What problem does it solve?
Keeping track of IAM roles, policies, users, keys, and reports is tedious across AWS accounts, and manual checks can miss misconfigurations or expired credentials, so this skill centralizes permission inspection, lifecycle management, and credential auditing.
Core Features & Use Cases
- Role & Policy Inspection: Retrieve role definitions, attached and inline policies, tags, and trust relationships to understand who can do what.
- User & Credential Audits: List users, access keys, MFA devices, and generate credential reports to validate secure authentication settings.
- Simulation & Lifecycle Management: Run SimulatePrincipalPolicy calls, attach or detach policies, and create or delete IAM resources while referencing service integrations for Lambda, EC2, Glue, and CloudFormation.
Quick Start
Ask the awsclaw-iam skill to list the attached policies and tags for your role and simulate its permissions to verify access boundaries.