iam-review

Analyze cloud IAM systems for security risks and compliance violations.

Updated Apr 19, 2026
One-click install
npx skills add https://github.com/do360now/security-agents --skill iam-review
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: iam-review
Source: https://github.com/do360now/security-agents/tree/main/.claude/skills/iam-review
Command: npx skills add https://github.com/do360now/security-agents --skill iam-review

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill streamlines the process of evaluating an organization's identity and access management configurations for security gaps and compliance issues.

Core Features & Use Cases

  • Risk Analysis: Assess IAM policies, role assignments, and user privileges to identify over-permissioned or risky configurations.
  • Compliance Checks: Confirm adherence to standards like NIST SP 800-63B, NIST SP 800-207, and CIS Controls v8.
  • Use Case: Conduct an automated review of cloud provider IAM setups to find inactive users, excessive permissions, or missing multi-factor authentication policies, supporting audit readiness and security hardening.

Quick Start

Initiate an IAM security review for your cloud environment by running this skill on your IAM configurations and policies.

Frequently Asked Questions about iam-review

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I automate IAM security assessments across AWS, Azure, and GCP?

Automate IAM security assessments by analyzing identity inventories, roles, and policies to detect over-permissioned configurations and compliance violations across AWS, Azure, and GCP. The process evaluates privilege management and account hygiene to identify security risks.

Can I check my cloud IAM configurations for NIST SP 800-63B and CIS Controls v8 compliance?

Check cloud IAM configurations for NIST SP 800-63B, NIST SP 800-207, and CIS Controls v8 compliance by evaluating role assignments and user privileges. The assessment confirms adherence to these standards to support audit readiness and security hardening.

Does this IAM risk assessment process execute code or exfiltrate data from my cloud environment?

The IAM risk assessment process prevents code execution or data exfiltration within the process to ensure assessment safety. It strictly evaluates policies and identity inventories without executing scripts or moving data out of your environment.

How do I find inactive users and missing multi-factor authentication policies in my cloud IAM?

Find inactive users and missing multi-factor authentication policies by running an automated review of your cloud provider IAM setups. It assesses user privileges and account hygiene to pinpoint risky configurations and enforce zero trust alignment.

What is the best way to evaluate zero trust alignment for cloud identity and access management?

Evaluate zero trust alignment by assessing IAM policies and role assignments to identify excessive permissions and misconfigurations. This enforces best practices for privilege management and account hygiene across cloud providers like AWS, Azure, and GCP.