AWS Hardcoded Secrets — DevOps & Infrastructure agent for Claude Code
Find credentials sitting in AWS resource configuration and bound what each one reaches using the account's own APIs.
How to install AWS Hardcoded Secrets
Installs to ~/.claude/agents/mvanhorn-cynative-aws-hardcoded-secrets.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mvanhorn/cynative/HEAD/agents/aws-hardcoded-secrets.md -o ~/.claude/agents/mvanhorn-cynative-aws-hardcoded-secrets.md Restart Claude Code, or start a new session, for it to be picked up.
What AWS Hardcoded Secrets does
description: Find credentials sitting in AWS resource configuration and bound what each one reaches using the account's own APIs.
Research whether any credential is sitting in plaintext in the configuration of this account's resources, and what each one reaches.
Fetch the eleven configuration surfaces that carry free-text values: EC2 instance user data, launch template user data, Lambda function environment variables, ECS task definition environment variables, AWS Batch job definition
Alternatives in DevOps & Infrastructure
- Secrets Management — Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other 31.9k ★
- Deployment Expert — Specializes in Vercel deployment strategies, CI/CD pipelines, preview URLs, production promotions, rollbacks 263 ★
- Bazel CI Analyzer — Use this agent when:\\n- The user needs to analyze or optimize Bazel configuration in CI/CD pipelines, particu 216 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
AWS Supply Chain
Find the CodeBuild, CodeArtifact, Lambda layer and CDK paths that admit code or a build trigger from outside a
AWS Domain Takeover
Find AWS DNS records and resource references whose target no longer exists in the account, and registered doma
AWS Integration
Configure and manage AWS integration for monitoring, log collection, and resource tracking across AWS accounts
AWS Architect
AWS solutions architect: Well-Architected reviews, multi-account landing zones with AWS Organizations and Cont
Cloud Manager
Owns cloud architecture across AWS/Azure/GCP — account/subscription/project structure, landing zones, networki
Senior Fullstack Engineer
Use this agent when the user needs production-grade software engineering work across the full stack — backend
Related Skills
Audit Credentials
Find long-lived tokens, hardcoded secrets, and credentials that should be rotated or replaced
Secret Crusade
Unleash parallel Secret Purist agents to scan the codebase and git history for leaked credentials, API keys, a
Secrets Hunt
Hunt leaked credentials in a filesystem path, git history, JS bundles from a recon run, or an entire GitHub or