Audit AWS IAM policies for risky permissions with Cloudsplaining
SkillCloud & infraUse Cloudsplaining when an agent needs to flag privilege-escalation paths and overbroad IAM permissions before an AWS policy change reaches production.
Use Audit AWS IAM policies for risky permissions with Cloudsplaining in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Audit AWS IAM policies for risky permissions with Cloudsplaining and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Audit AWS IAM policies for risky permissions with Cloudsplaining skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by agentskillexchange/skills in skills/audit-aws-iam-policies-for-risky-permissions-with-cloudsplaining/SKILL.md and read by Ahel’s review.
Use Cloudsplaining when an agent needs to flag privilege-escalation paths and overbroad IAM permissions before an AWS policy change reaches production.
Prerequisites
Python 3, AWS IAM policy JSON or account data, and Cloudsplaining.
Installation
Use the upstream install or setup path that matches your environment:
- brew tap salesforce/cloudsplaining https://github.com/salesforce/cloudsplaining
- brew install cloudsplaining
Requirements and caveats from upstream:
- You must have the privileges to run iam:GetAccountAuthorizationDetails. The arn:aws:iam::aws:policy/SecurityAudit policy i...
- default-iam-results.json: This contains the raw JSON output of the report. You can use this data file for operating on the scan results for various purposes. For example, you could write a Python script that parses th...
Basic usage or getting-started notes:
-
Cloudsplaining also identifies IAM Roles that can be assumed by AWS Compute Services (such as EC2, ECS, EKS, or Lambda), as they can present greater risk than user-defined roles - especially if the AWS Compute service...
-
You can also specify a custom exclusions file to filter out results that are False Positives for various reasons. For example, User Policies are permissive by design, whereas System roles are generally more restrictiv...
-
Extracted from upstream docs: https://raw.githubusercontent.com/salesforce/cloudsplaining/HEAD/README.md
Documentation
Source
Signals
- GitHub stars
- 51
- Forks
- 73
- Last commit
- Oct 2026
Ahel review
S4info
community integration, published by agentskillexchange, not awsK1binfo
installs-packages
Automated review, not a security audit. Ruleset v1+k2.
Advanced
- Item type
- skill
- Key
audit-aws-iam-policies-for-risky-permissions-with-cl-0ylchuh- Source
- github.com/agentskillexchange/skills
github.com/agentskillexchange/skills
Related picks
Skill · awslabs
The pick for AWSaws-health-events
Skill · aws
The pick for AWSgenerate-sandbox-policy
Skill · nvidia
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infrasecrets-exposure-review
Skill · naodeng
The pick for Secretssecrets-with-git-crypt
Skill · derailed-dash
The pick for Secrets