All skills

Provides verified corrections for IAM behaviors that AI agents frequently get wrong — policy evaluation edge cases, trust policy gotchas, STS session limits, Organizations quirks, and SAML/MFA specifics. Also provides structured workflows for IAM role management and baseline policy generation from application source code or a Terraform plan JSON. Covers condition operator safety (ForAnyValue/ForAllValues with Null checks), bucket policy deny patterns (VPC endpoint restrictions, org paths), confused deputy protection, and service role creation for AWS services (Glue, CloudTrail, Lambda, ECS, etc.) with aws:SourceAccount/aws:SourceArn trust conditions. Applies when creating IAM roles, writing IAM or bucket policies, generating policies from application source code or a Terraform plan JSON, working with STS, Organizations, or condition operators, or any task needing a service or execution role. Does not cover non-IAM authorization like Cognito user-pool policies or app-level RBAC.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-iam

This session only. Nothing lands on disk.

referencescommon-pitfalls.md

≈856 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Common Pitfalls

Assuming Direct Name Mapping

API operation names and IAM action names frequently differ. Always query the service authorization reference.

{
  "Action": "dynamodb:QueryItems"
}

Wrong — the correct action is dynamodb:Query.

Missing Required Actions for an Operation

Some operations require multiple IAM actions. For example, dynamodb:BatchExecuteStatement requires dynamodb:PartiQLDelete, dynamodb:PartiQLInsert, dynamodb:PartiQLSelect, and dynamodb:PartiQLUpdate.

Using Wildcard Resources Unnecessarily

{
  "Action": "s3:GetObject",
  "Resource": "*"
}

Too broad. Specify bucket and object paths: arn:aws:s3:::my-bucket/*.

ForAnyValue/ForAllValues on Non-Array Condition Keys

ForAnyValue and ForAllValues MUST only be used with array-typed condition keys.

Check the type using the service reference ConditionKeys array:

  • Array types (safe for set operators): ArrayOfString, ArrayOfARN, ArrayOfNumeric
    • Examples: aws:TagKeys, dynamodb:Attributes, dynamodb:LeadingKeys
  • Scalar types (do NOT use set operators): String, Bool, ARN, Numeric
    • Examples: dynamodb:EnclosingOperation, dynamodb:FullTableScan

ForAnyValue in Deny Statements Without Null Check

ForAnyValue evaluates to FALSE when the context key does not exist. Deny statements using ForAnyValue will not block requests when the key is missing.

❌ Incorrect:

{
  "Effect": "Deny",
  "Principal": "*",
  "Action": ["s3:GetObject", "s3:PutObject"],
  "Resource": "arn:aws:s3:::my-bucket/*",
  "Condition": {
    "ForAnyValue:StringNotLike": {
      "aws:VpceOrgPaths": "o-abcdefg/r-12345/ou-123456/*"
    }
  }
}

✅ Correct — add a separate Null-check statement:

{
  "Effect": "Deny",
  "Principal": "*",
  "Action": ["s3:GetObject", "s3:PutObject"],
  "Resource": "arn:aws:s3:::my-bucket/*",
  "Condition": {
    "ForAnyValue:StringNotLike": {
      "aws:VpceOrgPaths": "o-abcdefg/r-12345/ou-123456/*"
    }
  }
},
{
  "Effect": "Deny",
  "Principal": "*",
  "Action": ["s3:GetObject", "s3:PutObject"],
  "Resource": "arn:aws:s3:::my-bucket/*",
  "Condition": {
    "Null": { "aws:VpceOrgPaths": "true" }
  }
}

ForAllValues in Allow Statements Without Null Check

ForAllValues evaluates to TRUE when the context key does not exist. Allow statements using ForAllValues will grant access when the key is missing.

❌ Incorrect:

{
  "Effect": "Allow",
  "Action": "s3:PutObject",
  "Resource": "*",
  "Condition": {
    "ForAllValues:StringEquals": { "aws:TagKeys": "a" }
  }
}

✅ Correct — require the key to exist:

{
  "Effect": "Allow",
  "Action": "s3:PutObject",
  "Resource": "*",
  "Condition": {
    "Null": { "aws:TagKeys": "false" },
    "ForAllValues:StringEquals": { "aws:TagKeys": "a" }
  }
}

ForAllValues in Allow statements is risky. If you must use it, always combine with Null: false.

Adding Conditions When They Are Not Needed

For identity policies, most policies only need Actions and Resources. Add conditions only when:

  • Restricting sensitive actions (e.g., requiring MFA for iam:DeleteUser)
  • Implementing tag-based access control (TBAC)
  • Enforcing organizational requirements (encryption, VPC restrictions)

Resource policies more commonly use conditions (VPC endpoints, source IPs, secure transport).

Source: SKILL.md on GitHub

No alerts17d3 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill provides a set of guidelines and references for managing AWS IAM policies, service roles, and workflows safely. It includes helpful instructions on avoiding common configuration pitfalls, ensuring condition operator safety, and utilizing tools like iam-policy-autopilot via uvx. All external links and packages trace back to standard development repositories and official documentation.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

Signed by skilld at 9593e1e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "version": "2"
}

README badge

README badge for aws/agent-toolkit-for-aws/aws-iam