Audit AWS IAM policies for risky permissions with Cloudsplaining

SkillCloud & infra

Use Cloudsplaining when an agent needs to flag privilege-escalation paths and overbroad IAM permissions before an AWS policy change reaches production.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Audit AWS IAM policies for risky permissions with Cloudsplaining skill

What this skill tells your AI

The instructions your AI receives, as published by agentskillexchange/skills in skills/audit-aws-iam-policies-for-risky-permissions-with-cloudsplaining/SKILL.md and read by ahel’s review.

Use Cloudsplaining when an agent needs to flag privilege-escalation paths and overbroad IAM permissions before an AWS policy change reaches production.

Prerequisites

Python 3, AWS IAM policy JSON or account data, and Cloudsplaining.

Installation

Use the upstream install or setup path that matches your environment:

Requirements and caveats from upstream:

  • You must have the privileges to run iam:GetAccountAuthorizationDetails. The arn:aws:iam::aws:policy/SecurityAudit policy i...
  • default-iam-results.json: This contains the raw JSON output of the report. You can use this data file for operating on the scan results for various purposes. For example, you could write a Python script that parses th...

Basic usage or getting-started notes:

Documentation

Source

Signals

GitHub stars
38
Forks
53
Last commit
Sep 2026

ahel review

  • S4info
    community integration — published by agentskillexchange, not aws

Automated review, not a security audit. Ruleset v1.

Advanced
Catalog kind
skill
Gateway key
audit-aws-iam-policies-for-risky-permissions-with-cl-0ylchuh
Source
github.com/agentskillexchange/skills