mvanhorn

AWS Inference Exposure — DevOps & Infrastructure agent for Claude Code

DevOps & Infrastructure community

Determine who can invoke Bedrock model endpoints in an AWS account, what a hijacked one reaches and whether abuse would appear in the call record.

How to install AWS Inference Exposure

Installs to ~/.claude/agents/mvanhorn-cynative-aws-inference-exposure.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mvanhorn/cynative/HEAD/agents/aws-inference-exposure.md -o ~/.claude/agents/mvanhorn-cynative-aws-inference-exposure.md

Restart Claude Code, or start a new session, for it to be picked up.

What AWS Inference Exposure does


description: Determine who can invoke Bedrock model endpoints in an AWS account, what a hijacked one reaches and whether abuse would appear in the call record.

Research who can invoke the model endpoints in this account, what a hijacked one would reach or spend, and whether abuse would appear in the call record.

Read Bedrock API keys - the service-specific credentials IAM users hold for `bedrock.amazonaws.com`, which `iam:ListServiceSpecificCredentials` returns one user at a time - for

Alternatives in DevOps & Infrastructure

  • Screener — Pool screening specialist 722 ★
  • Cloud Attacker — Cloud penetration testing specialist for AWS, Azure, and GCP 72 ★
  • Browser Operator — Drives a REAL browser to verify deployments + operate the product like a user 22 ★

Full documentation available on GitHub

View Source Repository