basitalisandhu

AWS Security Skills — Security skill for Claude Code

Security community

Claude Code skills for AWS security: a plugin with five skills for a read-only account audit, SCP guardrail builder and linter, blast-radius landing zone design, IAM least-privilege review and Securit.

How to install AWS Security Skills

This entry records only its repository, not the path inside it, so there is no exact command to give. Open basitalisandhu/aws-security-skills and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What AWS Security Skills does

Claude Code skills for AWS security: a plugin with five skills for a read-only account audit, SCP guardrail builder and linter, blast-radius landing zone design, IAM least-privilege review and Security Hub and GuardDuty triage. Tested standard-library scripts evaluate saved aws CLI output offline.

Alternatives in Security

  • Goal Prompt Builder — Build audit-friendly /goal prompts for OpenAI Codex 225 ★
  • AWS MCP Server — by alexei-led - Features multiple Python environment setup options with detailed code style guidelines, compre 182 ★
  • Public Skills Builder — Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no 155 ★

README

Claude Code skills for AWS security

**AWS security skills for Claude Code: account audit, SCP guardrails, blast-radius landing zones, IAM least privilege, Security Hub triage.**

aws-security-skills is a Claude Code plugin marketplace with one plugin, `aws-security`, holding five skills. Each skill is a fixed procedure plus a tested Python script (standard library only). The skills tell Claude which read-only `aws` CLI commands to run and where to save the JSON; the scripts then evaluate that saved output offline, so results are repeatable, reviewable by someone without account access, and produced without the script ever touching AWS.

It is written for cloud and platform engineers who look after one or many AWS accounts, especially multi-account organizations governed by service control policies. It exists because the same questions come up on every account (is root protected, is CloudTrail on, can this role escalate, which SCPs go where, what do we fix first in Security Hub), and a scripted procedure answers them the same way each time.

No network access from the scripts, no telemetry. Nothing in this repository changes an AWS account: every skill proposes fix commands and runs one only after you confirm that exact command.

Quickstart

In a Claude Code session:

/plugin marketplace add basitalisandhu/aws-security-skills
/plugin install aws-security@aws-security-skills

Then ask, for example: "Audit the AWS account I am logged into, regions us-east-1 and ap-southeast-2." Claude follows `aws-account-audit`: it shows the caller identity, collects read-only CLI output into `./aws-audit-/`, runs the audit script, and reports findings with evidence.

From a shell:

claude plugin marketplace add basitalisandhu/aws-security-skills
claude plugin install aws-security@aws-security-skills --scope user

To try it without installing, clone the repository and start Claude Code with `claude --plugin-dir ./plugins/aws-security`. The scripts a