Official agent skill

Securing S3 Buckets

by aws in aws/agent-toolkit-for-aws

Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations.

OfficialApache-2.0Auto-check passedBackend & APIs

Install Securing S3 Buckets

skills CLI
$ npx skills add aws/agent-toolkit-for-aws --skill securing-s3-buckets -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/agent-toolkit-for-aws securing-s3-buckets --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/storage-skills/securing-s3-buckets .claude/skills/securing-s3-buckets && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
securing-s3-buckets
GitHub stars
2.8k
Used in
1 other repo
Token cost
~2k tokens
SKILL.md length
817 words
Files
6 (incl. references)
Skills in repo
138
Repo updated
First seen
Licence
Apache-2.0

At a glance

Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations.

  • Works in 7 steps: Verify Dependencies → Classify the Request → Workflow A — Secure New Bucket → …
  • The user wants to secure a new bucket
  • SKILL.md covers Overview, Common Tasks, Troubleshooting and Additional Resources
  • Calls aws and python3

What it does

Securing S3 Buckets is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations. Use when the user wants to secure a new bucket, audit an existing bucket, fix a security finding, configure encryption, or enable logging and monitoring. Do NOT use for general S3 data operations, S3 Tables setup, or discovering existing data assets.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `references/audit-checklist.md`, `references/encryption.md` and `references/iam-permissions.md`).

It sits in Backend & APIs, covering File uploads and storage and Authorization and RBAC. It works with Amazon Web Services. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.

When your agent uses it

  • The user wants to secure a new bucket
  • Audit an existing bucket
  • Fix a security finding
  • Configure encryption

Example prompts

  • “/securing-s3-buckets”

Requirements

  • Python 3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Verify Dependencies
  2. Classify the Request
  3. Workflow A — Secure New Bucket
  4. Workflow B — Audit Existing Bucket
  5. Workflow C — Remediate Issue
  6. Workflow D — Configure Encryption
  7. Workflow E — Enable Monitoring

What it can do on your machine

Read from SKILL.md and the folder at commit 188af2f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Securing S3 Buckets loads about 2k tokens when it runs, and up to ~7.4k if it reads all its reference files. Until then it costs about 103 tokens; SKILL.md has 817 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/agent-toolkit-for-aws at commit 188af2f, republished under its Apache-2.0 licence (© aws). 817 words, ~1,951 tokens.

Download SKILL.mdSave it as .claude/skills/securing-s3-buckets/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
securing-s3-buckets
description
Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations. Use when the user wants to secure a new bucket, audit an existing bucket, fix a security finding, configure encryption, or enable logging and monitoring. Do NOT use for general S3 data operations, S3 Tables setup, or discovering existing data assets.
version
1

Overview

Implements layered S3 security controls across five workflows: securing new buckets, auditing existing configurations, remediating findings, configuring encryption, and enabling monitoring. Follows AWS Well-Architected security best practices.

Execute commands using the AWS MCP server when connected (sandboxed execution, audit logging, observability). Fall back to AWS CLI or shell otherwise.

Common Tasks

0. Verify Dependencies

Check for required tools before starting.

Constraints:

  • You MUST inform the user if required tools are missing
  • You SHOULD confirm credentials with aws sts get-caller-identity

See references/iam-permissions.md for IAM permissions by workflow.

1. Classify the Request
User intentWorkflow
Secure a new bucketA: Secure New Bucket
Audit / review existing bucketB: Audit Existing Bucket
Fix a specific findingC: Remediate Issue
Configure encryptionD: Configure Encryption
Enable logging / monitoringE: Enable Monitoring

Constraints:

  • You MUST ask for all required parameters upfront
  • You MUST confirm bucket name and region before any write operation
  • You MAY infer region from user context if clearly stated
  • You SHOULD run aws iam simulate-principal-policy to validate permissions before write operations
  • You SHOULD display write commands and wait for confirmation before executing
put-bucket-policy Safety Rules

These rules apply to ALL workflows that call put-bucket-policy:

  • You MUST attempt to retrieve the existing policy first (aws s3api get-bucket-policy) — put-bucket-policy replaces the entire policy
  • If a policy exists, you MUST back it up before modifying: aws s3api get-bucket-policy --bucket <name> --output text > backup-policy-$(date +%s).json
  • If NoSuchBucketPolicy is returned, proceed with a new policy — no backup is needed
  • You MUST merge new statements into the existing policy's Statement array (if one exists)
  • You MUST validate merged JSON syntax before applying (e.g. echo '<policy>' | python3 -m json.tool)
  • You SHOULD display the full put-bucket-policy command and wait for confirmation
2. Workflow A — Secure New Bucket

See references/workflows.md for full CLI steps.

Required steps (execute in order, do not skip):

  1. Create bucket with --bucket-namespace account-regional
  2. Enable versioning
  3. Enable encryption (SSE-S3 + Bucket Keys + block SSE-C)
  4. Enable logging (ask user which option — conditional)
  5. Enforce HTTPS-only via DenyInsecureTransport bucket policy
  6. Enable ABAC

Constraints:

  • You MUST pass --bucket-namespace account-regional on create-bucket call — this is REQUIRED, not optional. Example:

    aws s3api create-bucket --bucket <name> --bucket-namespace account-regional --region <region>
  • You MUST NOT change Block Public Access — S3 enables it by default on new buckets

  • You MUST NOT change ACL ownership controls — S3 disables ACLs (BucketOwnerEnforced) by default

  • You MUST apply a bucket policy with a DenyInsecureTransport statement that denies s3:* when aws:SecureTransport is false — this is REQUIRED, not optional. Example:

    aws s3api put-bucket-policy --bucket <name> --policy '{"Version":"2012-10-17","Statement":[{"Sid":"DenyInsecureTransport","Effect":"Deny","Principal":"*","Action":"s3:*","Resource":["arn:aws:s3:::<name>/*","arn:aws:s3:::<name>"],"Condition":{"Bool":{"aws:SecureTransport":"false"}}}]}'
  • You MUST ask the user which logging option they want before step 4

  • You MUST follow the put-bucket-policy safety rules for steps 4 and 5

  • You SHOULD confirm each step succeeded before proceeding

3. Workflow B — Audit Existing Bucket

See references/audit-checklist.md for the full checklist.

Constraints:

  • You MUST run all read-only audit commands before reporting findings
  • You MUST NOT execute any write or modify commands during an audit
  • You MUST report each control as PASS / FAIL / NOT CONFIGURED with severity
  • For logging: report PASS if either S3 server access logging OR CloudTrail data events are enabled; NOT CONFIGURED only if neither
Show full SKILL.md (313 more words)Show less
4. Workflow C — Remediate Issue

See references/remediation.md for fix commands by issue type.

Constraints:

  • You MUST identify the issue type before applying any fix
  • You MUST follow the put-bucket-policy safety rules when modifying policies
  • You MUST re-run the relevant audit check after applying the fix to confirm resolution
5. Workflow D — Configure Encryption

See references/encryption.md for encryption options and commands.

Constraints:

  • You MUST default to SSE-S3 with S3 Bucket Keys and SSE-C blocked unless the user explicitly requests KMS
  • When using SSE-KMS, you MUST use a customer managed key — NEVER the AWS managed aws/s3 key
  • You MUST specify customer-managed KMS keys by full ARN, not alias
  • You MUST include BucketKeyEnabled: true and BlockedEncryptionTypes: [SSE-C] in all configurations
  • Note: The S3 API accepts aws/s3 and aliases without error — agent-enforced constraints. Verify with get-bucket-encryption after applying.
6. Workflow E — Enable Monitoring

See references/workflows.md for full CLI steps.

Constraints:

  • You MUST check whether a GuardDuty detector already exists before creating one
  • You MUST use the trail's home region (not the bucket's region) for CloudTrail commands
  • You SHOULD enable all four core recommended AWS Config rules

Troubleshooting

ObjectLockConfigurationNotFoundError — Object Lock is not enabled. Treat as NOT CONFIGURED, not a failure.

AccessDenied on audit commands — Check IAM policy, bucket policy, Block Public Access, VPC endpoint policy, and SCPs/RCPs. Use aws iam simulate-principal-policy to diagnose.

put-bucket-policy silently removes existing statements — See put-bucket-policy safety rules.

GuardDuty BadRequestException: detector already exists — Run aws guardduty list-detectors first; only call create-detector if empty.

CloudTrail changes not taking effect — Verify you are using --region <trail-home-region>, not the bucket's region. Find it with aws cloudtrail describe-trails --query 'trailList[*].[Name,HomeRegion]'.

Additional Resources

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/specialized-skills/storage-skills/securing-s3-buckets of aws/agent-toolkit-for-aws.

  • SKILL.md
  • references/audit-checklist.md
  • references/encryption.md
  • references/iam-permissions.md
  • references/remediation.md
  • references/workflows.md

Open the folder on GitHubat commit 188af2f

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in aws/agent-toolkit-for-aws, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Securing S3 Buckets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Securing S3 Buckets compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Securing S3 Buckets this skillaws/agent-toolkit-for-aws2.8k1 repos~2kAutomated safety check: PassApache-2.0
S3itsmostafa/aws-agent-skills1.2k—~2.3kAutomated safety check: PassMIT
AWS Essentialsericrisco/rsc-harness167—~2.9kAutomated safety check: NotesMIT
FoundatioFoundatioFx/Foundatio2.1k—~3.9kAutomated safety check: PassApache-2.0
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
PhidownESA-PhiLab/phidown105—~1kAutomated safety check: PassApache-2.0

Similar skills

  • S3

    itsmostafa/aws-agent-skills

    AWS S3 object storage for bucket management, object operations, and access control.

    1.2k GitHub stars~2.3k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • AWS Essentials

    ericrisco/rsc-harness

    A skill your agent uses when standing up the core AWS surface a small product needs: hardening a fresh account, a private S3 bucket, encrypted RDS Postgres, ECS Fargate vs EC2, CloudFront + OAC, or…

    167 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Foundatio

    FoundatioFx/Foundatio

    A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.

    2.1k GitHub stars~3.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Phidown

    ESA-PhiLab/phidown

    Search, filter, download, and analyze Copernicus Data Space products with the phidown project.

    105 GitHub stars~1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Fftiers Ops

    borisachen/fftiers

    Operate the borischen.co fftiers pipeline — season rollover, run main.R, S3 deploy from Workbench or EC2.

    202 GitHub stars~1.8k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: warnings

More from aws/agent-toolkit-for-aws

All 138 skills in this repo
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Agents Build

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.

    2.8k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Launch With AWS

    aws/agent-toolkit-for-aws

    Official

    Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated today
    Auto-check passed
  • Agents Pay

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.

    2.8k GitHub stars~6.5k tokensUpdated today
    Auto-check: notes

Categories

Questions about Securing S3 Buckets

What does Securing S3 Buckets do?

Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations. Securing S3 Buckets is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations.

When should I use Securing S3 Buckets?

Securing S3 Buckets fits situations like: the user wants to secure a new bucket; audit an existing bucket; fix a security finding; configure encryption.

How do I install Securing S3 Buckets in Claude Code?

Run `npx skills add aws/agent-toolkit-for-aws --skill securing-s3-buckets -a claude-code`. Or copy the skill folder (skills/specialized-skills/storage-skills/securing-s3-buckets in aws/agent-toolkit-for-aws) into .claude/skills/securing-s3-buckets in your project. Claude Code loads it when a task matches its description.

How do I install Securing S3 Buckets in Codex?

Run `npx skills add aws/agent-toolkit-for-aws --skill securing-s3-buckets -a codex`. Or copy the skill folder (skills/specialized-skills/storage-skills/securing-s3-buckets in aws/agent-toolkit-for-aws) into .agents/skills/securing-s3-buckets in your project. Codex loads it when a task matches its description.

Can I use Securing S3 Buckets in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill securing-s3-buckets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/securing-s3-buckets, .gemini/skills/securing-s3-buckets, .github/skills/securing-s3-buckets and .opencode/skills/securing-s3-buckets in your project.

What does Securing S3 Buckets need to run?

Going by SKILL.md and its folder, Securing S3 Buckets needs the command-line tools its instructions call (aws and python3). Our summary lists: Python 3.

Does Securing S3 Buckets access the network?

SKILL.md names 1 domain. As links in the text: docs.aws.amazon.com. This is read from the text; nothing was executed.

Is Securing S3 Buckets safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Securing S3 Buckets use?

Securing S3 Buckets is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Securing S3 Buckets use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.5k tokens, read only when the agent opens those files.

What are the alternatives to Securing S3 Buckets?

Skills that share tags, products or a category with Securing S3 Buckets: S3 (itsmostafa/aws-agent-skills, 1.2k stars), AWS Essentials (ericrisco/rsc-harness, 167 stars), Foundatio (FoundatioFx/Foundatio, 2.1k stars) and Cognito (itsmostafa/aws-agent-skills, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Securing S3 Buckets?

aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,825 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.

Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.