cloud-security-architect

Audit AWS, Azure, and GCP cloud security posture against CIS benchmarks.

1|Updated Mar 13, 2026
One-click install
npx skills add https://github.com/coreymaypray/sloth-skill-tree --skill cloud-security-architect
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cloud-security-architect
Source: https://github.com/coreymaypray/sloth-skill-tree/tree/main/plugins/maycrest-secure/skills/cloud-security-architect
Command: npx skills add https://github.com/coreymaypray/sloth-skill-tree --skill cloud-security-architect

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Cloud infrastructure misconfigurations and weak IAM and logging controls across AWS, Azure, and GCP create hidden attack surfaces. This Skill provides an end-to-end security architecture review that maps to industry benchmarks and governance requirements, enabling you to secure cloud workloads from the ground up.

Core Features & Use Cases

  • CIS Benchmark assessments across AWS, Azure, and GCP with automated scanning and manual validation
  • IAM policy analysis for least privilege, cross-account access, and key lifecycle controls
  • Network and storage security reviews (VPC/VNet design, SG/NACL rules, bucket permissions, encryption)
  • Logging, monitoring, and audit compliance mapping (CloudTrail, Activity Logs, SIEM integration)
  • Infrastructure-as-code security checks (Terraform, CloudFormation, ARM) with drift detection
  • Multi-cloud security governance and remediation roadmaps for consistent controls

Quick Start

Initiate a multi-cloud security posture assessment for AWS, Azure, and GCP to identify misconfigurations, IAM risks, and governance gaps.

Frequently Asked Questions about cloud-security-architect

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit multi-cloud security posture across AWS, Azure, and GCP?

To audit multi-cloud security posture, you need to identify misconfigurations, overly permissive IAM policies, and insecure network designs. This process involves automated scanning and manual validation to map controls across providers to CIS benchmarks.

What is the best way to validate CIS benchmarks for cloud infrastructure?

Validating CIS benchmarks requires assessing your cloud environments against industry-standard controls to identify governance gaps. You can perform posture assessments to verify logging, IAM policies, and network security configurations align with compliance requirements.

How do I review IAM policies for least privilege in multi-cloud environments?

Reviewing IAM policies for least privilege involves analyzing cross-account access, key lifecycle controls, and permission levels. This identifies overly permissive roles and entitlements across AWS, Azure, and GCP to reduce hidden attack surfaces.

Can I scan Infrastructure-as-Code for security misconfigurations before deployment?

You can scan Infrastructure-as-Code for security misconfigurations by checking Terraform, CloudFormation, and ARM templates. This validates infrastructure definitions against security controls and detects configuration drift before cloud workload deployment.

How do I assess VPC and VNet network security designs for cloud workloads?

Assessing VPC and VNet network security requires reviewing security group and NACL rules, subnet designs, and storage encryption settings. This identifies insecure network designs and verifies storage bucket permissions across multi-cloud deployments.

Does multi-cloud security governance require cross-provider remediation roadmaps?

Multi-cloud security governance requires cross-provider remediation roadmaps to ensure consistent controls across AWS, Azure, and GCP. Prioritized remediation steps align hardening efforts with CIS controls and enterprise compliance requirements.