mvanhorn

AWS Policy Exposure — DevOps & Infrastructure agent for Claude Code

DevOps & Infrastructure community

Classify every non-storage AWS resource policy as anonymous, external-account or internal, and resolve the outside accounts each one names.

How to install AWS Policy Exposure

Installs to ~/.claude/agents/mvanhorn-cynative-aws-policy-exposure.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/mvanhorn/cynative/HEAD/agents/aws-policy-exposure.md -o ~/.claude/agents/mvanhorn-cynative-aws-policy-exposure.md

Restart Claude Code, or start a new session, for it to be picked up.

What AWS Policy Exposure does


description: Classify every non-storage AWS resource policy as anonymous, external-account or internal, and resolve the outside accounts each one names.

Research which Lambda functions, SNS topics, SQS queues, SES identities, Secrets Manager secrets, KMS keys, EventBridge buses and schema registries, CloudWatch log groups, Glue Data Catalogs, VPC endpoints and endpoint services and Transit Gateways in this account grant access to a principal outside the account, and what that principal

Alternatives in DevOps & Infrastructure

  • Cloud Recon — Cloud misconfiguration scanner 812 ★
  • Vibe Coder — Fullstack vibe coding assistant 51 ★
  • AWS Integration — Configure and manage AWS integration for monitoring, log collection, and resource tracking across AWS accounts 42 ★

Full documentation available on GitHub

View Source Repository