AWS Identity and Access Management for users, roles, policies, and permissions.

MITAuto-check passedSecurity

Install Iam

skills CLI
$ npx skills add itsmostafa/aws-agent-skills --skill iam -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install itsmostafa/aws-agent-skills iam --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/iam .claude/skills/iam && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
iam
GitHub stars
1.2k
Token cost
~1.8k tokens
SKILL.md length
475 words
Files
3
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

AWS Identity and Access Management for users, roles, policies, and permissions.

  • Works in 5 steps: Verify identity: aws sts… → Check attached policies: aws iam… → Simulate the action → …
  • Creating IAM policies
  • SKILL.md covers Table of Contents, Core Concepts, Common Patterns and CLI Reference, plus 3 more sections
  • Calls aws

What it does

Iam is an agent skill from itsmostafa/aws-agent-skills. AWS Identity and Access Management for users, roles, policies, and permissions. Use when creating IAM policies, configuring cross-account access, setting up service roles, troubleshooting permission errors, or managing access control.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `best-practices.md` and `policies.md`).

It sits in Security, covering Cloud security and Authorization and RBAC. It works with Amazon Web Services. The repository describes itself as: AWS Skills for Agents. The licence is MIT.

When your agent uses it

  • Creating IAM policies
  • Configuring cross-account access
  • Setting up service roles
  • Troubleshooting permission errors

Example prompts

  • “/iam”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Verify identity: aws sts get-caller-identity
  2. Check attached policies: aws iam list-attached-role-policies --role-name MyRole
  3. Simulate the action
  4. Check for explicit denies in SCPs or permission boundaries
  5. Verify resource-based policies allow the principal

What it can do on your machine

Read from SKILL.md and the folder at commit e786d25. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com
    • boto3.amazonaws.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Iam loads about 1.8k tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 475 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from itsmostafa/aws-agent-skills at commit e786d25, republished under its MIT licence (© itsmostafa). 475 words, ~1,768 tokens.

Download SKILL.mdSave it as .claude/skills/iam/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
iam
description
AWS Identity and Access Management for users, roles, policies, and permissions. Use when creating IAM policies, configuring cross-account access, setting up service roles, troubleshooting permission errors, or managing access control.
last_updated
2026-01-07
doc_source
https://docs.aws.amazon.com/IAM/latest/UserGuide/

AWS IAM

AWS Identity and Access Management (IAM) enables secure access control to AWS services and resources. IAM is foundational to AWS security—every AWS API call is authenticated and authorized through IAM.

Table of Contents

Core Concepts

Principals

Entities that can make requests to AWS: IAM users, roles, federated users, and applications.

Policies

JSON documents defining permissions. Types:

  • Identity-based: Attached to users, groups, or roles
  • Resource-based: Attached to resources (S3 buckets, SQS queues)
  • Permission boundaries: Maximum permissions an identity can have
  • Service control policies (SCPs): Organization-wide limits
Roles

Identities with permissions that can be assumed by trusted entities. No permanent credentials—uses temporary security tokens.

Trust Relationships

Define which principals can assume a role. Configured via the role's trust policy.

Common Patterns

Create a Service Role for Lambda

AWS CLI:

bash
# Create the trust policy
cat > trust-policy.json << 'EOF'
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": { "Service": "lambda.amazonaws.com" },
      "Action": "sts:AssumeRole"
    }
  ]
}
EOF

# Create the role
aws iam create-role \
  --role-name MyLambdaRole \
  --assume-role-policy-document file://trust-policy.json

# Attach a managed policy
aws iam attach-role-policy \
  --role-name MyLambdaRole \
  --policy-arn arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole

boto3:

python
import boto3
import json

iam = boto3.client('iam')

trust_policy = {
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {"Service": "lambda.amazonaws.com"},
            "Action": "sts:AssumeRole"
        }
    ]
}

# Create role
iam.create_role(
    RoleName='MyLambdaRole',
    AssumeRolePolicyDocument=json.dumps(trust_policy)
)

# Attach managed policy
iam.attach_role_policy(
    RoleName='MyLambdaRole',
    PolicyArn='arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole'
)
Create Custom Policy with Least Privilege
bash
cat > policy.json << 'EOF'
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "dynamodb:GetItem",
        "dynamodb:PutItem",
        "dynamodb:Query"
      ],
      "Resource": "arn:aws:dynamodb:us-east-1:123456789012:table/MyTable"
    }
  ]
}
EOF

aws iam create-policy \
  --policy-name MyDynamoDBPolicy \
  --policy-document file://policy.json
Cross-Account Role Assumption
bash
# In Account B (trusted account), create role with trust for Account A
cat > cross-account-trust.json << 'EOF'
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": { "AWS": "arn:aws:iam::111111111111:root" },
      "Action": "sts:AssumeRole",
      "Condition": {
        "StringEquals": { "sts:ExternalId": "unique-external-id" }
      }
    }
  ]
}
EOF

# From Account A, assume the role
aws sts assume-role \
  --role-arn arn:aws:iam::222222222222:role/CrossAccountRole \
  --role-session-name MySession \
  --external-id unique-external-id

CLI Reference

Essential Commands
CommandDescription
aws iam create-roleCreate a new IAM role
aws iam create-policyCreate a customer managed policy
aws iam attach-role-policyAttach a managed policy to a role
aws iam put-role-policyAdd an inline policy to a role
aws iam get-roleGet role details
aws iam list-rolesList all roles
aws iam simulate-principal-policyTest policy permissions
aws sts assume-roleAssume a role and get temporary credentials
aws sts get-caller-identityGet current identity
Useful Flags
  • --query: Filter output with JMESPath
  • --output table: Human-readable output
  • --no-cli-pager: Disable pager for scripting

Best Practices

Security
  • Never use root account for daily tasks
  • Enable MFA for all human users
  • Use roles instead of long-term access keys
  • Apply least privilege — grant only required permissions
  • Use conditions to restrict access by IP, time, or MFA
  • Rotate credentials regularly
  • Use permission boundaries for delegated administration
Show full SKILL.md (195 more words)Show less
Policy Design
  • Start with AWS managed policies, customize as needed
  • Use policy variables (${aws:username}) for dynamic policies
  • Prefer explicit denies for sensitive actions
  • Group related permissions logically
Monitoring
  • Enable CloudTrail for API auditing
  • Use IAM Access Analyzer to identify overly permissive policies
  • Review credential reports regularly
  • Set up alerts for root account usage

Troubleshooting

Access Denied Errors

Symptom: AccessDeniedException or UnauthorizedAccess

Debug steps:

  1. Verify identity: aws sts get-caller-identity
  2. Check attached policies: aws iam list-attached-role-policies --role-name MyRole
  3. Simulate the action:
    bash
    aws iam simulate-principal-policy \
      --policy-source-arn arn:aws:iam::123456789012:role/MyRole \
      --action-names dynamodb:GetItem \
      --resource-arns arn:aws:dynamodb:us-east-1:123456789012:table/MyTable
  4. Check for explicit denies in SCPs or permission boundaries
  5. Verify resource-based policies allow the principal
Role Cannot Be Assumed

Symptom: AccessDenied when calling AssumeRole

Causes:

  • Trust policy doesn't include the calling principal
  • Missing sts:AssumeRole permission on the caller
  • ExternalId mismatch (for cross-account roles)
  • Session duration exceeds maximum

Fix: Review and update the role's trust relationship.

Policy Size Limits
  • Managed policy: 6,144 characters
  • Inline policy: 2,048 characters (user), 10,240 characters (role/group)
  • Trust policy: 2,048 characters

Solution: Use multiple policies, reference resources by prefix/wildcard, or use tags-based access control.

References

© itsmostafa, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in skills/iam of itsmostafa/aws-agent-skills.

  • SKILL.md
  • best-practices.md
  • policies.md

Open the folder on GitHubat commit e786d25

Compare with similar skills

Iam next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Iam compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Iam this skillitsmostafa/aws-agent-skills1.2k—~1.8kAutomated safety check: PassMIT
AWS Essentialsericrisco/rsc-harness167—~2.9kAutomated safety check: NotesMIT
Cloud Auditbriiirussell/cybersecurity-skills413—~1.3kAutomated safety check: NotesMIT
AWS Security ArchitectureHack23/cia239—~2.3kAutomated safety check: PassApache-2.0
AWS Iamsickn33/agentic-awesome-skills47k2 repos~3.4kAutomated safety check: PassMIT
Container Securityhardw00t/ai-security-arsenal104—~2.8kAutomated safety check: PassNone

Similar skills

  • AWS Essentials

    ericrisco/rsc-harness

    A skill your agent uses when standing up the core AWS surface a small product needs: hardening a fresh account, a private S3 bucket, encrypted RDS Postgres, ECS Fargate vs EC2, CloudFront + OAC, or…

    167 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated today
    SecurityAuto-check passed
  • AWS Iam

    sickn33/agentic-awesome-skills

    Manage IAM users, roles, and policies. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.4k tokens
    SecurityAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • Auditing Cloud With Cis Benchmarks

    mukul975/Anthropic-Cybersecurity-Skills

    Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from itsmostafa/aws-agent-skills

All 17 skills in this repo
  • API Gateway

    itsmostafa/aws-agent-skills

    AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Bedrock

    itsmostafa/aws-agent-skills

    AWS Bedrock foundation models for generative AI. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Ecs

    itsmostafa/aws-agent-skills

    AWS ECS container orchestration for running Docker containers.

    1.2k GitHub starsUsed in 1 repo~4.7k tokens
    Auto-check passed
  • Cloudformation

    itsmostafa/aws-agent-skills

    AWS CloudFormation infrastructure as code for stack management.

    1.2k GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Cloudwatch

    itsmostafa/aws-agent-skills

    AWS CloudWatch monitoring for logs, metrics, alarms, and dashboards.

    1.2k GitHub stars~3.5k tokensUpdated 2 days ago
    Auto-check passed

Questions about Iam

What does Iam do?

AWS Identity and Access Management for users, roles, policies, and permissions. Iam is an agent skill from itsmostafa/aws-agent-skills. AWS Identity and Access Management for users, roles, policies, and permissions.

When should I use Iam?

Iam fits situations like: creating IAM policies; configuring cross-account access; setting up service roles; troubleshooting permission errors.

How do I install Iam in Claude Code?

Run `npx skills add itsmostafa/aws-agent-skills --skill iam -a claude-code`. Or copy the skill folder (skills/iam in itsmostafa/aws-agent-skills) into .claude/skills/iam in your project. Claude Code loads it when a task matches its description.

How do I install Iam in Codex?

Run `npx skills add itsmostafa/aws-agent-skills --skill iam -a codex`. Or copy the skill folder (skills/iam in itsmostafa/aws-agent-skills) into .agents/skills/iam in your project. Codex loads it when a task matches its description.

Can I use Iam in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add itsmostafa/aws-agent-skills --skill iam -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/iam, .gemini/skills/iam, .github/skills/iam and .opencode/skills/iam in your project.

What does Iam need to run?

Going by SKILL.md and its folder, Iam needs the command-line tools its instructions call (aws). Our summary lists: Python 3.

Does Iam access the network?

SKILL.md names 2 domains. As links in the text: docs.aws.amazon.com and boto3.amazonaws.com. This is read from the text; nothing was executed.

Is Iam safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Iam use?

Iam is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Iam use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Iam?

Skills that share tags, products or a category with Iam: AWS Essentials (ericrisco/rsc-harness, 167 stars), Cloud Audit (briiirussell/cybersecurity-skills, 413 stars), AWS Security Architecture (Hack23/cia, 239 stars) and AWS Iam (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Iam?

itsmostafa (a GitHub user) maintains it in itsmostafa/aws-agent-skills, which has 1,161 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 5, 2026.

Source: itsmostafa/aws-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.