and-response.mdFull discovery question set, adoption-challenge archetypes, the 8-step response framework, escalation criteria
os-ami-hardening.mdLayer 1 — Bottlerocket vs AL2023 vs Ubuntu/RHEL, CIS benchmark hierarchy, Image Builder hardened-AMI pipeline, FIPS
identity-and-access.mdLayer 2 — Pod Identity vs IRSA, Access Entries vs aws-auth, access policies
workload-security.mdLayer 3 — PSA, Kyverno/OPA, NetworkPolicy, Security Groups for Pods, service-mesh mTLS
image-supply-chain.mdLayer 4 — ECR Enhanced Scanning, Cosign/Notation signing, admission control, third-party scanners
runtime-security.mdLayer 5 — GuardDuty for EKS, Falco, Security Hub aggregation
audit-logging.mdLayer 6 — control-plane log types, CloudTrail, VPC Flow Logs, SIEM forwarding, retention
compliance-accelerators.mdLayer 7 — Audit Manager, Config, Security Hub, Artifact, kube-bench
encryption-and-secrets.mdDefault envelope encryption (KMS v2), CMK + its operational risk, EBS/EFS/FSx encryption, Secrets Manager/CSI/ESO/Sealed Secrets, secret hygiene
multi-tenancy.mdSoft vs hard multi-tenancy, in-cluster isolation (namespaces/RBAC/NetworkPolicy/quotas/node isolation), cluster-/account-per-tenant
incident-response-and-forensics.mdIR runbook for a compromised pod/node, isolation/eradication, credential revocation, forensic capture
compliance-regimes.mdPer-regime scope (HIPAA/PCI/FedRAMP/GDPR/ISO/…), the scope table, worked scenarios, regime-specific controls

Sources

© aws-samples, MIT-0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 12 other files (references) in .kiro/skills/eks-security of aws-samples/appmod-blueprints.

  • SKILL.md
  • references/audit-logging.md
  • references/compliance-accelerators.md
  • references/compliance-regimes.md
  • references/encryption-and-secrets.md
  • references/engagement-and-response.md
  • references/identity-and-access.md
  • references/image-supply-chain.md
  • references/incident-response-and-forensics.md
  • references/multi-tenancy.md
  • references/os-ami-hardening.md
  • references/runtime-security.md
  • references/workload-security.md

Open the folder on GitHubat commit 723cdc0

Compare with similar skills

Eks Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Eks Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Eks Security this skillaws-samples/appmod-blueprints113—~4.7kAutomated safety check: PassMIT-0
Audit Reportharness/harness-skills115—~1.3kAutomated safety check: PassApache-2.0
Security Compliancesangrokjung/claude-forge8492 repos~7.2kAutomated safety check: PassMIT
Ciso Advisoralirezarezvani/claude-skills28k1 repos~1.8kAutomated safety check: PassMIT
ComplianceRightNow-AI/openfang18k—~921Automated safety check: PassApache-2.0
Policy OpaAgentSecOps/SecOpsAgentKit2191 repos~3.5kAutomated safety check: PassCustom licence

Similar skills

  • Audit Report

    harness/harness-skills

    Generate audit reports and compliance trails using Harness audit trail data via MCP v2 tools.

    115 GitHub stars~1.3k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Security Compliance

    sangrokjung/claude-forge

    Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and…

    849 GitHub starsUsed in 2 repos~7.2k tokens
    Legal & ComplianceAuto-check passed
  • Ciso Advisor

    alirezarezvani/claude-skills

    Security leadership for growth-stage companies. An agent skill from alirezarezvani/claude-skills.

    28k GitHub starsUsed in 1 repo~1.8k tokens
    Legal & ComplianceAuto-check passed
  • Compliance

    RightNow-AI/openfang

    Compliance expert for SOC 2, GDPR, HIPAA, PCI-DSS, and security frameworks

    18k GitHub stars~921 tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    219 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Compliance Os

    alirezarezvani/claude-skills

    Compliance OS — meta-orchestrator that lets compliance teams CONFIGURE which frameworks apply, COMPUTE cross-framework control overlap, SIMULATE internal audits, and CONSOLIDATE evidence across…

    28k GitHub stars~3.3k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed

More from aws-samples/appmod-blueprints

All 9 skills in this repo
  • Eks Best Practices

    aws-samples/appmod-blueprints

    Official

    Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.

    113 GitHub stars~5k tokensUpdated today
    Auto-check passed
  • Troubleshoot Platform

    aws-samples/appmod-blueprints

    Official

    Systematic troubleshooting for the PEEKS workshop platform — EKS clusters, Terraform state, ingress, load balancers, MCP tool failures, YAML validation.

    113 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Eks Recon

    aws-samples/appmod-blueprints

    Official

    EKS cluster reconnaissance and environment discovery. An agent skill from aws-samples/appmod-blueprints.

    113 GitHub stars~4.7k tokensUpdated today
    Auto-check: warnings
  • Troubleshoot Kro

    aws-samples/appmod-blueprints

    Official

    Troubleshoot Kro ResourceGraphDefinition (RGD) issues — stuck instances, ACK resource failures, IAM trust policy problems, resource conflicts.

    113 GitHub stars~986 tokensUpdated today
    Auto-check passed
  • Eks Upgrade Check

    aws-samples/appmod-blueprints

    Official

    Assess EKS cluster upgrade readiness — run automated checks across 8 areas (version, breaking changes, deprecated APIs, add-on compatibility, node readiness, workload risks, AWS Insights, upgrade…

    113 GitHub stars~2.4k tokensUpdated today
    Auto-check: warnings
  • Eks Platform Engineering

    aws-samples/appmod-blueprints

    Official

    A skill your agent uses whenever someone is designing or building an Internal Developer Platform (IDP) or doing platform engineering on Amazon EKS — phrased as "build a developer platform"…

    113 GitHub stars~4.6k tokensUpdated today
    Auto-check passed

Questions about Eks Security

What does Eks Security do?

A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…. Eks Security is an agent skill from aws-samples/appmod-blueprints, published by the product's own GitHub organization.

When should I use Eks Security?

Eks Security fits situations like: someone needs security; compliance guidance for Amazon EKS — phrased as CIS Benchmark for EKS; HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS; harden my EKS cluster.

How do I install Eks Security in Claude Code?

Run `npx skills add aws-samples/appmod-blueprints --skill eks-security -a claude-code`. Or copy the skill folder (.kiro/skills/eks-security in aws-samples/appmod-blueprints) into .claude/skills/eks-security in your project. Claude Code loads it when a task matches its description.

How do I install Eks Security in Codex?

Run `npx skills add aws-samples/appmod-blueprints --skill eks-security -a codex`. Or copy the skill folder (.kiro/skills/eks-security in aws-samples/appmod-blueprints) into .agents/skills/eks-security in your project. Codex loads it when a task matches its description.

Can I use Eks Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws-samples/appmod-blueprints --skill eks-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/eks-security, .gemini/skills/eks-security, .github/skills/eks-security and .opencode/skills/eks-security in your project.

What does Eks Security need to run?

SKILL.md names no scripts, command-line tools or credentials: Eks Security is instructions for the agent only.

Does Eks Security access the network?

SKILL.md names 4 domains. As links in the text: docs.aws.amazon.com, aws.amazon.com, github.com and catalog.us-east-1.prod.workshops.aws. This is read from the text; nothing was executed.

Is Eks Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Eks Security use?

Eks Security is published under the MIT-0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Eks Security use?

About 4.7k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.

What are the alternatives to Eks Security?

Skills that share tags, products or a category with Eks Security: Audit Report (harness/harness-skills, 115 stars), Security Compliance (sangrokjung/claude-forge, 849 stars), Ciso Advisor (alirezarezvani/claude-skills, 28k stars) and Compliance (RightNow-AI/openfang, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Eks Security?

aws-samples (a GitHub organization, an official publisher) maintains it in aws-samples/appmod-blueprints, which has 113 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 6, 2026.

Source: aws-samples/appmod-blueprints on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.