Cloud Security
borghei/Claude-Skills
Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails.
Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…
$ npx skills add trilwu/secskills --skill hardening-cloud-posture -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trilwu/secskills hardening-cloud-posture --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-defense/skills/hardening-cloud-posture .claude/skills/hardening-cloud-posture && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "hardening-cloud-posture" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/hardening-cloud-posture into .claude/skills/hardening-cloud-posture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hardening-cloud-posture", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/hardening-cloud-postureType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trilwu/secskills --skill hardening-cloud-posture -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trilwu/secskills hardening-cloud-posture --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/secskills-defense/skills/hardening-cloud-posture .agents/skills/hardening-cloud-posture && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "hardening-cloud-posture" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/hardening-cloud-posture into .agents/skills/hardening-cloud-posture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hardening-cloud-posture", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill hardening-cloud-posture -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trilwu/secskills hardening-cloud-posture --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/secskills-defense/skills/hardening-cloud-posture .cursor/skills/hardening-cloud-posture && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "hardening-cloud-posture" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/hardening-cloud-posture into .cursor/skills/hardening-cloud-posture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hardening-cloud-posture", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trilwu/secskills.git --path secskills-defense/skills/hardening-cloud-posture--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trilwu/secskills --skill hardening-cloud-posture -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trilwu/secskills hardening-cloud-posture --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/secskills-defense/skills/hardening-cloud-posture .gemini/skills/hardening-cloud-posture && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "hardening-cloud-posture" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/hardening-cloud-posture into .gemini/skills/hardening-cloud-posture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hardening-cloud-posture", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trilwu/secskills hardening-cloud-postureInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trilwu/secskills --skill hardening-cloud-posture -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .github/skills && cp -r skills-src/secskills-defense/skills/hardening-cloud-posture .github/skills/hardening-cloud-posture && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "hardening-cloud-posture" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/hardening-cloud-posture into .github/skills/hardening-cloud-posture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hardening-cloud-posture", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trilwu/secskills --skill hardening-cloud-posture -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trilwu/secskills hardening-cloud-posture --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/secskills-defense/skills/hardening-cloud-posture .opencode/skills/hardening-cloud-posture && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "hardening-cloud-posture" agent skill from https://github.com/trilwu/secskills/tree/main/secskills-defense/skills/hardening-cloud-posture into .opencode/skills/hardening-cloud-posture/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "hardening-cloud-posture", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
hardening-cloud-postureProactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…
Hardening Cloud Posture is an agent skill from trilwu/secskills. Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage, over-broad roles, missing audit logging, unencrypted data), reading CSPM output critically, and enforcing guardrails at the org level. Use when reviewing a cloud environment's security posture, triaging a Prowler/ScoutSuite/Security Hub report, deciding which misconfigurations actually matter, or setting preventive…
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Cloud security and LLM guardrails. It works with Microsoft Azure, Google Cloud and Amazon Web Services. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
defuddle.mdFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Hardening Cloud Posture loads about 1.9k tokens when it runs. Until then it costs about 143 tokens; SKILL.md has 987 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 987 words, ~1,925 tokens.
.claude/skills/hardening-cloud-posture/SKILL.md (or your agent's skills folder).A CSPM scan returns a thousand findings. Almost none of them are the way in. The job is not to close a thousand findings; it is to find the handful that form an attack path and close those, then set guardrails so they cannot recur. Posture work that treats every finding as equal drowns the real one.
The organizing principle: identity is the perimeter. In cloud, the attack path is almost always a chain of IAM permissions, not a network hop. Rank by "what does this let a principal reach?", not by a scanner's severity label.
investigating-aws-incidents,
investigating-azure-incidents, or investigating-gcp-incidentsexploiting-cloud-platformsdefending-kubernetesmanaging-vulnerabilitiesWork findings in the order an attacker would exploit them, not the order the scanner lists them:
0.0.0.0/0.
These need no credential — they are pre-authentication. Close first.Action/Resource policies, roles
assumable by * or by external accounts without a condition, users with
iam:PassRole to a privileged role, service principals with Owner. This
is where a foothold becomes account-takeover.A public bucket with customer data outranks a hundred "encryption not enabled" findings, even though the scanner may score them alike.
Prowler, ScoutSuite, Security Hub, and Defender for Cloud are the standard tools and they are useful — but their output is a starting point, not a verdict:
*; it
does not tell you that role is attached to an internet-facing function. You
supply the reachability.Map the top findings to CIS Benchmark controls where a compliance frame helps, but do not let the benchmark set your priority — the benchmark is comprehensive, your remediation budget is not.
A fixed misconfiguration recurs the next time someone provisions a resource. A guardrail prevents the whole class:
s3:BlockPublicAccess at the account level.deny effects for public network access,
required encryption, required diagnostic settings.storage.publicAccessPrevention,
iam.disableServiceAccountKeyCreation, compute.requireOsLogin).Prefer the org-level deny over the per-resource fix. The point-fix closes one
finding; the guardrail closes the class and every future instance of it.
PassRole, wildcard trust policies, cross-account assume — not
nothing. Identity is the perimeter; it is not optional.Fetch public advisories, specifications, and vendor reports as Markdown:
curl -sL "https://defuddle.md/<url>" # scheme in the path is optionalThis strips page boilerplate — roughly 78% fewer tokens on a prose page — and returns the full text rather than a summary, so you can grep it and trust a negative result.
Three things it is not for. Fetch JSON and API responses raw, because readability extraction mangles structured data. Fetch authenticated or JavaScript-rendered pages directly, because it retrieves them anonymously. And never route adversary infrastructure (phishing links, C2, malware hosting), client-owned hosts, or engagement URLs through it — the request leaves your machine to a third party, and for live adversary infrastructure it also tips off the operator.
Some sites block the extractor and return an error blob rather than the page —
{"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for
instance. That is the fetch being refused, not the source saying the thing
does not exist. Re-fetch the URL directly before drawing any conclusion from
it.
exploiting-cloud-platforms — the attack paths this posture work closesinvestigating-aws-incidents / investigating-azure-incidents /
investigating-gcp-incidents — what the audit logging you enable here feedsdefending-kubernetes — the cluster plane, when the account runs managed k8smanaging-vulnerabilities — the workload-CVE counterpart to config posture© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in secskills-defense/skills/hardening-cloud-posture of trilwu/secskills.
Open the folder on GitHubat commit ca53957
Hardening Cloud Posture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Hardening Cloud Posture this skilltrilwu/secskills | 157 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Cloud Securityborghei/Claude-Skills | 891 | — | ~3.5k | Automated safety check: Pass | MIT | |
| Cloud Auditbriiirussell/cybersecurity-skills | 413 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Auditing Cloud With Cis Benchmarksmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Configuring Firewallsancoleman/ai-design-components | 525 | — | ~3.5k | Automated safety check: Notes | MIT |
borghei/Claude-Skills
Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails.
briiirussell/cybersecurity-skills
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
mukul975/Anthropic-Cybersecurity-Skills
Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…
mukul975/Anthropic-Cybersecurity-Skills
Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…
ancoleman/ai-design-components
Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.
criptogus/agent-evolve-network
Audits AWS, GCP and Azure environments (and matching IaC) for excessive permissions, public exposure, weak encryption defaults and missing logging.
trilwu/secskills
Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.
trilwu/secskills
Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.
trilwu/secskills
Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…
trilwu/secskills
Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.
trilwu/secskills
Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…
trilwu/secskills
Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…
Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…. Hardening Cloud Posture is an agent skill from trilwu/secskills. Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage, over-broad roles, missing audit logging, unencrypted data), reading CSPM output critically, and enforcing guardrails at the org level.
Hardening Cloud Posture fits situations like: reviewing a cloud environments security posture; triaging a Prowler/ScoutSuite/Security Hub report; deciding which misconfigurations actually matter; setting preventive controls across AWS.
Run `npx skills add trilwu/secskills --skill hardening-cloud-posture -a claude-code`. Or copy the skill folder (secskills-defense/skills/hardening-cloud-posture in trilwu/secskills) into .claude/skills/hardening-cloud-posture in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trilwu/secskills --skill hardening-cloud-posture -a codex`. Or copy the skill folder (secskills-defense/skills/hardening-cloud-posture in trilwu/secskills) into .agents/skills/hardening-cloud-posture in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill hardening-cloud-posture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hardening-cloud-posture, .gemini/skills/hardening-cloud-posture, .github/skills/hardening-cloud-posture and .opencode/skills/hardening-cloud-posture in your project.
Going by SKILL.md and its folder, Hardening Cloud Posture needs the command-line tools its instructions call (curl).
SKILL.md names 1 domain. In commands or code: defuddle.md; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Hardening Cloud Posture is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Hardening Cloud Posture: Cloud Security (borghei/Claude-Skills, 891 stars), Cloud Audit (briiirussell/cybersecurity-skills, 413 stars), Auditing Cloud With Cis Benchmarks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.
Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.