Agent skill

Cloud Security

by borghei in borghei/Claude-Skills

Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails.

MITAuto-check passedSecurity

Install Cloud Security

skills CLI
$ npx skills add borghei/Claude-Skills --skill cloud-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills cloud-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering/cloud-security .claude/skills/cloud-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloud-security
GitHub stars
874
Token cost
~3.5k tokens
SKILL.md length
1,736 words
Files
11 (incl. scripts, references, assets)
Skills in repo
364
Repo updated
First seen
Licence
MIT

At a glance

Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails.

  • Works in 5 steps: Export the resource inventory for every… → Populate tags.data_classification on… → Run the auditor, reading critical… → …
  • Auditing a cloud account
  • SKILL.md covers When to use this skill, Inputs the skill expects, Clarify First and Workflows, plus 3 more sections
  • Runs Python scripts from its folder; calls python3

What it does

Cloud Security is an agent skill from borghei/Claude-Skills. Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails. Use when auditing a cloud account, before a production launch, or after a scan.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including scripts, reference files and assets (for example `assets/inventory_export_guide.md`, `assets/posture_review_template.md` and `assets/sample_iam_export.json`).

It sits in Security, covering Cloud security, Cloud architecture and LLM guardrails. It works with Amazon Web Services, Google Cloud and Microsoft Azure. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • Auditing a cloud account
  • Before a production launch

Example prompts

  • “/cloud-security”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Export the resource inventory for every region, normalizing to the
  2. Populate tags.data_classification on data stores before scanning —
  3. Run the auditor, reading critical findings before the score.
  4. For each critical, answer explicitly: is it reachable from the internet
  5. Group findings into classes and name the preventive guardrail for each class

What it can do on your machine

Read from SKILL.md and the folder at commit c9a1487. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloud Security loads about 3.5k tokens when it runs, and up to ~8.2k if it reads all its reference files. Until then it costs about 60 tokens; SKILL.md has 1,736 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit c9a1487, republished under its MIT licence (© borghei). 1,736 words, ~3,491 tokens.

Download SKILL.mdSave it as .claude/skills/cloud-security/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
cloud-security
description
Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails. Use when auditing a cloud account, before a production launch, or after a scan.
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
borghei
metadata.category
engineering
metadata.domain
cloud-security
metadata.updated
2026-07-21
metadata.tags
cloud-security, iam, least-privilege, landing-zone, posture-management

Cloud Security

Cloud breaches are rarely clever. They are a public bucket, an over-permissive role, a database on an open security group, and no audit log to reconstruct what happened. This skill covers cloud posture specifically: the configuration of identity, network exposure, encryption, detection coverage, and multi-account guardrails across AWS, Azure, and GCP.

Scope boundary. This skill is deliberately narrow so it does not overlap its neighbours in engineering/. It does not cover application-code vulnerabilities, dependency CVEs, or compliance-framework mapping — that is senior-secops. It does not cover log analysis and intrusion signals — that is threat-detection. It does not cover offensive engagement planning or rules of engagement — that is red-team. It does not cover prompt injection, model extraction, or ML-pipeline threats — that is ai-security. What lives here is the posture of the cloud control plane itself: who can do what, what is reachable, what is encrypted, and what is logged.

When to use this skill

  • A cloud account or subscription is about to hold production customer data for the first time
  • An IAM sprawl problem has accumulated and nobody knows which roles are actually admin
  • A posture scanner produced hundreds of findings and the team needs a defensible priority order
  • A new landing zone or multi-account structure is being designed
  • A security questionnaire, SOC 2 audit, or customer due-diligence review asks for cloud evidence
  • An incident occurred and the review needs to establish what the exposure was and whether logs exist to prove it

Inputs the skill expects

  • An exported resource inventory per account, covering every region (see assets/inventory_export_guide.md)
  • An IAM principal export with policy statements, trust policies, and last-used data
  • Account/subscription/project settings: audit logging, managed detection, org guardrails, log-archive isolation
  • Data classification per store — which resources hold confidential, PCI, PHI, or restricted data
  • The organization's account topology and which accounts are production
  • The decision the review feeds: launch approval, audit evidence, or remediation backlog

Clarify First

Before running the review, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Which accounts hold production or classified data — decides review scope and which findings are launch-blocking rather than backlog
  • Data classification of the stores in scope — promotes unencrypted and un-logged findings from high to critical; without it every severity is a guess
  • Whether the exports cover all regions — a region-scoped export reliably misses the forgotten test database that becomes the incident
  • What the output feeds — a launch gate, an audit evidence pack, or a backlog; changes severity strictness and report format

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.

Workflows

Workflow 1 — Audit posture across an account
  1. Export the resource inventory for every region, normalizing to the schema in assets/inventory_export_guide.md. Include account-level settings.
  2. Populate tags.data_classification on data stores before scanning — severity depends on it, and an unclassified store defaults to the lower band.
  3. Run the auditor, reading critical findings before the score.
  4. For each critical, answer explicitly: is it reachable from the internet right now, and what data sits behind it.
  5. Group findings into classes and name the preventive guardrail for each class rather than ticketing every instance.
bash
python3 engineering/cloud-security/scripts/posture_auditor.py \
  --input engineering/cloud-security/assets/sample_inventory.json \
  --min-severity high --fail-on critical
Workflow 2 — Review IAM for least privilege and escalation paths
  1. Export principals with their policy statements, trust policies, MFA state, and last-used data. Populate trust.approved with your own account IDs.
  2. Run the review and read the escalation paths first — they convert a mid-privilege identity into an admin and outrank raw wildcard counts.
  3. Work the principal risk ranking top-down; for each high-tier principal, derive the replacement policy from 90 days of actual usage, never from what the owning team believes it needs.
  4. Disable stale principals for one cycle before deleting, so breakage surfaces as a report rather than an outage.
bash
python3 engineering/cloud-security/scripts/iam_least_privilege.py \
  --input engineering/cloud-security/assets/sample_iam_export.json \
  --stale-days 90 --min-severity high --fail-on critical
Workflow 3 — Convert findings into landing-zone guardrails
  1. Run both tools with --format json and count findings by class, not by instance.
  2. For any class appearing three or more times, stop remediating instances and write the preventive control from references/landing-zone-and-guardrails.md §3.
  3. Apply each guardrail to the Dev OU for two weeks before production, with a documented exception path and an owner.
  4. Re-scan at 30 days and report the delta, not the absolute count — absolute counts move with inventory growth and demoralize the team.
bash
python3 engineering/cloud-security/scripts/posture_auditor.py \
  --input engineering/cloud-security/assets/sample_inventory.json \
  --format json > /tmp/posture.json

python3 engineering/cloud-security/scripts/iam_least_privilege.py \
  --input engineering/cloud-security/assets/sample_iam_export.json \
  --format json > /tmp/iam.json

Decision frameworks

Severity calibration
SeverityDefinitionExamples
CriticalDirect path to data exposure or account takeover, exploitable nowPublic store holding classified data; admin port open to the internet; *:* on *; wildcard role trust; control-plane audit logging off
HighSignificant weakening, exploitable with one further stepService-wide wildcard grant; unencrypted classified store; no backups on a primary store; log archive not isolated; human without MFA
MediumDefence-in-depth or detection gapData-plane access logs off; no permission boundary on a privileged principal; provider-managed keys on classified data
LowGovernance hygieneMissing owner or classification tags

Gate on critical count, never on the aggregate score. Ten lows can drag a score below a threshold while one public database sits unremarked.

Where to spend the next two weeks
Current stateHighest-return moveWhy
No org-wide audit logging[PROVEN] Enable it to a separate account firstNothing else is provable without it; an attacker in the workload account can otherwise erase the evidence
Audit logging present, no guardrails[PROVEN] Deploy the four day-one denies: public storage, log tampering, detection tampering, region restrictionEach one permanently deletes a finding class instead of a finding
Guardrails present, static keys everywhere[RECOMMENDED] Migrate to workload identity federationStatic keys are the most commonly leaked credential and the hardest to rotate under pressure
Everything above done[RECOMMENDED] Data-plane logging on classified storesDecides whether a breach notification names 12 records or assumes all four million
Mature posture[EXPERIMENTAL] Just-in-time privilege elevationRemoves standing admin entirely; risk is that a broken elevation path blocks incident response, so keep an audited break-glass role
Preventive beats detective
LayerLatency to protectionUse for
Preventive (SCP / org policy / deny assignment)Instant, alwaysAny finding class seen three or more times
Proactive (policy-as-code in CI on the IaC plan)MinutesEverything expressible in Terraform, before merge
Detective (this skill's scanners, managed detection)Hours to daysBackstop for console changes and drift
Responsive (auto-remediation)Minutes to hoursOnly where the preventive control would be too blunt
Show full SKILL.md (680 more words)Show less

Anti-Patterns

Ranking findings by wildcard count

Mistake: The IAM review sorts by how many * characters appear in each policy, and the team spends a quarter tightening s3:* grants on single buckets. Why it happens: Wildcards are trivially greppable, so they become the metric, and tightening them produces a satisfying downward chart. Instead: Hunt privilege-escalation paths first. A tidy-looking policy with 40 scoped actions that happens to include iam:PassRole plus ec2:RunInstances is full account takeover; a sloppy s3:* on one non-sensitive bucket is not. iam_least_privilege.py reports escalation paths as critical for exactly this reason.

Treating the posture score as the gate

Mistake: The release check is "posture score above 80," so the team closes twenty low-severity tag findings to clear the bar. Why it happens: A single number is easy to put on a dashboard and easy to trend, and the low findings are genuinely the cheapest to close. Instead: Gate on critical count and on the specific finding classes that map to data exposure. Use the score only to trend across reviews of the same scope. The sample inventory here scores 0/100, and the number that matters is that five criticals include a publicly readable bucket of customer exports.

Remediating instances instead of writing the guardrail

Mistake: Each scan finds new public buckets; each one gets a ticket, gets fixed, and reappears next quarter from a different team. Why it happens: Ticketing an instance takes ten minutes and closing it feels like progress; writing an org policy requires a conversation with every team that might be blocked by it. Instead: The third time a finding class appears, stop remediating and write the preventive control. Public buckets found three times means account-level public access prevention is missing. Apply it to Dev for two weeks with a named exception path, then production.

Leaving the log archive inside the workload account

Mistake: CloudTrail or the diagnostic settings write to a bucket in the same account they monitor. Why it happens: It is the default when you enable logging from the console, and the separation looks like bureaucratic account sprawl. Instead: Put the log archive in a dedicated account with no workload administrators and write-only access from everywhere else. The entire value of audit logging is that it survives the compromise of the thing it audits — an attacker with account admin deletes in-account logs as step two, and your incident timeline starts and ends with "we do not know."

Scanning one region

Mistake: The export script runs against the default region and reports a clean account. Why it happens: Every provider CLI defaults to a single region, and the code that loops over regions is one more thing to write. Instead: Enumerate regions and export all of them, then apply a region-restriction guardrail so the surface stops growing. The forgotten test database in an unused region — unencrypted, unlogged, open to 0.0.0.0/0 because it was "just for a demo" — is the single most common origin of cloud incidents in organizations that otherwise scan diligently.

Files

FilePurpose
scripts/posture_auditor.pyAudits a normalized cloud inventory for public exposure, open ingress, unencrypted stores, missing logging, absent backups, and account guardrail gaps; severity-scored with provider-specific remediation
scripts/iam_least_privilege.pyReviews IAM principals for wildcard grants, privilege-escalation paths, over-broad trust, stale credentials, and missing MFA; ranks principals by risk with an effective-privilege tier
scripts/posture_rules.pyRule data behind the posture auditor — severity weights, sensitive-port and data-store vocabularies, account-level guardrail checks, and the provider-specific remediation catalog; --list-rules prints them
scripts/iam_rules.pyRule data behind the IAM review — severity weights, admin-grant and write-verb vocabularies, the privilege-escalation path catalog, and the policy-flattening and privilege-tier primitives; --list-rules prints them
references/cloud-control-catalog.mdControls mapped across AWS/Azure/GCP for identity, network, encryption, logging, and resilience, with passing thresholds and severity calibration
references/landing-zone-and-guardrails.mdAccount topology, preventive vs detective controls, the guardrail baseline per provider, and a five-level posture maturity model
assets/sample_inventory.jsonSeven-resource AWS inventory exercising every posture check
assets/sample_iam_export.jsonSix-principal IAM export containing escalation paths, wildcard trust, and stale credentials
assets/posture_review_template.mdReview report template structured around decisions rather than finding dumps
assets/inventory_export_guide.mdExport schemas, field semantics, per-provider collection commands, and export hygiene rules

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files (scripts, references, assets) in engineering/cloud-security of borghei/Claude-Skills.

  • SKILL.md
  • assets/inventory_export_guide.md
  • assets/posture_review_template.md
  • assets/sample_iam_export.json
  • assets/sample_inventory.json
  • references/cloud-control-catalog.md
  • references/landing-zone-and-guardrails.md
  • scripts/iam_least_privilege.py
  • scripts/iam_rules.py
  • scripts/posture_auditor.py
  • scripts/posture_rules.py

Open the folder on GitHubat commit c9a1487

Compare with similar skills

Cloud Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloud Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloud Security this skillborghei/Claude-Skills874—~3.5kAutomated safety check: PassMIT
Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Hardening Cloud Posturetrilwu/secskills156—~1.9kAutomated safety check: PassMIT
Cloud Auditbriiirussell/cybersecurity-skills412—~1.3kAutomated safety check: NotesMIT
Implementing Cloud Vulnerability Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0
Performing Cloud Incident Containment Proceduresmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0

Similar skills

  • Implementing Cloud Security Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hardening Cloud Posture

    trilwu/secskills

    Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…

    156 GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    412 GitHub stars~1.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Implementing Cloud Vulnerability Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Implement multi-cloud CSPM to detect cloud-native misconfigurations and vulnerabilities (IAM over-permissions, exposed storage, unencrypted data, missing network controls) using AWS Security Hub…

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Performing Cloud Incident Containment Procedures

    mukul975/Anthropic-Cybersecurity-Skills

    Execute cloud-native incident containment across AWS, Azure, and GCP using platform CLIs to revoke or disable compromised IAM credentials, isolate resources with security groups and network ACLs…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Auditing Cloud With Cis Benchmarks

    mukul975/Anthropic-Cybersecurity-Skills

    Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from borghei/Claude-Skills

All 364 skills in this repo
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    874 GitHub stars~4.2k tokensUpdated today
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    874 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    874 GitHub stars~3.6k tokensUpdated today
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    874 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    874 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Brainstorm Okrs

    borghei/Claude-Skills

    OKR brainstorming and validation using the Radical Focus framework — outcome objectives, measurable key results, counter-metrics.

    874 GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Categories

Questions about Cloud Security

What does Cloud Security do?

Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails. Cloud Security is an agent skill from borghei/Claude-Skills. Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails.

When should I use Cloud Security?

Cloud Security fits situations like: auditing a cloud account; before a production launch.

How do I install Cloud Security in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill cloud-security -a claude-code`. Or copy the skill folder (engineering/cloud-security in borghei/Claude-Skills) into .claude/skills/cloud-security in your project. Claude Code loads it when a task matches its description.

How do I install Cloud Security in Codex?

Run `npx skills add borghei/Claude-Skills --skill cloud-security -a codex`. Or copy the skill folder (engineering/cloud-security in borghei/Claude-Skills) into .agents/skills/cloud-security in your project. Codex loads it when a task matches its description.

Can I use Cloud Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill cloud-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-security, .gemini/skills/cloud-security, .github/skills/cloud-security and .opencode/skills/cloud-security in your project.

What does Cloud Security need to run?

Going by SKILL.md and its folder, Cloud Security needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Cloud Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cloud Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Cloud Security use?

Cloud Security is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloud Security use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.7k tokens, read only when the agent opens those files.

What are the alternatives to Cloud Security?

Skills that share tags, products or a category with Cloud Security: Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Hardening Cloud Posture (trilwu/secskills, 156 stars), Cloud Audit (briiirussell/cybersecurity-skills, 412 stars) and Implementing Cloud Vulnerability Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloud Security?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 874 GitHub stars. The repository holds 364 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.