Agent skill

Detecting S3 Data Exfiltration Attempts

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify…

Apache-2.0Auto-check passedBackend & APIs

Install Detecting S3 Data Exfiltration Attempts

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-s3-data-exfiltration-attempts -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-s3-data-exfiltration-attempts --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/detecting-s3-data-exfiltration-attempts .claude/skills/detecting-s3-data-exfiltration-attempts && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detecting-s3-data-exfiltration-attempts
GitHub stars
34k
Token cost
~3.1k tokens
SKILL.md length
626 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify…

  • Works in 6 steps: Enable S3 Data Event Logging in CloudTrail → Query CloudTrail for Anomalous S3 Access… → Review GuardDuty S3 Findings → …
  • Tasks that involve File uploads and storage
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls aws

What it does

Detecting S3 Data Exfiltration Attempts is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Backend & APIs, covering File uploads and storage. It works with Amazon S3. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve File uploads and storage

Example prompts

  • “/detecting-s3-data-exfiltration-attempts”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Enable S3 Data Event Logging in CloudTrail
  2. Query CloudTrail for Anomalous S3 Access Patterns
  3. Review GuardDuty S3 Findings
  4. Analyze Macie Findings for Sensitive Data Access
  5. Build Automated Detection Rules
  6. Implement Preventive Controls

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Detecting S3 Data Exfiltration Attempts loads about 3.1k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 72 tokens; SKILL.md has 626 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 626 words, ~3,131 tokens.

Download SKILL.mdSave it as .claude/skills/detecting-s3-data-exfiltration-attempts/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
detecting-s3-data-exfiltration-attempts
description
Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.
domain
cybersecurity
subdomain
cloud-security
tags
cloud-security, aws, s3, data-exfiltration, guardduty, macie, threat-detection
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, ID.AM-08, GV.SC-06, DE.CM-01
mitre_attack
T1530, T1567.002, T1537, T1119

Detecting S3 Data Exfiltration Attempts

When to Use

  • When GuardDuty detects anomalous S3 access patterns such as bulk downloads from unusual IPs
  • When investigating suspected data breach involving S3-stored sensitive data
  • When building detection rules for S3 data loss prevention monitoring
  • When responding to Macie alerts about sensitive data being accessed or moved
  • When compliance requires monitoring and logging of all access to classified data stores

Do not use for preventing data exfiltration (use S3 bucket policies, VPC endpoints, and SCPs), for data classification (use Amazon Macie discovery jobs), or for network-level exfiltration detection (use VPC Flow Logs with network analysis tools).

Prerequisites

  • CloudTrail configured with S3 data event logging (GetObject, PutObject, CopyObject)
  • GuardDuty enabled with S3 Protection feature activated
  • Amazon Macie enabled for sensitive data discovery in target buckets
  • CloudWatch Logs or Athena for querying CloudTrail logs at scale
  • VPC endpoint policies configured for S3 access monitoring

Workflow

Step 1: Enable S3 Data Event Logging in CloudTrail

Configure CloudTrail to capture all S3 object-level operations for forensic analysis.

bash
# Enable S3 data events on an existing trail
aws cloudtrail put-event-selectors \
  --trail-name management-trail \
  --event-selectors '[{
    "ReadWriteType": "All",
    "IncludeManagementEvents": true,
    "DataResources": [{
      "Type": "AWS::S3::Object",
      "Values": ["arn:aws:s3:::sensitive-data-bucket/", "arn:aws:s3:::customer-records/"]
    }]
  }]'

# Verify data event configuration
aws cloudtrail get-event-selectors --trail-name management-trail \
  --query 'EventSelectors[*].DataResources' --output json

# Enable GuardDuty S3 Protection
aws guardduty update-detector \
  --detector-id $(aws guardduty list-detectors --query 'DetectorIds[0]' --output text) \
  --data-sources '{"S3Logs":{"Enable":true}}'
Step 2: Query CloudTrail for Anomalous S3 Access Patterns

Analyze CloudTrail logs for bulk download activity, unusual access times, and unfamiliar source IPs.

bash
# Athena query: Top S3 downloaders by volume in last 24 hours
cat << 'EOF'
SELECT
  useridentity.arn as principal,
  sourceipaddress,
  COUNT(*) as request_count,
  SUM(CAST(json_extract_scalar(requestparameters, '$.bytesTransferredOut') AS bigint)) as bytes_downloaded
FROM cloudtrail_logs
WHERE eventname = 'GetObject'
  AND eventsource = 's3.amazonaws.com'
  AND eventtime > date_add('hour', -24, now())
GROUP BY useridentity.arn, sourceipaddress
ORDER BY request_count DESC
LIMIT 50
EOF

# CloudWatch Logs Insights: S3 GetObject requests from unusual IPs
aws logs start-query \
  --log-group-name cloudtrail-logs \
  --start-time $(date -d "24 hours ago" +%s) \
  --end-time $(date +%s) \
  --query-string '
    fields @timestamp, userIdentity.arn, sourceIPAddress, requestParameters.bucketName, requestParameters.key
    | filter eventName = "GetObject"
    | stats count() as requestCount by sourceIPAddress, userIdentity.arn
    | sort requestCount desc
    | limit 25
  '

# Detect cross-account copies (potential exfiltration)
aws logs start-query \
  --log-group-name cloudtrail-logs \
  --start-time $(date -d "7 days ago" +%s) \
  --end-time $(date +%s) \
  --query-string '
    fields @timestamp, userIdentity.arn, sourceIPAddress, requestParameters.bucketName
    | filter eventName in ["CopyObject", "ReplicateObject", "UploadPart"]
    | filter userIdentity.accountId != "OUR_ACCOUNT_ID"
    | sort @timestamp desc
    | limit 100
  '
Step 3: Review GuardDuty S3 Findings

Check for GuardDuty S3-specific finding types that indicate exfiltration activity.

bash
# List active S3 exfiltration-related findings
aws guardduty list-findings \
  --detector-id $(aws guardduty list-detectors --query 'DetectorIds[0]' --output text) \
  --finding-criteria '{
    "Criterion": {
      "type": {
        "Eq": [
          "Exfiltration:S3/MaliciousIPCaller",
          "Exfiltration:S3/ObjectRead.Unusual",
          "Discovery:S3/MaliciousIPCaller.Custom",
          "Discovery:S3/BucketEnumeration.Unusual",
          "UnauthorizedAccess:S3/MaliciousIPCaller.Custom",
          "UnauthorizedAccess:S3/TorIPCaller",
          "Impact:S3/AnomalousBehavior.Delete"
        ]
      }
    }
  }' --output json

# Get detailed finding information
aws guardduty get-findings \
  --detector-id $(aws guardduty list-detectors --query 'DetectorIds[0]' --output text) \
  --finding-ids FINDING_IDS \
  --query 'Findings[*].{Type:Type,Severity:Severity,Resource:Resource.S3BucketDetails[0].Name,Action:Service.Action}' \
  --output table
Step 4: Analyze Macie Findings for Sensitive Data Access

Review Macie findings to correlate data sensitivity with access anomalies.

bash
# List Macie findings for sensitive data exposure
aws macie2 list-findings \
  --finding-criteria '{
    "criterion": {
      "category": {"eq": ["CLASSIFICATION"]},
      "severity.description": {"eq": ["High", "Critical"]}
    }
  }' \
  --sort-criteria '{"attributeName": "updatedAt", "orderBy": "DESC"}' \
  --max-results 25

# Get detailed finding with data classification
aws macie2 get-findings \
  --finding-ids FINDING_IDS \
  --query 'findings[*].{Type:type,Severity:severity.description,Bucket:resourcesAffected.s3Bucket.name,SensitiveDataTypes:classificationDetails.result.sensitiveData[*].category}' \
  --output table

# Run a sensitive data discovery job on target bucket
aws macie2 create-classification-job \
  --job-type ONE_TIME \
  --name "exfiltration-investigation" \
  --s3-job-definition '{
    "bucketDefinitions": [{
      "accountId": "ACCOUNT_ID",
      "buckets": ["sensitive-data-bucket"]
    }]
  }'
Step 5: Build Automated Detection Rules

Create CloudWatch alarms and EventBridge rules for real-time exfiltration detection.

bash
# CloudWatch metric filter for high-volume S3 downloads
aws logs put-metric-filter \
  --log-group-name cloudtrail-logs \
  --filter-name s3-bulk-download \
  --filter-pattern '{$.eventName = "GetObject" && $.eventSource = "s3.amazonaws.com"}' \
  --metric-transformations '[{
    "metricName": "S3GetObjectCount",
    "metricNamespace": "SecurityMetrics",
    "metricValue": "1",
    "defaultValue": 0
  }]'

# Alarm for anomalous download volume (>1000 objects/hour)
aws cloudwatch put-metric-alarm \
  --alarm-name s3-exfiltration-alert \
  --metric-name S3GetObjectCount \
  --namespace SecurityMetrics \
  --statistic Sum \
  --period 3600 \
  --threshold 1000 \
  --comparison-operator GreaterThanThreshold \
  --evaluation-periods 1 \
  --alarm-actions arn:aws:sns:us-east-1:ACCOUNT:security-alerts

# EventBridge rule for GuardDuty S3 findings
aws events put-rule \
  --name guardduty-s3-exfiltration \
  --event-pattern '{
    "source": ["aws.guardduty"],
    "detail-type": ["GuardDuty Finding"],
    "detail": {
      "type": [{"prefix": "Exfiltration:S3/"}]
    }
  }'
Step 6: Implement Preventive Controls

Deploy bucket policies and VPC endpoint policies to restrict data movement paths.

bash
# VPC endpoint policy restricting S3 access to specific buckets
aws ec2 modify-vpc-endpoint \
  --vpc-endpoint-id vpce-ENDPOINT_ID \
  --policy-document '{
    "Statement": [{
      "Sid": "RestrictToOwnBuckets",
      "Effect": "Allow",
      "Principal": "*",
      "Action": ["s3:GetObject", "s3:PutObject"],
      "Resource": ["arn:aws:s3:::approved-bucket-1/*", "arn:aws:s3:::approved-bucket-2/*"]
    }]
  }'

# Bucket policy denying access from outside the VPC
aws s3api put-bucket-policy --bucket sensitive-data-bucket --policy '{
  "Version": "2012-10-17",
  "Statement": [{
    "Sid": "DenyNonVpcAccess",
    "Effect": "Deny",
    "Principal": "*",
    "Action": "s3:GetObject",
    "Resource": "arn:aws:s3:::sensitive-data-bucket/*",
    "Condition": {
      "StringNotEquals": {
        "aws:sourceVpce": "vpce-ENDPOINT_ID"
      }
    }
  }]
}'

Key Concepts

TermDefinition
S3 Data EventsCloudTrail object-level logging that captures GetObject, PutObject, DeleteObject, and CopyObject API calls with request details
GuardDuty S3 ProtectionThreat detection feature analyzing CloudTrail S3 data events to identify anomalous access patterns and exfiltration attempts
Amazon MacieData security service that discovers and classifies sensitive data in S3 and generates findings for data exposure risks
VPC Endpoint PolicyAccess control policy on an S3 VPC endpoint that restricts which buckets and actions can be accessed through the endpoint
Data ExfiltrationUnauthorized transfer of data from an organization's S3 storage to an external location controlled by an attacker
Anomalous Behavior DetectionMachine learning-based identification of S3 access patterns that deviate from established baselines for a principal
Show full SKILL.md (245 more words)Show less

Tools & Systems

  • AWS CloudTrail: Audit logging of S3 object-level operations for forensic analysis and anomaly detection
  • Amazon GuardDuty: ML-based threat detection with S3-specific finding types for exfiltration and unauthorized access
  • Amazon Macie: Sensitive data discovery and classification for correlating access anomalies with data sensitivity
  • Amazon Athena: SQL query engine for analyzing CloudTrail logs at scale to identify bulk download patterns
  • CloudWatch Logs Insights: Real-time log analysis for building detection queries against CloudTrail data

Common Scenarios

Scenario: Compromised IAM Credentials Used for Bulk S3 Data Download

Context: GuardDuty reports an Exfiltration:S3/ObjectRead.Unusual finding indicating that a developer's access key is downloading thousands of objects from a sensitive data bucket at 3 AM from an IP address in a foreign country.

Approach:

  1. Immediately deactivate the compromised access key
  2. Query CloudTrail for all S3 actions by the compromised principal in the last 72 hours
  3. Identify which buckets and objects were accessed using Athena queries
  4. Cross-reference accessed objects with Macie classifications to assess data sensitivity
  5. Check for CopyObject calls to external accounts (cross-account exfiltration)
  6. Review how the credentials were compromised (TruffleHog scan, phishing investigation)
  7. Implement VPC endpoint policies to restrict future S3 access to approved network paths

Pitfalls: CloudTrail S3 data events can generate massive log volume. Use Athena with partitioned tables rather than CloudWatch Logs Insights for queries spanning more than 24 hours. GuardDuty baseline learning requires 7-14 days, so new accounts may generate false positives for normal access patterns.

Output Format

S3 Data Exfiltration Investigation Report
============================================
Account: 123456789012
Detection Source: GuardDuty Exfiltration:S3/ObjectRead.Unusual
Investigation Date: 2026-02-23

INCIDENT TIMELINE:
  2026-02-23 02:47 UTC - First anomalous GetObject from 185.x.x.x
  2026-02-23 02:47-04:12 UTC - 12,847 GetObject requests
  2026-02-23 04:15 UTC - GuardDuty finding generated
  2026-02-23 04:20 UTC - PagerDuty alert received by SOC
  2026-02-23 04:25 UTC - Access key deactivated

COMPROMISED PRINCIPAL:
  ARN: arn:aws:iam::123456789012:user/developer-jane
  Access Key: AKIA...WXYZ
  Source IP: 185.x.x.x (Tor exit node)

DATA IMPACT ASSESSMENT:
  Buckets accessed: 3
  Objects downloaded: 12,847
  Total data volume: 4.7 GB
  Sensitive data types: PII (SSN, email), Financial (credit card)
  Macie severity: CRITICAL

CONTAINMENT ACTIONS:
  [x] Access key deactivated
  [x] User password reset and MFA re-enrolled
  [x] VPC endpoint policy applied to sensitive buckets
  [x] Bucket policy restricting to VPC-only access
  [x] TruffleHog scan initiated on developer repositories

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/detecting-s3-data-exfiltration-attempts of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Detecting S3 Data Exfiltration Attempts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detecting S3 Data Exfiltration Attempts compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detecting S3 Data Exfiltration Attempts this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Processing S3 Uploads With Step Functionsaws/agent-toolkit-for-aws2.8k—~4kAutomated safety check: PassApache-2.0
S3 User Filesaws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore177—~779Automated safety check: PassMIT-0
Django Storages for S3Jeffallan/claude-skills12k—~1.9kAutomated safety check: PassMIT
Neon Object Storageneondatabase/agent-skills100—~3.5kAutomated safety check: NotesApache-2.0
AWS S3sickn33/agentic-awesome-skills47k2 repos~3.1kAutomated safety check: PassMIT

Similar skills

  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • S3 User Files

    aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore

    Official

    Per-user persistent file storage backed by AWS S3. An agent skill from aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore.

    177 GitHub stars~779 tokensUpdated 11 days ago
    Backend & APIsAuto-check passed
  • Django Storages for S3

    Jeffallan/claude-skills

    Sets up Django 4.2+ to keep static and media files on AWS S3 through django-storages, with public and private backends, presigned URLs and CloudFront.

    12k GitHub stars~1.9k tokensUpdated 6 days ago
    Backend & APIsAuto-check passed
  • Neon Object Storage

    neondatabase/agent-skills

    Official

    S3-compatible object storage that branches with your Neon project, so files and the database stay in sync across every branch.

    100 GitHub stars~3.5k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • AWS S3

    sickn33/agentic-awesome-skills

    Configure S3 buckets, policies, and lifecycle rules. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.1k tokens
    Backend & APIsAuto-check passed
  • R2 Upload

    zebbern/claude-code-guide

    Upload files to Cloudflare R2, AWS S3, or any S3-compatible storage (like MinIO) and generate secure, time-limited presigned download links with configurable expiration, typically set to 5 minutes.

    4.7k GitHub stars~886 tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Detecting S3 Data Exfiltration Attempts

What does Detecting S3 Data Exfiltration Attempts do?

Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify…. Detecting S3 Data Exfiltration Attempts is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.

When should I use Detecting S3 Data Exfiltration Attempts?

Detecting S3 Data Exfiltration Attempts fits situations like: tasks that involve File uploads and storage.

How do I install Detecting S3 Data Exfiltration Attempts in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-s3-data-exfiltration-attempts -a claude-code`. Or copy the skill folder (skills/detecting-s3-data-exfiltration-attempts in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/detecting-s3-data-exfiltration-attempts in your project. Claude Code loads it when a task matches its description.

How do I install Detecting S3 Data Exfiltration Attempts in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-s3-data-exfiltration-attempts -a codex`. Or copy the skill folder (skills/detecting-s3-data-exfiltration-attempts in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/detecting-s3-data-exfiltration-attempts in your project. Codex loads it when a task matches its description.

Can I use Detecting S3 Data Exfiltration Attempts in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-s3-data-exfiltration-attempts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-s3-data-exfiltration-attempts, .gemini/skills/detecting-s3-data-exfiltration-attempts, .github/skills/detecting-s3-data-exfiltration-attempts and .opencode/skills/detecting-s3-data-exfiltration-attempts in your project.

What does Detecting S3 Data Exfiltration Attempts need to run?

Going by SKILL.md and its folder, Detecting S3 Data Exfiltration Attempts needs Python for the scripts in its folder and the command-line tools its instructions call (aws). Our summary lists: Python 3.

Does Detecting S3 Data Exfiltration Attempts access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Detecting S3 Data Exfiltration Attempts safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Detecting S3 Data Exfiltration Attempts use?

Detecting S3 Data Exfiltration Attempts is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detecting S3 Data Exfiltration Attempts use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 635 tokens, read only when the agent opens those files.

What are the alternatives to Detecting S3 Data Exfiltration Attempts?

Skills that share tags, products or a category with Detecting S3 Data Exfiltration Attempts: Processing S3 Uploads With Step Functions (aws/agent-toolkit-for-aws, 2.8k stars), S3 User Files (aws-samples/sample-host-openclaw-on-amazon-bedrock-agentcore, 177 stars), Django Storages for S3 (Jeffallan/claude-skills, 12k stars) and Neon Object Storage (neondatabase/agent-skills, 100 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detecting S3 Data Exfiltration Attempts?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.