Agent skill

Hardening Cloud Posture

by trilwu in trilwu/secskills

Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…

MITAuto-check passedSecurity

Install Hardening Cloud Posture

skills CLI
$ npx skills add trilwu/secskills --skill hardening-cloud-posture -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trilwu/secskills hardening-cloud-posture --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trilwu/secskills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/secskills-defense/skills/hardening-cloud-posture .claude/skills/hardening-cloud-posture && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hardening-cloud-posture
GitHub stars
157
Token cost
~1.9k tokens
SKILL.md length
987 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…

  • Works in 4 steps: Public exposure of data or compute.… → Identity that over-reaches. Wildcard… → Missing or disabled audit logging.… → …
  • Reviewing a cloud environments security posture
  • SKILL.md covers When to Use, When NOT to Use, Rank by Attack Path, Not… and Read CSPM Output Critically, plus 4 more sections
  • Calls curl; reaches defuddle.md

What it does

Hardening Cloud Posture is an agent skill from trilwu/secskills. Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage, over-broad roles, missing audit logging, unencrypted data), reading CSPM output critically, and enforcing guardrails at the org level. Use when reviewing a cloud environment's security posture, triaging a Prowler/ScoutSuite/Security Hub report, deciding which misconfigurations actually matter, or setting preventive…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cloud security and LLM guardrails. It works with Microsoft Azure, Google Cloud and Amazon Web Services. The repository describes itself as: Transform Claude Code into your personal security engineer. The licence is MIT.

When your agent uses it

  • Reviewing a cloud environments security posture
  • Triaging a Prowler/ScoutSuite/Security Hub report
  • Deciding which misconfigurations actually matter
  • Setting preventive controls across AWS

Example prompts

  • “/hardening-cloud-posture”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Public exposure of data or compute. Public S3/GCS buckets and storage
  2. Identity that over-reaches. Wildcard Action/Resource policies, roles
  3. Missing or disabled audit logging. CloudTrail not multi-region, GCP Data
  4. Unencrypted data and absent key management. Real, but rarely the entry

What it can do on your machine

Read from SKILL.md and the folder at commit ca53957. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • defuddle.md

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hardening Cloud Posture loads about 1.9k tokens when it runs. Until then it costs about 143 tokens; SKILL.md has 987 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~143
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trilwu/secskills at commit ca53957, republished under its MIT licence (© trilwu). 987 words, ~1,925 tokens.

Download SKILL.mdSave it as .claude/skills/hardening-cloud-posture/SKILL.md (or your agent's skills folder).
name
hardening-cloud-posture
description
Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage, over-broad roles, missing audit logging, unencrypted data), reading CSPM output critically, and enforcing guardrails at the org level. Use when reviewing a cloud environment's security posture, triaging a Prowler/ScoutSuite/Security Hub report, deciding which misconfigurations actually matter, or setting preventive controls across AWS, Azure, or GCP.
verified
2026-07-27

Hardening Cloud Posture

A CSPM scan returns a thousand findings. Almost none of them are the way in. The job is not to close a thousand findings; it is to find the handful that form an attack path and close those, then set guardrails so they cannot recur. Posture work that treats every finding as equal drowns the real one.

The organizing principle: identity is the perimeter. In cloud, the attack path is almost always a chain of IAM permissions, not a network hop. Rank by "what does this let a principal reach?", not by a scanner's severity label.

When to Use

  • Reviewing an AWS/Azure/GCP account or organization's security posture
  • Triaging a Prowler, ScoutSuite, Security Hub, or Defender for Cloud report
  • Deciding which of many misconfigurations actually matter
  • Setting preventive guardrails (SCPs, Azure Policy, org policies)
  • Enabling the logging and controls an investigation will later depend on

When NOT to Use

  • Actively investigating a live incident — use investigating-aws-incidents, investigating-azure-incidents, or investigating-gcp-incidents
  • Attacking the environment to prove the path — use exploiting-cloud-platforms
  • Kubernetes cluster-plane hardening — use defending-kubernetes
  • Ranking CVEs in workloads rather than cloud config — use managing-vulnerabilities

Rank by Attack Path, Not Finding Count

Work findings in the order an attacker would exploit them, not the order the scanner lists them:

  1. Public exposure of data or compute. Public S3/GCS buckets and storage accounts, publicly reachable databases, management ports open to 0.0.0.0/0. These need no credential — they are pre-authentication. Close first.
  2. Identity that over-reaches. Wildcard Action/Resource policies, roles assumable by * or by external accounts without a condition, users with iam:PassRole to a privileged role, service principals with Owner. This is where a foothold becomes account-takeover.
  3. Missing or disabled audit logging. CloudTrail not multi-region, GCP Data Access logs off, Azure diagnostic settings absent. This does not create the breach but it blinds the investigation — enable it now, because you cannot retroactively log the incident you are about to have.
  4. Unencrypted data and absent key management. Real, but rarely the entry path. Fix after the above unless a compliance obligation reorders it.

A public bucket with customer data outranks a hundred "encryption not enabled" findings, even though the scanner may score them alike.

Read CSPM Output Critically

Prowler, ScoutSuite, Security Hub, and Defender for Cloud are the standard tools and they are useful — but their output is a starting point, not a verdict:

  • Severity is generic. The tool does not know your environment. A "medium" on a role assumable cross-account may be your worst finding; a "high" on an internal-only resource may be noise.
  • Findings lack blast radius. The tool reports that a policy has *; it does not tell you that role is attached to an internet-facing function. You supply the reachability.
  • Suppressions hide real risk. A finding suppressed months ago "because it was accepted" may no longer be acceptable. Review the suppression list as carefully as the open findings.
  • Green is not clean. The scanner checks what it checks. A passing scan with Data Access logging disabled has a large blind spot it will never report as a finding.

Map the top findings to CIS Benchmark controls where a compliance frame helps, but do not let the benchmark set your priority — the benchmark is comprehensive, your remediation budget is not.

Guardrails Beat Findings

A fixed misconfiguration recurs the next time someone provisions a resource. A guardrail prevents the whole class:

  • AWS: Service Control Policies to deny public S3 org-wide, deny disabling CloudTrail, restrict regions; s3:BlockPublicAccess at the account level.
  • Azure: Azure Policy with deny effects for public network access, required encryption, required diagnostic settings.
  • GCP: Organization Policy constraints (storage.publicAccessPrevention, iam.disableServiceAccountKeyCreation, compute.requireOsLogin).

Prefer the org-level deny over the per-resource fix. The point-fix closes one finding; the guardrail closes the class and every future instance of it.

Show full SKILL.md (362 more words)Show less

Rationalizations to Reject

  • "We closed all the high-severity findings." Severity is the scanner's guess about a generic environment. The finding that matters is the one on the attack path, whatever it is labelled.
  • "The scan is green, so the account is secure." The scan covers its checks. Disabled logging, an over-broad role the tool rates low, and a suppressed finding are all invisible to a green result.
  • "Encryption-at-rest is our top gap." Rarely the entry path. A public bucket or a cross-account-assumable admin role outranks it unless compliance forces the order.
  • "We fixed the public bucket." One bucket. Without an org-level guardrail the next team makes the same bucket public next week. Fix the class.
  • "That finding was accepted as a risk." By whom, when, and is it still true? Stale acceptances are where real exposure hides.
  • "IAM is too complex to audit fully." Then audit the escalation primitives first — PassRole, wildcard trust policies, cross-account assume — not nothing. Identity is the perimeter; it is not optional.

Reading External Sources

Fetch public advisories, specifications, and vendor reports as Markdown:

bash
curl -sL "https://defuddle.md/<url>"      # scheme in the path is optional

This strips page boilerplate — roughly 78% fewer tokens on a prose page — and returns the full text rather than a summary, so you can grep it and trust a negative result.

Three things it is not for. Fetch JSON and API responses raw, because readability extraction mangles structured data. Fetch authenticated or JavaScript-rendered pages directly, because it retrieves them anonymously. And never route adversary infrastructure (phishing links, C2, malware hosting), client-owned hosts, or engagement URLs through it — the request leaves your machine to a third party, and for live adversary infrastructure it also tips off the operator.

Some sites block the extractor and return an error blob rather than the page — {"error":"Failed to fetch: 418 I'm a teapot"} from freedesktop.org, for instance. That is the fetch being refused, not the source saying the thing does not exist. Re-fetch the URL directly before drawing any conclusion from it.

References

  • exploiting-cloud-platforms — the attack paths this posture work closes
  • investigating-aws-incidents / investigating-azure-incidents / investigating-gcp-incidents — what the audit logging you enable here feeds
  • defending-kubernetes — the cluster plane, when the account runs managed k8s
  • managing-vulnerabilities — the workload-CVE counterpart to config posture

© trilwu, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in secskills-defense/skills/hardening-cloud-posture of trilwu/secskills.

Open the folder on GitHubat commit ca53957

Compare with similar skills

Hardening Cloud Posture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hardening Cloud Posture compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hardening Cloud Posture this skilltrilwu/secskills157—~1.9kAutomated safety check: PassMIT
Cloud Securityborghei/Claude-Skills891—~3.5kAutomated safety check: PassMIT
Cloud Auditbriiirussell/cybersecurity-skills413—~1.3kAutomated safety check: NotesMIT
Auditing Cloud With Cis Benchmarksmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Configuring Firewallsancoleman/ai-design-components525—~3.5kAutomated safety check: NotesMIT

Similar skills

  • Cloud Security

    borghei/Claude-Skills

    Cloud posture security across AWS, Azure, and GCP — IAM least privilege, public exposure, encryption, logging coverage, landing-zone guardrails.

    891 GitHub stars~3.5k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Auditing Cloud With Cis Benchmarks

    mukul975/Anthropic-Cybersecurity-Skills

    Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Implementing Cloud Security Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Configuring Firewalls

    ancoleman/ai-design-components

    Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts.

    525 GitHub stars~3.5k tokensUpdated 10 mo ago
    SecurityAuto-check: notes
  • Cloud Misconfig Auditor

    criptogus/agent-evolve-network

    Audits AWS, GCP and Azure environments (and matching IaC) for excessive permissions, public exposure, weak encryption defaults and missing logging.

    288 GitHub stars~965 tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from trilwu/secskills

All 50 skills in this repo
  • Audit source code for exploitable vulnerabilities using threat-model-driven review, taint tracing, invariant checking, and variant analysis.

    157 GitHub stars~3.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Perform OSINT, subdomain enumeration, port scanning, web reconnaissance, email harvesting, and cloud asset discovery for initial access.

    157 GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check: notes
  • Securing AI Systems

    trilwu/secskills

    Assess and harden LLM applications and agentic systems against prompt injection, tool misuse, excessive agency, memory poisoning, RAG data leakage, and model supply-chain risk, mapped to the OWASP…

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Binaries

    trilwu/secskills

    Reverse engineer compiled binaries, firmware, and mobile app packages using triage, static disassembly, decompilation, and dynamic instrumentation.

    157 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing Go Binaries

    trilwu/secskills

    Reverse engineer Go binaries by recovering function names and types from pclntab and moduledata using GoReSym, redress, and IDA/Ghidra Go plugins, and by reading Go's non-standard calling…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Analyzing iOS Binaries

    trilwu/secskills

    Analyze iOS applications at the binary level — decrypting FairPlay-protected IPAs with frida-ios-dump or bagbak, inspecting Mach-O load commands, recovering Objective-C headers with class-dump, and…

    157 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Hardening Cloud Posture

What does Hardening Cloud Posture do?

Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage…. Hardening Cloud Posture is an agent skill from trilwu/secskills. Proactively harden a cloud account or organization before an incident — prioritizing IAM and identity risk over checkbox findings, closing the exposures that become attack paths (public storage, over-broad roles, missing audit logging, unencrypted data), reading CSPM output critically, and enforcing guardrails at the org level.

When should I use Hardening Cloud Posture?

Hardening Cloud Posture fits situations like: reviewing a cloud environments security posture; triaging a Prowler/ScoutSuite/Security Hub report; deciding which misconfigurations actually matter; setting preventive controls across AWS.

How do I install Hardening Cloud Posture in Claude Code?

Run `npx skills add trilwu/secskills --skill hardening-cloud-posture -a claude-code`. Or copy the skill folder (secskills-defense/skills/hardening-cloud-posture in trilwu/secskills) into .claude/skills/hardening-cloud-posture in your project. Claude Code loads it when a task matches its description.

How do I install Hardening Cloud Posture in Codex?

Run `npx skills add trilwu/secskills --skill hardening-cloud-posture -a codex`. Or copy the skill folder (secskills-defense/skills/hardening-cloud-posture in trilwu/secskills) into .agents/skills/hardening-cloud-posture in your project. Codex loads it when a task matches its description.

Can I use Hardening Cloud Posture in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trilwu/secskills --skill hardening-cloud-posture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hardening-cloud-posture, .gemini/skills/hardening-cloud-posture, .github/skills/hardening-cloud-posture and .opencode/skills/hardening-cloud-posture in your project.

What does Hardening Cloud Posture need to run?

Going by SKILL.md and its folder, Hardening Cloud Posture needs the command-line tools its instructions call (curl).

Does Hardening Cloud Posture access the network?

SKILL.md names 1 domain. In commands or code: defuddle.md; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Hardening Cloud Posture safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Hardening Cloud Posture use?

Hardening Cloud Posture is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hardening Cloud Posture use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Hardening Cloud Posture?

Skills that share tags, products or a category with Hardening Cloud Posture: Cloud Security (borghei/Claude-Skills, 891 stars), Cloud Audit (briiirussell/cybersecurity-skills, 413 stars), Auditing Cloud With Cis Benchmarks (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hardening Cloud Posture?

trilwu (a GitHub user) maintains it in trilwu/secskills, which has 157 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on September 4, 2026.

Source: trilwu/secskills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.