AWS Policy Exposure — DevOps & Infrastructure agent for Claude Code
Classify every non-storage AWS resource policy as anonymous, external-account or internal, and resolve the outside accounts each one names.
How to install AWS Policy Exposure
Installs to ~/.claude/agents/mvanhorn-cynative-aws-policy-exposure.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mvanhorn/cynative/HEAD/agents/aws-policy-exposure.md -o ~/.claude/agents/mvanhorn-cynative-aws-policy-exposure.md Restart Claude Code, or start a new session, for it to be picked up.
What AWS Policy Exposure does
description: Classify every non-storage AWS resource policy as anonymous, external-account or internal, and resolve the outside accounts each one names.
Research which Lambda functions, SNS topics, SQS queues, SES identities, Secrets Manager secrets, KMS keys, EventBridge buses and schema registries, CloudWatch log groups, Glue Data Catalogs, VPC endpoints and endpoint services and Transit Gateways in this account grant access to a principal outside the account, and what that principal
Alternatives in DevOps & Infrastructure
- Cloud Recon — Cloud misconfiguration scanner 812 ★
- Vibe Coder — Fullstack vibe coding assistant 51 ★
- AWS Integration — Configure and manage AWS integration for monitoring, log collection, and resource tracking across AWS accounts 42 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
AWS Supply Chain
Find the CodeBuild, CodeArtifact, Lambda layer and CDK paths that admit code or a build trigger from outside a
AWS Snapshot Exposure
Determine which AWS snapshots, AMIs and SSM documents are shared outside the account, whether the share is usa
GCP Architect
Google Cloud solutions architect: Well-Architected Framework reviews, resource hierarchy and organization poli
Sf Architect
Classify work, interview user, run impact analysis, design Salesforce Apex/LWC/Flow solutions, decompose into
Example CI Investigator
Classify a concrete CI failure or review-check discrepancy from logs and workflow files. Read-only diagnosis;
Production Docker Auditor
Audits Dockerfiles and container configuration for production hardening — multi-stage builds, non-root users,
Related Skills
API Security
API security audit (OWASP API Security Top 10 2023): BOLA/IDOR, broken authentication, broken object-property-
Evaluate Repo Security
Security-first evaluation of an external repository. Adversarial assessment of hooks, permissions, dependencie
Load Schema
Initialise the system by running schema-analyst to discover all tables, event names, columns and fields dynami