mvanhorn

AWS Container Isolation — Security agent for Claude Code

Security community

Determine which running ECS tasks cross the boundary to the host that runs them, what the container instance behind each one reaches, and which EKS clusters carry no cluster security group.

How to install AWS Container Isolation

Installs to ~/.claude/agents/mvanhorn-cynative-aws-container-isolation.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mvanhorn/cynative/HEAD/agents/aws-container-isolation.md -o ~/.claude/agents/mvanhorn-cynative-aws-container-isolation.md

Restart Claude Code, or start a new session, for it to be picked up.

What AWS Container Isolation does


description: Determine which running ECS tasks cross the boundary to the host that runs them, what the container instance behind each one reaches, and which EKS clusters carry no cluster security group.

Research which ECS task definitions actually running in this account cross the boundary to the host that runs them, and which EKS clusters carry no cluster security group.

Take the revisions to read from the running services and tasks themselves, each of which records the revision it ru

Alternatives in Security

Full documentation available on GitHub

View Source Repository