Topic · Security
Best cloud security skills for Claude Code, Codex and other agents.
- skills
- 90
- official
- 21
Cloud security skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | 1.Fedramp Expert guidance for FedRAMP certification and compliance under CR26 (FedRAMP Consolidated Rules for 2026). | Sushegaad/ | 939 | 1 repo | ~4.4k | Automated safety check: Pass | MIT | 2 days ago |
| 2 | Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references. | LukasNiessen/ | 444 | — | ~1.2k | Automated safety check: Pass | MIT | 24 days ago |
| 3 | Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants. | google/ | 21k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | today |
| 4 | Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity. | thomast1906/ | 202 | — | ~3.1k | Automated safety check: Pass | MIT | 2 mo ago |
| 5 | Cloud and container security auditing workflow using prowler, trivy, kube-hunter, and docker-bench for AWS, GCP, Azure, Kubernetes, and container images | CommonHuman-Lab/ | 156 | — | ~1.1k | Automated safety check: Pass | Unknown | today |
| 6 | Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps. | briiirussell/ | 412 | — | ~1.3k | Automated safety check: Notes | MIT | 4 mo ago |
| 7 | A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. | AratKruglik/ | 155 | 1 repo | ~1.1k | Automated safety check: Notes | No licence | 5 mo ago |
| 8 | Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks. | briiirussell/ | 412 | — | ~2.5k | Automated safety check: Notes | MIT | 4 mo ago |
| 9 | Turns a company's domains into likely storage bucket names and checks six cloud providers for publicly readable buckets, for authorized security assessments only. | forefy/ | 152 | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |
| 10 | Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI. | luongnv89/ | 131 | — | ~4.5k | Automated safety check: Pass | MIT | today |
| 11 | Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review. | Jeffallan/ | 12k | — | ~1.3k | Automated safety check: Pass | MIT | 4 days ago |
| 12 | Secure secrets in Google Cloud Secret Manager. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 3 repos | ~3.3k | Automated safety check: Pass | MIT | yesterday |
| 13 | Scans Android APKs for Firebase security misconfigurations such as open databases, storage buckets, weak authentication and exposed cloud functions, for authorized testing only. | trailofbits/ | 7.4k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 14 | Azure Key Vault Keys Java SDK for cryptographic key management. | microsoft/ | 3.1k | 5 repos | ~2.9k | Automated safety check: Pass | MIT | yesterday |
| 15 | Azure Key Vault Secrets Java SDK for secret management. An agent skill from microsoft/skills. | microsoft/ | 3.1k | 5 repos | ~3.1k | Automated safety check: Pass | MIT | yesterday |
| 16 | 16.Iam AWS Identity and Access Management for users, roles, policies, and permissions. | itsmostafa/ | 1.2k | — | ~1.8k | Automated safety check: Pass | MIT | yesterday |
| 17 | Verification loop for Quarkus projects: build, static analysis (Checkstyle, PMD, SpotBugs), tests with JaCoCo coverage, OWASP dependency and container security scans, GraalVM native compilation… | affaan-m/ | 274k | 1 repo | ~2.7k | Automated safety check: Pass | MIT | 2 days ago |
| 18 | Azure Key Vault Keys SDK for .NET. An agent skill from microsoft/skills. | microsoft/ | 3.1k | 5 repos | ~3.1k | Automated safety check: Pass | MIT | yesterday |
| 19 | AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment | Hack23/ | 239 | — | ~2.3k | Automated safety check: Pass | Apache-2.0 | today |
| 20 | Audits AWS, GCP and Azure environments (and matching IaC) for excessive permissions, public exposure, weak encryption defaults and missing logging. | criptogus/ | 288 | — | ~965 | Automated safety check: Pass | CC-BY-SA-4.0 | 27 days ago |
| 21 | 21.AWS Iam Manage IAM users, roles, and policies. An agent skill from sickn33/agentic-awesome-skills. | sickn33/ | 47k | 2 repos | ~3.4k | Automated safety check: Pass | MIT | yesterday |
| 22 | Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and… | hardw00t/ | 104 | — | ~2.8k | Automated safety check: Pass | No licence | 5 mo ago |
| 23 | Implement multi-cloud CSPM to detect cloud-native misconfigurations and vulnerabilities (IAM over-permissions, exposed storage, unencrypted data, missing network controls) using AWS Security Hub… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 24 | Run the agentless, open-source ScoutSuite tool (via pip install and the scout CLI) against an AWS account to enumerate resources across services, identify misconfigurations, and generate an… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 25 | Execute cloud-native incident containment across AWS, Azure, and GCP using platform CLIs to revoke or disable compromised IAM credentials, isolate resources with security groups and network ACLs… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 26 | Set up the Datadog AWS integration with Terraform - creates the cross-account IAM role Datadog assumes (external ID, no stored credentials), attaches the permission policies Datadog publishes, and… | datadog-labs/ | 177 | — | ~6.8k | Automated safety check: Notes | MIT | 5 days ago |
| 27 | Harden Docker/container images and runtime deployments with secure base images, non-root users, CVE scanning, SBOM/signing, seccomp/AppArmor, and Kubernetes pod security controls. | sickn33/ | 47k | 1 repo | ~1k | Automated safety check: Notes | MIT | yesterday |
| 28 | Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Respond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit Logs), resource isolation, and forensic… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 30 | Exploits privileged pods, host mounts, runC CVEs, and exposed Docker sockets to break out of a container and reach the underlying host during an authorized container-security assessment. | mukul975/ | 34k | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | Deploy AWS Security Hub as a centralized CSPM platform, backed by AWS Config, aggregating findings from GuardDuty, Inspector, Macie, and third-party tools; enable CIS Foundations, PCI-DSS, and NIST… | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | Deploy AWS Security Hub, backed by AWS Config, to aggregate findings from GuardDuty, Inspector, Macie, Firewall Manager, and Prowler across multi-account AWS Organizations, enable standards like CIS… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 33 | Enable Microsoft Defender for Cloud (CSPM + CWPP) across VMs, containers, SQL, storage, and Key Vault, using Azure Policy for evaluation, Log Analytics for telemetry, Azure Arc for hybrid coverage… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 34 | Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 35 | Uses AWS Athena to query CloudTrail, VPC Flow Logs, S3 access logs, and ALB logs for forensic investigation. | mukul975/ | 34k | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 36 | Hardens AWS IAM configurations to enforce least-privilege access, covering IAM policy scoping, permission boundaries, IAM Access Analyzer integration, and credential rotation strategies. | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 37 | Hardens AWS Lambda execution roles by writing least-privilege IAM policies, applying permission boundaries, restricting resource-based policies, validating permissions with IAM Access Analyzer, and… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 38 | Deploys and configures Microsoft Defender for Cloud as a CNAPP for Azure, multi-cloud, and hybrid environments: enabling Defender plans for servers, containers, storage, and databases, configuring… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 39 | Implement Kubernetes security contexts, Pod Security Standards, and network policies. | sickn33/ | 47k | 1 repo | ~858 | Automated safety check: Pass | MIT | yesterday |
| 40 | Generates and updates secure, production-ready Kubernetes YAML manifests optimized for GKE Autopilot and GKE Standard clusters. | google/ | 21k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | today |
| 41 | Audit Azure Blob and ADLS storage accounts for public access exposure, weak or long-lived SAS tokens, missing encryption at rest, disabled HTTPS-only traffic, and outdated TLS versions, using the… | mukul975/ | 34k | — | ~732 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 42 | Implements security monitoring using Datadog Cloud SIEM, Cloud Security Management (CSM), and Workload Protection to detect threats, enforce compliance, and respond to security events across cloud… | mukul975/ | 34k | — | ~3.7k | Automated safety check: Notes | Apache-2.0 | 1 mo ago |
| 43 | Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed… | mukul975/ | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 44 | Performing comprehensive security assessments of Google Cloud Platform environments using Forseti Security, Security Command Center, and gcloud CLI to audit IAM policies, firewall rules, storage… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 45 | Configure host-based firewalls (iptables, nftables, UFW) and cloud security groups (AWS, GCP, Azure) with practical rules for common scenarios like web servers, databases, and bastion hosts. | ancoleman/ | 526 | — | ~3.5k | Automated safety check: Notes | MIT | 10 mo ago |
| 46 | Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks. | aiskillstore/ | 430 | 6 repos | ~2.6k | Automated safety check: Pass | No licence | today |
| 47 | AWS security finding analysis: analyze findings, map to Atmos components/stacks, generate structured remediation with exact Terraform changes and deploy commands | cloudposse/ | 1.4k | — | ~867 | Automated safety check: Pass | Apache-2.0 | today |
| 48 | Creates and manages secrets in AWS Secrets Manager following security best practices. | aws/ | 2.8k | 1 repo | ~461 | Automated safety check: Pass | Apache-2.0 | today |
Questions, answered from the data.
What is the best cloud security skill?
Fedramp from Sushegaad/Claude-Skills-Governance-Risk-and-Compliance ranks first of the 90 cloud security skills listed here, with the highest score: its repository has 939 GitHub stars, 1 other GitHub owner carry a copy, its SKILL.md loads about 4.4k tokens and it passes the automated safety check with no findings. Next come KubeShark for Kubernetes and Google Cloud PAM Helper.
Which cloud security skills are official?
21 of the 90 cloud security skills are official, published by the vendor's own GitHub organization: Google Cloud PAM Helper, Firebase APK Security Scanner, Azure Security Keyvault Keys Java, Azure Security Keyvault Secrets Java, Azure Security Keyvault Keys Dotnet and 16 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
More topics in Security
- Security review611
- Web application vulnerabilities460
- Vulnerability scanning303
- Static analysis and SAST281
- Security operations248
- Supply chain security242
- Threat modeling207
- Penetration testing183
- Cryptography155
- Prompt injection and agent security154
- Red teaming and adversary simulation147
- Reverse engineering and malware132
- OSINT117
- Secure coding105
- Digital forensics86
- Smart contract auditing80
- Fuzzing75
- Bug bounty74
- Network security66
- Capture the flag45
- Mobile application security42
- Access reviews and audit trails34