What problem does it solve?
This Skill audits cloud IAM (AWS/Azure/GCP) for least privilege risks, identifying over-permissioned identities, wildcard/admin grants, public or cross-account access, unused credentials, and privilege-escalation paths.
Core Features & Use Cases
- Identity Risk Assessment: Identifies over-permissioned identities, dangerous permissions, external exposure, credential hygiene issues, and privilege-escalation paths.
- Excess Privilege Detection: Flags wildcard actions/resources, admin/owner roles, and unused permissions vs. actual usage.
- External Exposure Analysis: Identifies public principals, cross-account/cross-tenant trust, and federated/external identities.
- Credential Hygiene Review: Checks long-lived keys, MFA on privileged users, and root/break-glass usage.
- Escalation Path Tracing: Traces escalation paths from low-priv to high-priv identities.
- Use Case: Automate the review of cloud IAM configurations to ensure least privilege, reducing the risk of cloud compromise.
Quick Start
Use the cloud-iam-review skill to audit IAM configurations for the AWS account 'my-account-id'.