infra-rbac-audit

Community

Continuously verify least-privilege access

Authorivanshamaev
Version1.0.0
Installs0

System Documentation

What problem does it solve?

This Skill helps you prevent data-platform over-privileged access by auditing RBAC and permissions across Kubernetes, AWS IAM, GCP IAM, databases, and Airflow, so risky configurations are found before they cause incidents.

Core Features & Use Cases

  • Kubernetes RBAC audit: Detects cluster-admin bindings, wildcard permissions, over-permissive service accounts, and token automount patterns to enforce least privilege.
  • Cloud IAM audits (AWS/GCP): Reviews external access findings, flags admin-equivalent policies, checks role last-used behavior, and identifies overly broad owner/editor bindings and service account key usage.
  • Database & Airflow RBAC checks: Surfaces dangerous PostgreSQL roles (e.g., superuser/CREATEDB), audits Trino/public grants, and highlights Airflow users with administrative roles.
  • Operational use cases: Pre-compliance reviews (SOC2/GDPR/PCI-DSS), insider-threat investigations, onboarding permission alignment, quarterly access reviews, and cleanup of orphaned or excessive service accounts.

Quick Start

Ask your agent to run an RBAC audit across Kubernetes, AWS IAM, GCP IAM, PostgreSQL/Trino grants, and Airflow roles and return a prioritized checklist of violations with remediation guidance.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: infra-rbac-audit
Download link: https://github.com/ivanshamaev/de-agent-skills/archive/main.zip#infra-rbac-audit

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.