AWS Security Assessment — AGNI 🔥

Detect AWS infrastructure misconfigurations across IAM, S3, EC2, RDS, Lambda, CloudTrail, and containers.

Updated Jun 3, 2026
One-click install
npx skills add https://github.com/jayjpatel9717/kurukshetra_updated --skill aws-security-assessment-agni
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: AWS Security Assessment — AGNI 🔥
Source: https://github.com/jayjpatel9717/kurukshetra_updated/tree/main/squads/cloud-security/agents/agni/skills/aws-security
Command: npx skills add https://github.com/jayjpatel9717/kurukshetra_updated --skill aws-security-assessment-agni

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires boto3, awscli, and includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill systematically assesses AWS infrastructure for security misconfigurations, providing in-depth analysis and vulnerability detection without exploitation.

Core Features & Use Cases

  • IAM Misconfigurations: Enumerate IAM users, roles, policies, and flags overly permissive policies.
  • S3 Bucket Security: Check for public access, bucket policies, and encryption settings.
  • EC2 & Compute Security: Detect IMDSv1, public security group rules, user data secrets, and public EBS snapshots.
  • RDS Database Security: Identify publicly accessible instances, default credentials, and encryption settings.
  • Lambda Security: Analyze Lambda functions for overly permissive roles, environment variables, and public URLs.
  • CloudTrail & Logging: Assess CloudTrail configuration and logging settings.
  • EKS/ECS Container Security: Verify container security posture and IAM role assignments.
  • Use Case: For an AWS environment with multiple resources, this Skill will provide a detailed security assessment, identifying potential risks and misconfigurations.

Quick Start

Run the 'AGNI' skill to initiate a comprehensive AWS security assessment.

Frequently Asked Questions about AWS Security Assessment — AGNI 🔥

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I run an AWS security assessment to detect misconfigurations across IAM, S3, and EC2?

To run an AWS security assessment, you need read-only access to your AWS resources. The assessment systematically detects misconfigurations across IAM, S3, EC2, RDS, Lambda, and CloudTrail without exploitation, providing an in-depth vulnerability analysis.

What is the best way to check my AWS infrastructure for overly permissive IAM policies and public S3 buckets?

Checking AWS infrastructure for security risks involves enumerating IAM users and roles to flag overly permissive policies, and verifying S3 bucket settings for public access and encryption. This systematic misconfiguration detection covers IAM, S3, and compute resources.

Can I use boto3 and awscli to audit EKS, ECS, and RDS security posture?

Yes, you can use boto3 and awscli to audit EKS, ECS, and RDS security posture. The assessment verifies container security and IAM role assignments for EKS/ECS, while identifying publicly accessible RDS instances and default credentials.

Does this AWS security assessment require write access to modify my CloudTrail and Lambda configurations?

No, this AWS security assessment does not require write access. It requires only read-only access to your AWS resources to analyze Lambda environment variables, public URLs, and CloudTrail logging settings without modifying your existing configurations.

How do I identify public security group rules and IMDSv1 usage in my EC2 compute environment?

Identifying EC2 compute security risks requires analyzing security group rules and instance metadata settings. The assessment detects IMDSv1 usage, public security group rules, user data secrets, and public EBS snapshots across your environment.

What AWS services are covered by a systematic cloud security misconfiguration detection process?

A systematic cloud security misconfiguration detection process covers IAM, S3, EC2, RDS, Lambda, CloudTrail, and container services like EKS and ECS. It assesses these AWS resources for public exposure, encryption settings, and logging configurations.