AWS Credential Exposure — DevOps & Infrastructure agent for Claude Code
Assess AWS root credentials, IAM user MFA state and long-lived access keys against what each one reaches.
How to install AWS Credential Exposure
Installs to ~/.claude/agents/mvanhorn-cynative-aws-credential-exposure.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mvanhorn/cynative/HEAD/agents/aws-credential-exposure.md -o ~/.claude/agents/mvanhorn-cynative-aws-credential-exposure.md Restart Claude Code, or start a new session, for it to be picked up.
What AWS Credential Exposure does
description: Assess AWS root credentials, IAM user MFA state and long-lived access keys against what each one reaches.
Research whether the root account or any IAM user in this account holds a credential that is usable as a way in, and how far each one reaches.
Read the account credential report and take, per user, the console password state, the MFA device state, and each access key's creation date, last-used date, last-used service and last-used region. Read the root account's MFA de
Alternatives in DevOps & Infrastructure
- Terraform Specialist — You are a Terraform/OpenTofu specialist focused on advanced infrastructure automation, state managem 31.9k ★
- Ark Build Manager — Triage and fix CI/CD build failures in Ark 419 ★
- Bazel CI Analyzer — Use this agent when:\\n- The user needs to analyze or optimize Bazel configuration in CI/CD pipelines, particu 216 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Infrastructure Analyst
Analyzes infrastructure as code, plans, drift, IAM, network exposure, state layout and recovery from the Unkno
AWS Hardcoded Secrets
Find credentials sitting in AWS resource configuration and bound what each one reaches using the account's own
AWS Inference Exposure
Determine who can invoke Bedrock model endpoints in an AWS account, what a hijacked one reaches and whether ab
Gagarin CI
Wires a repository's CI pipeline to deploy to Gagarin Cloud on push — mints a scoped deploy credential, stores
Design Reviewer Infra
The infrastructure reviewer of the stage-2 design review round — service configs, exposure, IAM, cost vs real
Kth
Cloud-native engineer and educator. Co-author of Kubernetes Up & Running (2017, 2019). Long-time Google Cloud
Related Skills
Bashrc Credential Guard
Always check ~/.bashrc for credentials, API keys, passwords, and configuration values before asking user
Sandy
Sandboxed TypeScript runtime for AI coding agents to query AWS — full SDK access with in-sandbox aggregation,
AWS
AWS patterns and best practices. Use when working with S3, Lambda, DynamoDB, IAM, SQS, or other AWS services.