aws-security-audit

Audits AWS IAM configurations and CloudTrail API events for compliance.

627|175|Updated Feb 19, 2026
One-click install
npx skills add https://github.com/automateyournetwork/netclaw --skill aws-security-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: aws-security-audit
Source: https://github.com/automateyournetwork/netclaw/tree/main/workspace/skills/aws-security-audit
Command: npx skills add https://github.com/automateyournetwork/netclaw --skill aws-security-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill helps you proactively identify and remediate security vulnerabilities within your AWS environment by auditing IAM configurations and CloudTrail logs.

Core Features & Use Cases

  • IAM Auditing: Inspect users, roles, policies, and access keys for misconfigurations and overly permissive access.
  • CloudTrail Analysis: Trace API activity to investigate security incidents and ensure compliance.
  • Use Case: A security engineer can use this skill to quickly generate a report on all IAM roles used by network services, identify any users lacking MFA, and check for recent suspicious API calls related to security group modifications.

Quick Start

Audit AWS security posture by inspecting IAM users, roles, policies, and CloudTrail API events.

Frequently Asked Questions about aws-security-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit AWS IAM configurations for security misconfigurations?

This skill audits AWS security posture by inspecting IAM users, roles, policies, and CloudTrail API events. It traces API activity across multiple regions to investigate security incidents and ensure compliance by analyzing configurations and access keys.

How can I trace CloudTrail API events to investigate a security incident?

Tracing CloudTrail API events involves analyzing API activity across multiple AWS regions to investigate security incidents. This skill inspects CloudTrail logs to identify recent suspicious API calls, such as security group modifications, ensuring compliance.

What do I need to audit AWS IAM and CloudTrail logs using MCP servers?

You need valid AWS credentials and access to IAM and CloudTrail MCP servers. The skill uses these MCP servers to perform read-only operations, inspecting IAM configurations and CloudTrail API events across multiple regions for compliance and incident investigation.

Can I check for IAM users lacking MFA and roles with overly permissive access?

Yes, you can check for IAM users lacking MFA and roles with overly permissive access. The skill inspects IAM users, roles, policies, and access keys to identify misconfigurations and generate a report on your security posture.

Does this AWS security audit support read-only access across multiple regions?

Yes, this AWS security audit supports read-only access across multiple regions. It requires AWS credentials and uses IAM and CloudTrail MCP servers to perform read-only operations, tracing API activity and analyzing configurations without making changes.