cloud-security

Map cloud and AI workload threats to compliance controls for AWS, Azure, and GCP.

Updated May 11, 2026
One-click install
npx skills add https://github.com/blamejs/exceptd-skills --skill cloud-security-blamejs
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cloud-security
Source: https://github.com/blamejs/exceptd-skills/tree/main/skills/cloud-security
Command: npx skills add https://github.com/blamejs/exceptd-skills --skill cloud-security-blamejs

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Legacy security and compliance frameworks (NIST 800-53, ISO 27001, SOC 2) were designed for on-prem and early-cloud environments, and fail to address mid-2026 threats including cloud control plane abuse, workload identity federation misconfigurations, AI workload egress risks, and shared responsibility ambiguity for managed AI services. This skill bridges that gap with threat-informed, cloud-native guidance aligned to current attack patterns.

Core Features & Use Cases

  • Threat-informed TTP mapping: Maps cloud and AI workload attack techniques from MITRE ATT&CK and ATLAS to real-world mid-2026 incident patterns, including federation trust-policy abuse, IMDSv1 SSRF, and AI model registry tampering.
  • Compliance gap analysis: Explicitly flags where legacy framework controls are insufficient for modern cloud and AI workloads, with cross-jurisdiction coverage for NIS2, DORA, NYDFS 500, and 30+ regional regulations.
  • Layered defense guidance: Provides actionable steps for implementing CSPM drift detection, CIEM least-privilege IAM, eBPF runtime security, egress controls, and encryption tailored to ephemeral cloud-native and AI workloads.
  • Use Case: A cloud security engineer can use this skill to audit AWS IRSA trust policies for confused-deputy risks, map findings to NIST 800-53 and CSA CCM gaps, and generate evidence for a SOC 2 audit.

Quick Start

Use the cloud-security skill to audit your cloud workload identity federation policies for confused-deputy risks and generate a compliance gap report for NIST 800-53 and CSA CCM v4.

Frequently Asked Questions about cloud-security

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I map cloud workload identity federation abuse to MITRE ATT&CK and compliance frameworks?

Cloud control plane threats target the management APIs and configuration layers of AWS, Azure, and GCP, bypassing traditional network perimeter defenses and requiring posture assessments that map to modern MITRE ATT&CK techniques to secure ephemeral cloud-native workloads.

How do I close compliance gaps for AI workloads in AWS, Azure, and GCP?

You close compliance gaps for AI workloads by performing cross-jurisdiction posture assessments that flag insufficient legacy controls, mapping configurations to NIS2, DORA, NYDFS 23 NYCRR 500, and SOC 2 requirements across your cloud environments.

What is the best way to implement CIEM least-privilege IAM validation and CSPM drift detection?

The best way to implement CIEM least-privilege IAM and CSPM drift detection is using threat-informed guidance to validate trust policies for confused-deputy risks and monitor configuration drift across ephemeral cloud-native and AI workloads.

How does eBPF runtime security protect cloud-native and AI workloads?

eBPF runtime security protects cloud-native and AI workloads by providing deep kernel-level visibility into process execution and network egress, enabling the implementation of layered defenses and egress controls tailored for ephemeral environments.

Does this approach support NIST 800-53 and ISO 27001 audits for managed AI services?

Yes, this approach supports NIST 800-53 and ISO 27001 audits by explicitly addressing shared responsibility ambiguity for managed AI services and generating compliance gap analysis for over 30 regional regulations including NYDFS 500.