security-review-owasp-secure-cloud-architecture

Review cloud architecture for privilege, isolation, and exposure weaknesses.

Updated Mar 26, 2026
One-click install
npx skills add https://github.com/sjinks/ai-owasp-skillset --skill security-review-owasp-secure-cloud-architecture
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: security-review-owasp-secure-cloud-architecture
Source: https://github.com/sjinks/ai-owasp-skillset/tree/main/.github/skills/security-review-owasp-secure-cloud-architecture
Command: npx skills add https://github.com/sjinks/ai-owasp-skillset --skill security-review-owasp-secure-cloud-architecture

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps reviewers identify Secure Cloud Architecture weaknesses that expand attacker reach through unsafe defaults, excessive privilege, weak isolation, and exposed control planes.

Core Features & Use Cases

  • Architecture and Boundary Review: Examines runtime identities, service accounts, tenant isolation, and trust boundaries across cloud, container, pipeline, and dependency layers.
  • Operational Security Assessment: Checks deployment hardening, secret handling, logging, scanning, and CI/CD safeguards that affect real-world cloud security.
  • Use Case: Use this Skill when reviewing a cloud service, infrastructure change, or deployment manifest to find confirmed security gaps with evidence-backed recommendations.

Quick Start

Ask the skill to review your cloud architecture, deployment files, or service flow for Secure Cloud Architecture risks and focus on privilege, isolation, and management exposure.

Frequently Asked Questions about security-review-owasp-secure-cloud-architecture

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I review cloud architecture for security gaps and trust boundary weaknesses?

Review cloud architecture security by assessing runtime identities, privilege boundaries, tenant isolation, and exposed control planes across service and deployment layers to find evidence-backed risks. This process identifies unsafe defaults and weak isolation that expand attacker reach.

What is a trust boundary review for cloud deployment security?

A trust boundary review examines isolation between tenants, containers, and pipelines to verify privilege separation and prevent lateral movement. It evaluates dependency trust and exposed management surfaces to confirm secure boundaries across cloud and container layers.

Can I use this approach to check CI/CD pipeline and deployment manifest security?

Yes, you can review deployment manifests and CI/CD pipelines to evaluate operational security controls including secret handling, logging, scanning, and deployment hardening. This validates that deployment safeguards properly protect cloud services and infrastructure changes.

Does cloud security architecture review cover container isolation and service accounts?

Cloud security architecture review covers container isolation by examining runtime identities, service accounts, and tenant separation across container layers. It verifies privilege boundaries and isolation controls to detect configuration weaknesses that expose management surfaces.

What's the best way to assess privilege boundaries and exposed management surfaces in cloud services?

Assess privilege boundaries by evaluating runtime identities and service accounts against isolation controls, then check exposed management surfaces across cloud and dependency layers. This evidence-backed approach confirms whether excessive privileges or weak isolation expand attacker reach.