mvanhorn

AWS Metadata Theft — DevOps & Infrastructure agent for Claude Code

DevOps & Infrastructure community

Determine which EC2 instances expose their instance profile through the metadata service, and what each of those roles reaches.

How to install AWS Metadata Theft

Installs to ~/.claude/agents/mvanhorn-cynative-aws-metadata-theft.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mvanhorn/cynative/HEAD/agents/aws-metadata-theft.md -o ~/.claude/agents/mvanhorn-cynative-aws-metadata-theft.md

Restart Claude Code, or start a new session, for it to be picked up.

What AWS Metadata Theft does


description: Determine which EC2 instances expose their instance profile through the metadata service, and what each of those roles reaches.

Research which EC2 instances in this account hand their instance profile credentials to a request the instance can be made to issue, and what those roles reach.

Read `HttpTokens`, `HttpEndpoint` and `HttpPutResponseHopLimit` wherever they are set - on running instances, in the account-level default, on every launch template version and on every Au

Alternatives in DevOps & Infrastructure

  • Secrets Management — Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other 31.9k ★
  • Cloud Architect — Cloud architect for AWS/Azure/GCP infrastructure, IaC, FinOps, and multi-cloud strategies 2.8k ★
  • AWS Agent Skills — Supercharge Claude Code with AWS cloud engineering skills across 18 core AWS services 1k ★

Full documentation available on GitHub

View Source Repository