Eks Security
aws-samples/appmod-blueprints
A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…
AWS compliance commands in Atmos: atmos aws compliance report, Security Hub standards, CIS AWS, PCI DSS, SOC2, HIPAA, NIST, report formats, AI summaries
$ npx skills add cloudposse/atmos --skill atmos-aws-compliance -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cloudposse/atmos atmos-aws-compliance --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-skills/skills/atmos-aws-compliance .claude/skills/atmos-aws-compliance && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "atmos-aws-compliance" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-aws-compliance into .claude/skills/atmos-aws-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-aws-compliance", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-aws-complianceType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cloudposse/atmos --skill atmos-aws-compliance -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cloudposse/atmos atmos-aws-compliance --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agent-skills/skills/atmos-aws-compliance .agents/skills/atmos-aws-compliance && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "atmos-aws-compliance" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-aws-compliance into .agents/skills/atmos-aws-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-aws-compliance", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cloudposse/atmos --skill atmos-aws-compliance -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cloudposse/atmos atmos-aws-compliance --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agent-skills/skills/atmos-aws-compliance .cursor/skills/atmos-aws-compliance && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "atmos-aws-compliance" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-aws-compliance into .cursor/skills/atmos-aws-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-aws-compliance", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cloudposse/atmos.git --path agent-skills/skills/atmos-aws-compliance--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cloudposse/atmos --skill atmos-aws-compliance -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cloudposse/atmos atmos-aws-compliance --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agent-skills/skills/atmos-aws-compliance .gemini/skills/atmos-aws-compliance && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "atmos-aws-compliance" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-aws-compliance into .gemini/skills/atmos-aws-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-aws-compliance", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cloudposse/atmos atmos-aws-complianceInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cloudposse/atmos --skill atmos-aws-compliance -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .github/skills && cp -r skills-src/agent-skills/skills/atmos-aws-compliance .github/skills/atmos-aws-compliance && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "atmos-aws-compliance" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-aws-compliance into .github/skills/atmos-aws-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-aws-compliance", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cloudposse/atmos --skill atmos-aws-compliance -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cloudposse/atmos atmos-aws-compliance --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agent-skills/skills/atmos-aws-compliance .opencode/skills/atmos-aws-compliance && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "atmos-aws-compliance" agent skill from https://github.com/cloudposse/atmos/tree/main/agent-skills/skills/atmos-aws-compliance into .opencode/skills/atmos-aws-compliance/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "atmos-aws-compliance", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
atmos-aws-complianceAWS compliance commands in Atmos: atmos aws compliance report, Security Hub standards, CIS AWS, PCI DSS, SOC2, HIPAA, NIST, report formats, AI summaries
Atmos AWS Compliance is an agent skill from cloudposse/atmos. AWS compliance commands in Atmos: atmos aws compliance report, Security Hub standards, CIS AWS, PCI DSS, SOC2, HIPAA, NIST, report formats, AI summaries
Its SKILL.md is about 680 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Legal & Compliance, covering Healthcare and finance regulation and SOC 2 and security compliance. It works with Amazon Web Services. The repository describes itself as: Atmos is the open-source runtime for infrastructure — it builds, authenticates, and ships Terraform, OpenTofu, Packer, Ansible, Kubernetes, Helm, and containers the same way on… The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 110e139. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and yaml).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Atmos AWS Compliance loads about 679 tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 246 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cloudposse/atmos at commit 110e139, republished under its Apache-2.0 licence (© cloudposse). 246 words, ~679 tokens.
.claude/skills/atmos-aws-compliance/SKILL.md (or your agent's skills folder).Use this skill for compliance posture reporting through AWS Security Hub. It owns
atmos aws compliance report.
atmos aws compliance report retrieves enabled Security Hub standard controls, maps failing
controls to Atmos stacks/components where possible, and writes reports for humans or automation.
atmos aws compliance report --framework cis-aws --stack prod-us-east-1
atmos aws compliance report --framework pci-dss --format json --file compliance.json
atmos aws compliance report --controls CIS.1.1,CIS.1.2 --format markdown
atmos aws compliance report --aiSupported report formats are markdown, json, yaml, and csv.
Configure defaults in atmos.yaml under aws.security. Route identity setup to atmos-auth.
aws:
security:
enabled: true
identity: security-readonly
region: us-east-2
frameworks:
- cis-aws
- pci-dssUse --identity to override the configured identity for a run.
| Framework | Use |
|---|---|
cis-aws | CIS AWS Foundations Benchmark |
pci-dss | Payment Card Industry Data Security Standard |
soc2 | SOC 2 trust service criteria |
hipaa | HIPAA controls for protected health information |
nist | NIST 800-53 controls |
--framework for targeted checks. Omit it only when the user explicitly wants all enabled
frameworks.--stack when the report should map compliance status to a specific Atmos stack.--format json or --format yaml for automation and CI gates; use markdown for human
reports.--file for durable artifacts. Parent directories are created by the command.--ai only when the user asks for AI-generated summary or remediation guidance.atmos-aws-security.| Need | Skill |
|---|---|
| Detailed security finding analysis and remediation format | atmos-aws-security |
| AWS identity/provider setup, SSO, SAML, OIDC, assume role/root | atmos-auth |
AI provider setup for --ai summaries | atmos-ai |
| Stack/component lookup before remediation | atmos-introspection, atmos-components |
© cloudposse, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agent-skills/skills/atmos-aws-compliance of cloudposse/atmos.
Open the folder on GitHubat commit 110e139
Atmos AWS Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Atmos AWS Compliance this skillcloudposse/atmos | 1.4k | — | ~679 | Automated safety check: Pass | Apache-2.0 | |
| Eks Securityaws-samples/appmod-blueprints | 115 | — | ~4.7k | Automated safety check: Pass | MIT-0 | |
| AWS Compliance Checkeraiskillstore/marketplace | 433 | 4 repos | ~3.7k | Automated safety check: Pass | None | |
| Implementing AWS Security Hubmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Grc Knowledgemlunato47/claude-grc-plugin | 184 | — | ~6.1k | Automated safety check: Pass | MIT |
aws-samples/appmod-blueprints
A skill your agent uses whenever someone needs security or compliance guidance for Amazon EKS — phrased as "CIS Benchmark for EKS", "HIPAA / PCI-DSS / FedRAMP / SOC 2 / GDPR on EKS", "harden my EKS…
aiskillstore/marketplace
Automated compliance checking against CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks
mukul975/Anthropic-Cybersecurity-Skills
Deploy AWS Security Hub as a centralized CSPM platform, backed by AWS Config, aggregating findings from GuardDuty, Inspector, Macie, and third-party tools; enable CIS Foundations, PCI-DSS, and NIST…
mukul975/Anthropic-Cybersecurity-Skills
Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…
mlunato47/claude-grc-plugin
Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…
GRCEngClub/claude-grc-engineering
Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.
cloudposse/atmos
A skill your agent uses when implementing, finishing, documenting, or reviewing a fix, repair, remediation, bug fix, debug-and-fix task, workflow fix, infrastructure fix, or any change that should…
cloudposse/atmos
Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings.
cloudposse/atmos
Blog post authoring for Atmos: MDX template, frontmatter, website/blog/tags.yml and authors.yml rules, problem-first framing, backtick-opening ban, optional cast embeds, and no-Go-internals leakage.
cloudposse/atmos
Decide whether a PR's new or changed default needs edition-journal handling (pkg/edition, docs/prd/editions.md), and do the mechanical work if so: journal entries, the four-layer default check…
cloudposse/atmos
Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…
cloudposse/atmos
Start an hourly background loop that keeps the current branch's PR rebased, its addressed CodeRabbit threads resolved, its CI checks passing, its lint clean, its tests passing with adequate patch…
Works with
Categories
AWS compliance commands in Atmos: atmos aws compliance report, Security Hub standards, CIS AWS, PCI DSS, SOC2, HIPAA, NIST, report formats, AI summaries. Atmos AWS Compliance is an agent skill from cloudposse/atmos.
Atmos AWS Compliance fits situations like: tasks that involve Healthcare and finance regulation; tasks that involve SOC 2 and security compliance.
Run `npx skills add cloudposse/atmos --skill atmos-aws-compliance -a claude-code`. Or copy the skill folder (agent-skills/skills/atmos-aws-compliance in cloudposse/atmos) into .claude/skills/atmos-aws-compliance in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cloudposse/atmos --skill atmos-aws-compliance -a codex`. Or copy the skill folder (agent-skills/skills/atmos-aws-compliance in cloudposse/atmos) into .agents/skills/atmos-aws-compliance in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cloudposse/atmos --skill atmos-aws-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/atmos-aws-compliance, .gemini/skills/atmos-aws-compliance, .github/skills/atmos-aws-compliance and .opencode/skills/atmos-aws-compliance in your project.
SKILL.md names no scripts, command-line tools or credentials: Atmos AWS Compliance is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Atmos AWS Compliance is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 679 tokens (SKILL.md is roughly 2.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Atmos AWS Compliance: Eks Security (aws-samples/appmod-blueprints, 115 stars), AWS Compliance Checker (aiskillstore/marketplace, 433 stars), Implementing AWS Security Hub (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cloudposse (a GitHub organization) maintains it in cloudposse/atmos, which has 1,398 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on October 10, 2026.
Source: cloudposse/atmos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.