aws AI Agent Skills

Browse 34 skills related to aws

terraform-iac-expert

43
curiositechcuriositech

Expert in Infrastructure as Code using Terraform and OpenTofu. Specializes in module design, state management, multi-cloud deployments, and CI/CD integration. Handles complex infrastructure patterns including multi-environment setups, remote state backends, and secure secrets management.

terraformiacinfrastructure+4
189 days ago

aws-cloud-architecture

40
manutejmanutej

Comprehensive guide to AWS cloud architecture covering compute, storage, databases, networking, security, serverless, and cost optimization with production-ready patterns

awscloud-architectureinfrastructure+5
189 days ago

terraform-infrastructure-as-code

40
manutejmanutej

Comprehensive Terraform Infrastructure as Code skill covering resources, modules, state management, workspaces, providers, and advanced patterns for cloud-agnostic infrastructure deployment

terraforminfrastructure-as-codecloud+7
189 days ago

AWS Penetration Testing

14
zebbernzebbern

This skill should be used when the user asks to "pentest AWS", "test AWS security", "enumerate IAM", "exploit cloud infrastructure", "AWS privilege escalation", "S3 bucket testing", "metadata SSRF", "Lambda exploitation", or needs guidance on Amazon Web Services security assessment.

awscloud-securitypenetration-testing+4
189 days ago

Cloud Penetration Testing

14
zebbernzebbern

This skill should be used when the user asks to "perform cloud penetration testing", "assess Azure or AWS or GCP security", "enumerate cloud resources", "exploit cloud misconfigurations", "test O365 security", "extract secrets from cloud environments", or "audit cloud infrastructure". It provides comprehensive techniques for security assessment across major cloud platforms.

cloudawsazure+4
189 days ago

aws-advanced-patterns

13
williamzujkowskiwilliamzujkowski

Orchestration & Events:

awsstep-functionseventbridge+3
189 days ago

Terraform Infrastructure as Code

10
bobmatnycbobmatnyc

Production-grade Terraform development with HCL best practices, module design, state management, multi-cloud patterns, and AI-enhanced infrastructure as code for scalable cloud deployments

terraforminfrastructure-as-codeiac+8
189 days ago

cloud-infrastructure

7
louloulinlouloulin

Expert in cloud infrastructure design, deployment, and management across AWS, Azure, and GCP

cloudawsazure+4
189 days ago

aws-iam-best-practices

4
ngxtmngxtm

IAM policy review, hardening, and least privilege implementation

awsiamsecurity+3
189 days ago

aws-secrets-rotation

4
ngxtmngxtm

Automate AWS secrets rotation for RDS, API keys, and credentials

awssecrets-managersecurity+3
189 days ago

aws-security-audit

4
ngxtmngxtm

Comprehensive AWS security posture assessment using AWS CLI and security best practices

awssecurityaudit+3
189 days ago

aws-compliance-checker

4
ngxtmngxtm

Automated compliance checking against CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks

awscomplianceaudit+4
189 days ago

implementing-aws-iam-permission-boundaries

2
mukul975mukul975

Configure IAM permission boundaries in AWS to delegate role creation to developers while enforcing maximum privilege limits set by the security team.

awsiampermission-boundaries+3
189 days ago

implementing-aws-security-hub-compliance

2
mukul975mukul975

Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security insights for organizational risk management.

cloud-securityawssecurity-hub+3
189 days ago

performing-aws-privilege-escalation-assessment

2
mukul975mukul975

Performing authorized privilege escalation assessments in AWS environments to identify IAM misconfigurations that allow users or roles to elevate their permissions using Pacu, CloudFox, Principal Mapper, and manual IAM policy analysis techniques.

cloud-securityawsprivilege-escalation+3
189 days ago

detecting-aws-credential-exposure-with-trufflehog

2
mukul975mukul975

Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.

cloud-securityawscredential-exposure+3
189 days ago

performing-cloud-forensics-investigation

2
mukul975mukul975

Conduct forensic investigations in cloud environments by collecting and analyzing logs, snapshots, and metadata from AWS, Azure, and GCP services.

forensicscloud-forensicsaws+4
189 days ago

securing-aws-lambda-execution-roles

2
mukul975mukul975

Securing AWS Lambda execution roles by implementing least-privilege IAM policies, applying permission boundaries, restricting resource-based policies, using IAM Access Analyzer to validate permissions, and enforcing role scoping through SCPs.

cloud-securityawslambda+3
189 days ago

detecting-s3-data-exfiltration-attempts

2
mukul975mukul975

Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.

cloud-securityawss3+4
189 days ago

conducting-cloud-infrastructure-penetration-test

2
mukul975mukul975

Perform a cloud infrastructure penetration test across AWS, Azure, and GCP to identify IAM misconfigurations, exposed storage buckets, insecure serverless functions, and cloud-native attack paths using Pacu, ScoutSuite, and Prowler.

cloud-pentestAWSAzure+7
189 days ago

auditing-aws-s3-bucket-permissions

2
mukul975mukul975

Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enforce least-privilege data access controls.

cloud-securityawss3+3
189 days ago

implementing-aws-config-rules-for-compliance

2
mukul975mukul975

Implementing AWS Config rules for continuous compliance monitoring of AWS resources, deploying managed and custom rules aligned to CIS and PCI DSS frameworks, configuring automatic remediation with SSM Automation, and aggregating compliance data across accounts.

cloud-securityawsconfig-rules+3
189 days ago

implementing-cloud-trail-log-analysis

2
mukul975mukul975

Implementing AWS CloudTrail log analysis for security monitoring, threat detection, and forensic investigation using Athena, CloudWatch Logs Insights, and SIEM integration to identify unauthorized access, privilege escalation, and suspicious API activity.

cloud-securityawscloudtrail+3
189 days ago

detecting-aws-guardduty-findings-automation

2
mukul975mukul975

Automate AWS GuardDuty threat detection findings processing using EventBridge and Lambda to enable real-time incident response, automatic quarantine of compromised resources, and security notification workflows.

awsguarddutyeventbridge+5
189 days ago

performing-cloud-incident-containment-procedures

2
mukul975mukul975

Execute cloud-native incident containment across AWS, Azure, and GCP by isolating compromised resources, revoking credentials, preserving forensic evidence, and applying security group restrictions to prevent lateral movement.

cloud-securityincident-containmentaws+5
189 days ago

implementing-aws-macie-for-data-classification

2
mukul975mukul975

Implement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials detection.

awsmaciedata-classification+5
189 days ago

securing-api-gateway-with-aws-waf

2
mukul975mukul975

Securing API Gateway endpoints with AWS WAF by configuring managed rule groups for OWASP Top 10 protection, creating custom rate limiting rules, implementing bot control, setting up IP reputation filtering, and monitoring WAF metrics for security effectiveness.

cloud-securityawswaf+4
189 days ago

performing-aws-account-enumeration-with-scout-suite

2
mukul975mukul975

Perform comprehensive security posture assessment of AWS accounts using ScoutSuite to enumerate resources, identify misconfigurations, and generate actionable security reports.

awsscoutsuitecloud-security+5
189 days ago

configuring-aws-verified-access-for-ztna

2
mukul975mukul975

Configure AWS Verified Access to provide VPN-less zero trust network access to internal applications using identity and device posture verification with Cedar policy language.

zero-trustawsverified-access+6
189 days ago

performing-cloud-penetration-testing-with-pacu

2
mukul975mukul975

Performing authorized AWS penetration testing using Pacu, the open-source AWS exploitation framework, to enumerate IAM configurations, discover privilege escalation paths, test credential harvesting, and validate security controls through systematic attack simulation.

cloud-securityawspacu+3
189 days ago

implementing-envelope-encryption-with-aws-kms

2
mukul975mukul975

Envelope encryption is a strategy where data is encrypted with a data encryption key (DEK), and the DEK itself is encrypted with a master key (KEK) managed by AWS KMS. This approach allows encrypting

cryptographyencryptionaws+3
189 days ago

cfn-template-compare

pantheon-orgpantheon-org

Compare deployed CloudFormation templates with locally synthesized CDK templates to detect drift, validate changes, and ensure consistency before deployment.

cloudformationcdkaws+4
189 days ago

Cloud Cost

novas10novas10

Track cloud costs across AWS, GCP, and Azure. Alert on budget spikes.

cloudcostaws+3
189 days ago

senior-network-infrastructure

arielperez82arielperez82

Network infrastructure specialist for VPC/VNet design, VPN configuration, firewall policies, load balancing, and multi-cloud networking. Includes topology analysis, security group generation, and network compliance auditing.

networkinfrastructureVPN+12
189 days ago