iam-policy-auditorAudit AWS IAM policies and roles for over-privilege, wildcard permissions, and least-privilege violations
Install via ClawdBot CLI:
clawdbot install anmolnagpal/iam-policy-auditorGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated Mar 21, 2026
Financial institutions must adhere to strict regulations like PCI DSS and GDPR, requiring regular IAM policy reviews to prevent unauthorized access to sensitive customer data. This skill automates detection of over-privileged roles, such as wildcard permissions on S3 buckets containing financial records, reducing manual audit effort and ensuring compliance with least-privilege principles. It helps flag high-risk patterns like iam:PassRole without conditions, which could lead to privilege escalation in cloud environments.
E-commerce platforms with continuous deployment pipelines need to secure IAM policies for microservices and CI/CD tools to prevent breaches during updates. This skill can be integrated into pre-deployment checks to audit policies for EC2 instance profiles, identifying dangerous patterns like sts:AssumeRole with no conditions that might allow cross-account attacks. It generates least-privilege replacements to maintain functionality while minimizing attack surfaces in dynamic cloud infrastructures.
Healthcare organizations store protected health information (PHI) in AWS, requiring stringent IAM controls to meet HIPAA security rules. This skill audits policies for wildcard permissions on resources like RDS databases, flagging violations such as s3:* on * that could expose patient data. By mapping findings to MITRE ATT&CK techniques, it provides actionable insights to remediate risks and enable IAM Access Analyzer for ongoing monitoring of access policies.
Startups often prioritize speed over security, leading to overly permissive IAM policies that increase breach risks. This skill helps small teams quickly audit existing policies for critical issues like admin-equivalent actions or no conditions on production resources, providing a risk score and remediation guidance. It supports cost-effective security by automating audits without extensive expertise, allowing startups to focus on growth while maintaining a secure AWS environment.
During cloud migration, enterprises need to validate IAM policies for legacy applications being moved to AWS to avoid introducing vulnerabilities. This skill analyzes policies for dangerous patterns like iam:CreatePolicyVersion, which could enable privilege escalation in new environments. It generates corrected policies with inline comments to ensure least-privilege adherence, facilitating a smooth and secure transition while mapping risks to real-world attack scenarios for stakeholder reporting.
Offer this skill as part of a monthly subscription service priced at $49/month, targeting small to medium businesses seeking affordable AWS security tools. It provides continuous updates and support, with tiered pricing for additional features like custom reporting or integration with other security platforms. This model ensures recurring revenue while helping customers maintain compliance and reduce breach risks through regular audits.
Bundle the skill with professional services for enterprises needing hands-on IAM policy audits and remediation. Consultants use it to automate initial assessments, then provide tailored recommendations and implementation support. This model generates revenue through project-based fees or retainer agreements, appealing to organizations with complex AWS environments that require expert guidance beyond automated tools.
Provide a basic version of the skill for free to attract users, with limited features like risk scoring and basic findings. Upsell premium features such as MITRE ATT&CK mapping, advanced remediation policies, and IAM Access Analyzer integration for a one-time purchase or higher subscription tier. This model drives user adoption and converts free users to paying customers by demonstrating value through initial audits.
💬 Integration Tip
Integrate this skill into CI/CD pipelines using bash scripts to automate IAM policy audits before deployment, ensuring security checks are part of the development workflow.
Scored Apr 19, 2026
基于睿观的产品图片政策合规检测,通过视觉相似度匹配识别潜在违规商品。当用户提到政策合规检查、产品图片合规、违规检测、禁售商品筛查、基于图片的合规审查、上架前风险排查、policy compliance detection, product compliance review, violation detectio...
AI 合同风险审查服务。当用户需要审查合同、检查法律风险、分析合同条款、 审阅法律文书时使用本技能。覆盖违约责任、知识产权、付款条件、验收标准、 保密义务、管辖法院等15类法律风险。支持快速扫描和深度审查两档服务。 触发词:合同审查、审核合同、检查合同、法律风险、条款分析、法务审查、 合同风险、审合同、法律审查、...
产品图片的图形商标检测与相似度搜索。当用户提到商标检测、图形商标搜索、Logo侵权检查、商标相似度分析、图片商标风险评估、产品图片商标筛查、graphic trademark detection, logo infringement, trademark similarity, trademark risk, i...
面向电商产品Listing的文字商标检测与侵权风险分析。当用户提到商标检测、商标风险检查、品牌侵权筛查、产品标题商标扫描、文字商标查询、Listing合规检查、知识产权风险评估、text trademark detection, trademark infringement, brand infringement...
GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks data subject rights requests. Use for GD...
CAPA system management for medical device QMS. Covers root cause analysis, corrective action planning, effectiveness verification, and CAPA metrics. Use for...