What problem does it solve? AI agents frequently produce incorrect answers about AWS IAM edge cases such as policy evaluation quirks, STS session limits, trust policy requirements, and Organizations behaviors, leading to broken configurations and security gaps. ## Core Features & Use Cases - Verified Edge-Case Corrections: Documents confirmed behaviors for CloudTrail logging, STS session restrictions, role chaining limits, and SAML federation specifics. - Policy Evaluation Guidance: Explains ForAllValues vacuous truth, PassRole privilege escalation paths, permissions boundary bypasses, and the eight privilege escalation actions. - SDK and Service Specifics: Covers boto3 IAM method names, Organizations exception names, Redshift Serverless trust policies, and OIDC thumbprint changes. - Use Case: When writing an IAM policy that restricts EC2 tagging or troubleshooting a cross-account AssumeRole failure into an opt-in region, consult this Skill to avoid known pitfalls before deploying. ## Quick Start Ask the agent to review your IAM policy or answer an IAM question using the aws-iam skill to check for known pitfalls.