Build IAM from scratch — roles, policies, service accounts with least privilege.

MITAuto-check: notesDevOps & Cloud

Install Warden Iam

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-iam -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace warden-iam --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ai-agency/tonone/skills/warden-iam .claude/skills/warden-iam && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
warden-iam
GitHub stars
2.8k
Token cost
~987 tokens
SKILL.md length
401 words
Files
2
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Build IAM from scratch — roles, policies, service accounts with least privilege.

  • Works in 6 steps: Detect Environment → Map Services and Access Needs → Design Roles with Least Privilege → …
  • Asked to set up IAM
  • SKILL.md covers Steps and Delivery
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Warden Iam is an agent skill from jeremylongshore/tons-of-skills-marketplace. Build IAM from scratch — roles, policies, service accounts with least privilege. Use when asked to "set up IAM", "create roles", "service accounts", or "access control".

Its SKILL.md is about 990 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `.claude-plugin/plugin.json`).

It sits in DevOps & Cloud, covering Authorization and RBAC and Infrastructure as code. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Asked to set up IAM
  • Service accounts

Example prompts

  • “set up IAM”
  • “create roles”
  • “service accounts”
  • “/warden-iam”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash, Glob, Grep, WebFetch, WebSearch, Task, TodoWrite, AskUserQuestion

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Detect Environment
  2. Map Services and Access Needs
  3. Design Roles with Least Privilege
  4. Generate IaC
  5. Add Guardrails
  6. Present the IAM Design

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash
    • Glob
    • Grep
    • WebFetch
    • WebSearch
    • Task
    • TodoWrite

    …and 1 more on the same allowed-tools line.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Warden Iam loads about 987 tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 401 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~987

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Bash, Glob, Grep, WebFetch, WebSearch, Task, TodoWrite, AskUserQuestion

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 401 words, ~987 tokens.

Download SKILL.mdSave it as .claude/skills/warden-iam/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
warden-iam
description
Build IAM from scratch — roles, policies, service accounts with least privilege. Use when asked to "set up IAM", "create roles", "service accounts", or "access control".
allowed-tools
Read, Write, Edit, Bash, Glob, Grep, WebFetch, WebSearch, Task, TodoWrite, AskUserQuestion
version
0.6.4
author
tonone-ai <hello@tonone.ai>
license
MIT

Build IAM from Scratch

You are Warden — the security engineer on the Engineering Team.

Steps

Step 0: Detect Environment

Identify the cloud platform and IaC tooling:

  • Check for cloud platform: gcloud configs, AWS configs, Azure configs, Terraform files, Pulumi files
  • Check for existing IAM: service accounts, roles, policies already defined
  • Check for IaC: *.tf (Terraform), Pulumi.*, CloudFormation templates, gcloud scripts
  • Check for services: what services exist in the project? (APIs, workers, databases, storage)
  • Identify the deployment model (Kubernetes, Cloud Run, Lambda, EC2, etc.)

If the stack is ambiguous, ask the user.

Step 1: Map Services and Access Needs

Understand what exists and who needs access to what:

  • Services — list every service/component in the system
  • Resources — what does each service need to access? (databases, storage, queues, APIs, secrets)
  • Human access — who needs access to what? (developers, ops, CI/CD)
  • Cross-service communication — which services talk to each other?

Build an access matrix:

Service/UserResourceAccess Needed
[service][resource][read/write/admin]
Step 2: Design Roles with Least Privilege

Design roles following these principles:

  • No wildcards — never * for resources or actions
  • No admin-by-default — start with zero permissions and add what is needed
  • One service account per service — never share service accounts across services
  • Scope to exactly what is needed — if a service only reads from a bucket, it gets storage.objects.get, not storage.admin
  • Prefer predefined roles where they match (e.g., roles/cloudsql.client instead of custom)
  • Custom roles only when predefined roles are too broad
Show full SKILL.md (165 more words)Show less
Step 3: Generate IaC

Generate infrastructure-as-code for the complete IAM setup:

  • Service accounts — one per service, with descriptive names
  • Custom roles — if predefined roles are too permissive
  • Policy bindings — connect service accounts to roles, scoped to specific resources
  • Workload identity — if running on Kubernetes, bind K8s service accounts to cloud IAM

Use the project's IaC tool (Terraform, Pulumi, gcloud commands, CloudFormation). If no IaC exists, use Terraform as the default.

Step 4: Add Guardrails
  • Organization policies — prevent public access, enforce encryption, restrict regions
  • Audit logging — enable on all sensitive resources
  • Alerts — notify on privilege escalation, new admin grants, service account key creation
Step 5: Present the IAM Design

Follow the output format defined in docs/output-kit.md — 40-line CLI max, box-drawing skeleton, unified severity indicators, compressed prose.

## IAM Design

### Service Accounts
| Service Account | Service | Permissions |
|---|---|---|
| [sa-name] | [service] | [roles/permissions] |

### Custom Roles (if any)
| Role | Permissions | Rationale |
|---|---|---|
| [role] | [permissions] | [why predefined wasn't sufficient] |

### Human Access
| Group | Role | Scope |
|---|---|---|
| [group] | [role] | [project/resource] |

### Guardrails
- [policy or alert] — [what it prevents/detects]

### Files Generated
- [file] — [what it contains]

Delivery

If output exceeds the 40-line CLI budget, invoke /atlas-report with the full findings. The HTML report is the output. CLI is the receipt — box header, one-line verdict, top 3 findings, and the report path. Never dump analysis to CLI.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugins/ai-agency/tonone/skills/warden-iam of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • .claude-plugin/plugin.json

Open the folder on GitHubat commit cfae287

Compare with similar skills

Warden Iam next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Warden Iam compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Warden Iam this skilljeremylongshore/tons-of-skills-marketplace2.8k—~987Automated safety check: NotesMIT
Admingrafana/skills282—~1.5kAutomated safety check: PassApache-2.0
Azure Validatemicrosoft/GitHub-Copilot-for-Azure2551 repos~880Automated safety check: PassMIT
AWS Iamaws/agent-toolkit-for-aws2.8k1 repos~1.7kAutomated safety check: PassApache-2.0
Azure EnclaveMicrosoftDocs/Agent-Skills776—~2.7kAutomated safety check: PassCC-BY-4.0
Azure Firmware AnalysisMicrosoftDocs/Agent-Skills776—~1.2kAutomated safety check: PassCC-BY-4.0

Similar skills

  • Admin

    grafana/skills

    Official

    Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning.

    282 GitHub stars~1.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Azure Validate

    microsoft/GitHub-Copilot-for-Azure

    Official

    Pre-deployment validation for Azure readiness. An agent skill from microsoft/GitHub-Copilot-for-Azure.

    255 GitHub starsUsed in 1 repo~880 tokens
    DevOps & CloudAuto-check passed
  • AWS Iam

    aws/agent-toolkit-for-aws

    Official

    Provides verified corrections for IAM behaviors that AI agents frequently get wrong — policy evaluation edge cases, trust policy gotchas, STS session limits, Organizations quirks, and SAML/MFA…

    2.8k GitHub starsUsed in 1 repo~1.7k tokens
    DevOps & CloudAuto-check passed
  • Azure Enclave

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Enclave development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, and deployment.

    776 GitHub stars~2.7k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Azure Firmware Analysis

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Firmware Analysis development including best practices, security, integrations & coding patterns, and deployment.

    776 GitHub stars~1.2k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Code Review

    Azure/sap-automation

    Official

    Review pull requests in the SAP Deployment Automation Framework.

    146 GitHub stars~7k tokensUpdated 2 days ago
    DevelopmentAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Categories

Questions about Warden Iam

What does Warden Iam do?

Build IAM from scratch — roles, policies, service accounts with least privilege. Warden Iam is an agent skill from jeremylongshore/tons-of-skills-marketplace. Build IAM from scratch — roles, policies, service accounts with least privilege.

When should I use Warden Iam?

Warden Iam fits situations like: asked to set up IAM; service accounts.

How do I install Warden Iam in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-iam -a claude-code`. Or copy the skill folder (plugins/ai-agency/tonone/skills/warden-iam in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/warden-iam in your project. Claude Code loads it when a task matches its description.

How do I install Warden Iam in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-iam -a codex`. Or copy the skill folder (plugins/ai-agency/tonone/skills/warden-iam in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/warden-iam in your project. Codex loads it when a task matches its description.

Can I use Warden Iam in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill warden-iam -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/warden-iam, .gemini/skills/warden-iam, .github/skills/warden-iam and .opencode/skills/warden-iam in your project.

What does Warden Iam need to run?

SKILL.md names no scripts, command-line tools or credentials: Warden Iam is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Glob, Grep, WebFetch, WebSearch, Task, TodoWrite, AskUserQuestion.

Does Warden Iam access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Warden Iam safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Warden Iam use?

Warden Iam is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Warden Iam use?

About 987 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Warden Iam?

Skills that share tags, products or a category with Warden Iam: Admin (grafana/skills, 282 stars), Azure Validate (microsoft/GitHub-Copilot-for-Azure, 255 stars), AWS Iam (aws/agent-toolkit-for-aws, 2.8k stars) and Azure Enclave (MicrosoftDocs/Agent-Skills, 776 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Warden Iam?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.