cspm-engineer

Build a multi-cloud CSPM engine assessing assets against CIS benchmarks.

Updated Feb 22, 2026
One-click install
npx skills add https://github.com/Muath2000/TradeStation --skill cspm-engineer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cspm-engineer
Source: https://github.com/Muath2000/TradeStation/tree/main/.claude/skills/cspm-engineer
Command: npx skills add https://github.com/Muath2000/TradeStation --skill cspm-engineer

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill addresses the complexity of managing cloud security posture across multiple cloud providers and diverse security tools by building a unified assessment engine.

Core Features & Use Cases

  • Multi-Cloud Support: Assesses security posture across AWS, Azure, GCP, and OCI.
  • Flexible Operation Modes: Supports standalone API scanning, integration with third-party security tools (connectors), and a hybrid approach combining both.
  • Comprehensive Assessment: Evaluates against CIS benchmarks, detects misconfigurations, analyzes IAM, identifies encryption gaps, and assesses network exposure.
  • Normalized Findings: Produces standardized posture data for integration into risk registers, control effectiveness tracking, compliance scoring, and Cyber Score computation.
  • Use Case: A large enterprise can use this Skill to consolidate security findings from their AWS direct scans, Azure Security Center, and Qualys vulnerability scans into a single, actionable view, enabling consistent risk management and compliance reporting.

Quick Start

Use the cspm-engineer skill to assess the security posture of your AWS account against CIS benchmarks.

Frequently Asked Questions about cspm-engineer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I assess cloud security posture across AWS, Azure, and GCP using CIS benchmarks?

To assess cloud security posture across AWS, Azure, and GCP, you can use a CSPM engine to evaluate assets against CIS benchmarks, detect misconfigurations, and analyze IAM and network exposure. This produces normalized findings for compliance tracking.

Can I consolidate security findings from direct API scans and third-party tools like Qualys or Wiz?

Yes, you can consolidate security findings using a hybrid mode that combines standalone API scanning with connector-fed data ingestion from tools like Qualys, Wiz, Tenable, Prisma Cloud, and Orca. This creates a unified, actionable view for consistent risk management.

What is the best way to normalize misconfiguration data for a multi-cloud risk register?

The best way to normalize misconfiguration data for a multi-cloud risk register is to use a CSPM engine that standardizes posture data from AWS, Azure, GCP, and OCI. It delivers consistent findings for control effectiveness tracking and Cyber Score computation.

Does cloud security posture management support standalone API scanning without external connectors?

Yes, cloud security posture management supports standalone API scanning without requiring external connectors. This mode requires direct API access to directly evaluate assets, identify encryption gaps, and assess network exposure across your cloud environments.

How do I analyze IAM and network exposure to detect cloud misconfigurations?

To analyze IAM and network exposure and detect cloud misconfigurations, you can run a CSPM engine that evaluates your multi-cloud assets against CIS benchmarks. It systematically identifies encryption gaps and security risks to produce actionable posture data.

When should I use a hybrid approach for cloud security posture management?

You should use a hybrid approach for cloud security posture management when you need to combine direct API scanning with existing third-party security tool data. This allows large enterprises to consolidate diverse findings into a single normalized view for compliance reporting.