aws-security

Automates AWS security baselines and incident-response patterns across multi-account environments.

Updated Apr 27, 2026
One-click install
npx skills add https://github.com/tomz/agent-skills --skill aws-security-tomz
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: aws-security
Source: https://github.com/tomz/agent-skills/tree/main/aws-security
Command: npx skills add https://github.com/tomz/agent-skills --skill aws-security-tomz

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

AWS environments struggle to implement consistent security controls across multiple services (IAM, KMS, Secrets Manager, guardrails, monitoring) and to maintain auditable trails in a multi-account setup.

Core Features & Use Cases

  • Comprehensive coverage across IAM, KMS, Secrets Manager, GuardDuty, Security Hub, WAF, Config, CloudTrail, SCPs, and Organizations to enforce security baselines.
  • Supports multi-account governance, compliance checks, encryption key management, secret rotation, and centralized auditing.
  • Use Case: An org with dozens of accounts can automatically apply and validate security baselines, detect misconfigurations, and generate incident-response playbooks.

Quick Start

Use predefined playbooks to apply AWS security baselines across your multi-account environment.

Frequently Asked Questions about aws-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I apply AWS security baselines across a multi-account environment?

You can apply AWS security baselines across multi-account setups using predefined playbooks that enforce controls via IAM, SCPs, and Organizations, automatically validating configurations and detecting misconfigurations.

What is the best way to centralize CloudTrail auditing and GuardDuty findings?

Centralizing CloudTrail auditing and GuardDuty findings is achieved by configuring Security Hub and Config to aggregate compliance checks and incident-response patterns across your organization's accounts.

Can I automate secret rotation and KMS encryption key management?

Yes, you can automate secret rotation and KMS encryption key management using built-in templates that manage Secrets Manager rotation schedules and enforce encryption baselines.

Does this approach support enforcing WAF and IAM policy compliance checks?

Yes, this approach supports enforcing WAF and IAM policy compliance by applying reusable checks and templates that satisfy industry baseline standards and continuously audit your security posture.

How do I generate incident-response playbooks for AWS security misconfigurations?

You generate incident-response playbooks for AWS security misconfigurations by using automated templates that detect issues across GuardDuty and Security Hub, providing actionable response patterns.