Agent skill

Securing AWS Iam Permissions

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Hardens AWS IAM configurations to enforce least-privilege access, covering IAM policy scoping, permission boundaries, IAM Access Analyzer integration, and credential rotation strategies.

Apache-2.0Auto-check passedSecurity

Install Securing AWS Iam Permissions

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill securing-aws-iam-permissions -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills securing-aws-iam-permissions --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/securing-aws-iam-permissions .claude/skills/securing-aws-iam-permissions && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
securing-aws-iam-permissions
GitHub stars
34k
Token cost
~3.3k tokens
SKILL.md length
855 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Hardens AWS IAM configurations to enforce least-privilege access, covering IAM policy scoping, permission boundaries, IAM Access Analyzer integration, and credential rotation strategies.

  • Works in 6 steps: Inventory Existing IAM Entities and… → Enable and Analyze IAM Access Analyzer… → Scope Policies to Specific Resources and… → …
  • Reducing the blast radius of compromised AWS identities
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls aws

What it does

Securing AWS Iam Permissions is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Hardens AWS IAM configurations to enforce least-privilege access, covering IAM policy scoping, permission boundaries, IAM Access Analyzer integration, and credential rotation strategies. Use when reducing the blast radius of compromised AWS identities, auditing overly permissive IAM policies, or setting up permission boundaries and Access Analyzer findings review across cloud accounts.

Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Cloud security. It works with Amazon Web Services. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Reducing the blast radius of compromised AWS identities
  • Auditing overly permissive IAM policies
  • Setting up permission boundaries and Access Analyzer findings review across cloud accounts

Example prompts

  • “Use the securing-aws-iam-permissions skill to harden AWS IAM configurations to enforce least-privilege access, covering IAM policy scoping…”
  • “/securing-aws-iam-permissions”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Inventory Existing IAM Entities and Policies
  2. Enable and Analyze IAM Access Analyzer Findings
  3. Scope Policies to Specific Resources and Conditions
  4. Implement Permission Boundaries
  5. Enforce MFA and Eliminate Long-Lived Credentials
  6. Automate Continuous IAM Monitoring

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Securing AWS Iam Permissions loads about 3.3k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 104 tokens; SKILL.md has 855 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~3.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 855 words, ~3,306 tokens.

Download SKILL.mdSave it as .claude/skills/securing-aws-iam-permissions/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
securing-aws-iam-permissions
description
Hardens AWS IAM configurations to enforce least-privilege access, covering IAM policy scoping, permission boundaries, IAM Access Analyzer integration, and credential rotation strategies. Use when reducing the blast radius of compromised AWS identities, auditing overly permissive IAM policies, or setting up permission boundaries and Access Analyzer findings review across cloud accounts.
domain
cybersecurity
subdomain
cloud-security
tags
aws-iam, least-privilege, permission-boundaries, access-analyzer, cloud-identity
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.IR-01, ID.AM-08, GV.SC-06, DE.CM-01
mitre_attack
T1078.004, T1530, T1537, T1580, T1003
mitre_f3.version
1.1
mitre_f3.tactics
initial-access, positioning

Securing AWS IAM Permissions

When to Use

  • When onboarding new AWS accounts or workloads that require scoped IAM policies
  • When IAM Access Analyzer reports overly permissive policies or unused permissions
  • When preparing for a compliance audit requiring least privilege evidence (SOC 2, PCI-DSS)
  • When migrating from long-lived access keys to short-lived role-based credentials
  • When remediating findings from AWS Security Hub related to IAM misconfigurations

Do not use for Azure AD or Google Cloud IAM configurations, application-level authorization logic, or federated identity provider setup (see managing-cloud-identity-with-okta).

Prerequisites

  • AWS account with administrative access or IAM:FullAccess permissions
  • AWS CLI v2 installed and configured with named profiles
  • AWS CloudTrail enabled for at least 90 days of API activity history
  • Familiarity with JSON-based IAM policy syntax and ARN resource notation

Workflow

Step 1: Inventory Existing IAM Entities and Policies

Generate a comprehensive inventory of all IAM users, roles, groups, and attached policies using the AWS CLI and IAM credential reports. Identify accounts with console access, programmatic access keys, and their last-used timestamps.

bash
# Generate IAM credential report
aws iam generate-credential-report
aws iam get-credential-report --query 'Content' --output text | base64 -d > iam-report.csv

# List all IAM roles and their attached policies
aws iam list-roles --query 'Roles[*].[RoleName,Arn,CreateDate]' --output table

# Find users with access keys older than 90 days
aws iam list-users --query 'Users[*].UserName' --output text | while read user; do
  aws iam list-access-keys --user-name "$user" \
    --query "AccessKeyMetadata[?CreateDate<='$(date -d '-90 days' +%Y-%m-%d)'].[UserName,AccessKeyId,Status,CreateDate]" \
    --output table
done
Step 2: Enable and Analyze IAM Access Analyzer Findings

Activate IAM Access Analyzer at the organization or account level to identify resources shared externally and generate least-privilege policy recommendations based on CloudTrail activity.

bash
# Create an Access Analyzer for the account
aws accessanalyzer create-analyzer \
  --analyzer-name account-analyzer \
  --type ACCOUNT

# List active findings for external access
aws accessanalyzer list-findings \
  --analyzer-arn arn:aws:access-analyzer:us-east-1:123456789012:analyzer/account-analyzer \
  --filter '{"status": {"eq": ["ACTIVE"]}}'

# Generate a policy based on CloudTrail activity for a specific role
aws accessanalyzer start-policy-generation \
  --policy-generation-details '{
    "principalArn": "arn:aws:iam::123456789012:role/AppRole",
    "cloudTrailDetails": {
      "trailArn": "arn:aws:cloudtrail:us-east-1:123456789012:trail/management-trail",
      "startTime": "2025-01-01T00:00:00Z",
      "endTime": "2025-03-01T00:00:00Z"
    }
  }'
Step 3: Scope Policies to Specific Resources and Conditions

Replace wildcard resource ARNs with specific resource identifiers. Add IAM policy conditions for MFA enforcement, source IP restrictions, and time-based access windows.

json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowS3ReadSpecificBucket",
      "Effect": "Allow",
      "Action": [
        "s3:GetObject",
        "s3:ListBucket"
      ],
      "Resource": [
        "arn:aws:s3:::production-data-bucket",
        "arn:aws:s3:::production-data-bucket/*"
      ],
      "Condition": {
        "Bool": {"aws:MultiFactorAuthPresent": "true"},
        "IpAddress": {"aws:SourceIp": "10.0.0.0/8"},
        "DateGreaterThan": {"aws:CurrentTime": "2025-01-01T00:00:00Z"}
      }
    }
  ]
}
Step 4: Implement Permission Boundaries

Attach permission boundaries to IAM roles and users to define the maximum scope of permissions an entity can receive, preventing privilege escalation even if an administrator attaches an overly permissive policy.

bash
# Create a permission boundary policy
aws iam create-policy \
  --policy-name DeveloperPermissionBoundary \
  --policy-document file://developer-boundary.json

# Attach the boundary to an IAM role
aws iam put-role-permissions-boundary \
  --role-name DeveloperRole \
  --permissions-boundary "arn:aws:iam::123456789012:policy/DeveloperPermissionBoundary"
json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "AllowCommonServices",
      "Effect": "Allow",
      "Action": [
        "s3:*",
        "dynamodb:*",
        "lambda:*",
        "logs:*",
        "cloudwatch:*"
      ],
      "Resource": "*"
    },
    {
      "Sid": "DenyIAMChanges",
      "Effect": "Deny",
      "Action": [
        "iam:CreateUser",
        "iam:DeleteUser",
        "iam:CreateRole",
        "iam:DeleteRole",
        "iam:AttachRolePolicy",
        "iam:PutRolePermissionsBoundary"
      ],
      "Resource": "*"
    }
  ]
}
Step 5: Enforce MFA and Eliminate Long-Lived Credentials

Require MFA for all human users accessing the AWS console and CLI. Migrate workloads from IAM user access keys to IAM roles with temporary credentials via STS AssumeRole.

bash
# Enforce MFA via SCP at the organization level
aws organizations create-policy \
  --name RequireMFA \
  --type SERVICE_CONTROL_POLICY \
  --content '{
    "Version": "2012-10-17",
    "Statement": [
      {
        "Sid": "DenyAllExceptMFA",
        "Effect": "Deny",
        "NotAction": [
          "iam:CreateVirtualMFADevice",
          "iam:EnableMFADevice",
          "iam:ListMFADevices",
          "iam:ResyncMFADevice",
          "sts:GetSessionToken"
        ],
        "Resource": "*",
        "Condition": {
          "BoolIfExists": {"aws:MultiFactorAuthPresent": "false"}
        }
      }
    ]
  }'

# Deactivate unused access keys
aws iam update-access-key --user-name old-user --access-key-id AKIAEXAMPLE --status Inactive
Step 6: Automate Continuous IAM Monitoring

Deploy AWS Config rules and Security Hub controls to continuously evaluate IAM posture. Set up EventBridge rules to alert on high-risk IAM changes such as new root access key creation or policy modifications.

bash
# Enable AWS Config rule for IAM password policy
aws configservice put-config-rule \
  --config-rule '{
    "ConfigRuleName": "iam-password-policy",
    "Source": {
      "Owner": "AWS",
      "SourceIdentifier": "IAM_PASSWORD_POLICY"
    },
    "InputParameters": "{\"RequireUppercaseCharacters\":\"true\",\"RequireLowercaseCharacters\":\"true\",\"RequireSymbols\":\"true\",\"RequireNumbers\":\"true\",\"MinimumPasswordLength\":\"14\",\"MaxPasswordAge\":\"90\"}"
  }'

# EventBridge rule to detect root account usage
aws events put-rule \
  --name DetectRootUsage \
  --event-pattern '{
    "detail-type": ["AWS API Call via CloudTrail"],
    "detail": {
      "userIdentity": {"type": ["Root"]}
    }
  }'

Key Concepts

TermDefinition
Least PrivilegeGranting only the minimum permissions required for an identity to perform its function
Permission BoundaryAn advanced IAM feature that sets the maximum permissions an entity can have, regardless of attached policies
IAM Access AnalyzerAWS service that uses automated reasoning to identify resources shared externally and generate least-privilege policies from CloudTrail activity
Service Control Policy (SCP)Organization-level policy that sets permission guardrails across all accounts in an AWS Organization
Assume RoleSTS operation that returns temporary security credentials for cross-account or service-to-service access
Credential ReportAWS-generated CSV listing all IAM users, their access keys, MFA status, and last activity timestamps
Policy ConditionConstraints in IAM policies that restrict when and how permissions apply, such as MFA requirements or IP ranges
Identity FederationAllowing external identity providers to grant temporary AWS access without creating IAM users
Show full SKILL.md (371 more words)Show less

Tools & Systems

  • AWS IAM Access Analyzer: Generates least-privilege policies from CloudTrail activity and identifies resources shared with external entities
  • AWS Config: Continuously evaluates IAM configuration compliance against managed and custom rules
  • AWS Security Hub: Aggregates IAM security findings from Access Analyzer, Config, and third-party tools into a unified dashboard
  • IAM Policy Simulator: Tests the effects of IAM policies before deployment by simulating API calls against policy evaluation logic
  • Prowler: Open-source AWS security assessment tool that runs over 300 checks including IAM best practices and CIS benchmark controls

Common Scenarios

Scenario: Developer Role Over-Provisioned with AdministratorAccess

Context: A startup attached the AWS-managed AdministratorAccess policy to all developer roles for speed during early development. A security audit reveals 15 roles with full account access while developers only use S3, Lambda, and DynamoDB.

Approach:

  1. Enable IAM Access Analyzer and generate policy recommendations based on 90 days of CloudTrail data for each role
  2. Create scoped policies allowing only the specific S3 buckets, Lambda functions, and DynamoDB tables each team accesses
  3. Attach a permission boundary denying IAM, Organizations, and billing actions
  4. Deploy the new policies in a parallel role with CloudTrail monitoring before replacing the original
  5. Remove AdministratorAccess and rotate all access keys

Pitfalls: Replacing policies without a parallel testing period causes service disruptions. Forgetting to scope Lambda:InvokeFunction to specific function ARNs leaves lateral movement paths open.

Scenario: Rotating Compromised Access Keys Across Multiple Services

Context: An access key is found in a public GitHub repository. The key belongs to an IAM user with S3 and EC2 permissions across three AWS accounts.

Approach:

  1. Immediately deactivate the compromised key using aws iam update-access-key --status Inactive
  2. Review CloudTrail logs for all API calls made with the compromised key in the past 30 days
  3. Create a new access key for the user and update all dependent services and CI/CD pipelines
  4. Delete the compromised key after confirming all services use the new credentials
  5. Migrate the workload to use IAM roles with STS temporary credentials to prevent future key exposure

Pitfalls: Deleting the key before deactivating it prevents forensic analysis of which services relied on it. Failing to check all three accounts for unauthorized activity leaves potential backdoors undetected.

Output Format

IAM Security Assessment Report
==============================
Account ID: 123456789012
Assessment Date: 2025-02-23
Analyzer: IAM Access Analyzer + Prowler v4.3

CRITICAL FINDINGS:
[C-001] Root account has active access keys
  - Resource: arn:aws:iam::123456789012:root
  - Remediation: Delete root access keys, enable MFA on root
  - CIS Benchmark: 1.4 (Ensure no root account access key exists)

[C-002] IAM user 'deploy-bot' has AdministratorAccess with no MFA
  - Resource: arn:aws:iam::123456789012:user/deploy-bot
  - Last Activity: 2025-02-20
  - Remediation: Replace with IAM role, enforce MFA condition

HIGH FINDINGS:
[H-001] 3 IAM policies use wildcard Resource "*" with sensitive actions
  - Policies: DevPolicy, CIPolicy, LegacyAdminPolicy
  - Remediation: Scope resources to specific ARNs using Access Analyzer

[H-002] 7 access keys older than 90 days detected
  - Users: svc-backup, svc-monitoring, dev-alice, dev-bob, ...
  - Remediation: Rotate keys, migrate to role-based access

SUMMARY:
  Total Findings: 14
  Critical: 2 | High: 4 | Medium: 5 | Low: 3
  Compliance Score: 62% (CIS AWS Foundations Benchmark v3.0)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/securing-aws-iam-permissions of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Securing AWS Iam Permissions next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Securing AWS Iam Permissions compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Securing AWS Iam Permissions this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.3kAutomated safety check: PassApache-2.0
Cloud Auditbriiirussell/cybersecurity-skills413—~1.3kAutomated safety check: NotesMIT
Iamitsmostafa/aws-agent-skills1.2k—~1.8kAutomated safety check: PassMIT
AWS Security ArchitectureHack23/cia239—~2.3kAutomated safety check: PassApache-2.0
AWS Iamsickn33/agentic-awesome-skills47k2 repos~3.4kAutomated safety check: PassMIT
Configuring Firewallsancoleman/ai-design-components525—~3.5kAutomated safety check: NotesMIT

Similar skills

  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Iam

    itsmostafa/aws-agent-skills

    AWS Identity and Access Management for users, roles, policies, and permissions.

    1.2k GitHub stars~1.8k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • AWS Iam

    sickn33/agentic-awesome-skills

    Manage IAM users, roles, and policies. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.4k tokens
    SecurityAuto-check passed
  • Configuring Firewalls

    ancoleman/ai-design-components

    Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.

    525 GitHub stars~3.5k tokensUpdated 10 mo ago
    SecurityAuto-check: notes
  • Creating Secrets Using Best Practices

    aws/agent-toolkit-for-aws

    Official

    Creates and manages secrets in AWS Secrets Manager following security best practices.

    2.8k GitHub starsUsed in 1 repo~461 tokens
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Securing AWS Iam Permissions

What does Securing AWS Iam Permissions do?

Hardens AWS IAM configurations to enforce least-privilege access, covering IAM policy scoping, permission boundaries, IAM Access Analyzer integration, and credential rotation strategies. Securing AWS Iam Permissions is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Hardens AWS IAM configurations to enforce least-privilege access, covering IAM policy scoping, permission boundaries, IAM Access Analyzer integration, and credential rotation strategies.

When should I use Securing AWS Iam Permissions?

Securing AWS Iam Permissions fits situations like: reducing the blast radius of compromised AWS identities; auditing overly permissive IAM policies; setting up permission boundaries and Access Analyzer findings review across cloud accounts.

How do I install Securing AWS Iam Permissions in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill securing-aws-iam-permissions -a claude-code`. Or copy the skill folder (skills/securing-aws-iam-permissions in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/securing-aws-iam-permissions in your project. Claude Code loads it when a task matches its description.

How do I install Securing AWS Iam Permissions in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill securing-aws-iam-permissions -a codex`. Or copy the skill folder (skills/securing-aws-iam-permissions in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/securing-aws-iam-permissions in your project. Codex loads it when a task matches its description.

Can I use Securing AWS Iam Permissions in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill securing-aws-iam-permissions -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/securing-aws-iam-permissions, .gemini/skills/securing-aws-iam-permissions, .github/skills/securing-aws-iam-permissions and .opencode/skills/securing-aws-iam-permissions in your project.

What does Securing AWS Iam Permissions need to run?

Going by SKILL.md and its folder, Securing AWS Iam Permissions needs Python for the scripts in its folder and the command-line tools its instructions call (aws). Our summary lists: Python 3.

Does Securing AWS Iam Permissions access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Securing AWS Iam Permissions safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Securing AWS Iam Permissions use?

Securing AWS Iam Permissions is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Securing AWS Iam Permissions use?

About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 582 tokens, read only when the agent opens those files.

What are the alternatives to Securing AWS Iam Permissions?

Skills that share tags, products or a category with Securing AWS Iam Permissions: Cloud Audit (briiirussell/cybersecurity-skills, 413 stars), Iam (itsmostafa/aws-agent-skills, 1.2k stars), AWS Security Architecture (Hack23/cia, 239 stars) and AWS Iam (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Securing AWS Iam Permissions?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.