AWS Network Exposure — DevOps & Infrastructure agent for Claude Code
Determine which AWS network paths from the internet complete end to end, and what the identity attached to each exposed resource reaches.
How to install AWS Network Exposure
Installs to ~/.claude/agents/mvanhorn-cynative-aws-network-exposure.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mvanhorn/cynative/HEAD/agents/aws-network-exposure.md -o ~/.claude/agents/mvanhorn-cynative-aws-network-exposure.md Restart Claude Code, or start a new session, for it to be picked up.
What AWS Network Exposure does
description: Determine which AWS network paths from the internet complete end to end, and what the identity attached to each exposed resource reaches.
Research which EC2 instances, load balancer interfaces, ECS tasks, EKS clusters, Lightsail instances and EMR clusters in this account are reachable from the internet, which SageMaker notebooks, training jobs and models reach the internet with no isolation in the path, and what the identity attached to each one holds. A managed database or
Alternatives in DevOps & Infrastructure
- Secrets Management — Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other 31.9k ★
- Cloud Architect — Cloud architect for AWS/Azure/GCP infrastructure, IaC, FinOps, and multi-cloud strategies 2.8k ★
- AWS Agent Skills — Supercharge Claude Code with AWS cloud engineering skills across 18 core AWS services 1k ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
AWS Inference Exposure
Determine who can invoke Bedrock model endpoints in an AWS account, what a hijacked one reaches and whether ab
AWS Credential Exposure
Assess AWS root credentials, IAM user MFA state and long-lived access keys against what each one reaches.
Infrastructure Analyst
Analyzes infrastructure as code, plans, drift, IAM, network exposure, state layout and recovery from the Unkno
AWS Integration
Configure and manage AWS integration for monitoring, log collection, and resource tracking across AWS accounts
Cloud Recon
Cloud misconfiguration scanner. Use for S3 bucket enumeration, Azure blob discovery, GCP storage checks, expos
DevOps Agent
DevOps teammate — infrastructure, CI/CD, containers, configuration, and documentation. Claims tasks from the s
Related Skills
Cloud Arch Deck
Architecture diagrams and capability decks as editable PowerPoint — Azure, AWS and open source. Real vendor ic
Pyrycode Relay Agents
Agent instructions and dispatcher for pyrycode/pyrycode-relay. Forked from pyrycode/agents; per-role CLAUDE.md
API Security
API security audit (OWASP API Security Top 10 2023): BOLA/IDOR, broken authentication, broken object-property-