All skills
aws avatar

/aws-security

@21be518

Covers AWS security services and workflows — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, and security posture summaries; Security Hub CSPM (V1/ASFF) controls and compliance standards; GuardDuty threat findings; Inspector vulnerability findings; Macie sensitive data findings; Detective investigation; and Security Lake configuration and data aggregation. Applicable when questions involve security posture, Exposure findings, CSPM failed controls, threat findings, vulnerability findings, sensitive data findings, automation rules, or cross-service security configuration across AWS environments. Procedures use standard AWS CLI syntax and work with or without the AWS MCP server.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-security

This session only. Nothing lands on disk.

referencesdetective-configuration.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Reviewing Detective Configuration

Overview

Audits Amazon Detective configuration across single accounts and organizations. Checks behavior graph existence, data source enablement, member account coverage, and invitation status. Results are presented as a configuration state summary.

Detective ingests CloudTrail management events, VPC Flow Logs, EKS Audit Logs, and Security Hub findings to build behavior graphs for investigation. Detective does NOT support S3 data events.

Works from both standalone accounts and delegated administrator accounts.

Classify the Request

Signal Workflow
Single account, no org context A: Review Single Account
Org admin, multi-account coverage B: Review Organization Coverage
"Is Detective set up correctly?" A then B if org

Workflow A: Review Single Account

  1. List behavior graphs:

    aws detective list-graphs

    Configured: at least one graph. Not Configured: no graphs.

  2. For each graph, check data source packages:

    aws detective list-datasource-packages --graph-arn <graph-arn>

    Expected packages:

    • DETECTIVE_CORE (CloudTrail management events)
    • EKS_AUDIT (EKS Audit Logs)
    • ASFF_SECURITYHUB_FINDING (Security Hub findings)

    For each: STARTED = Configured, STOPPED/DISABLED = Not Configured.

  3. List members:

    aws detective list-members --graph-arn <graph-arn>

    Check each member status: ENABLED, VERIFICATION_FAILED, VERIFICATION_IN_PROGRESS.

  4. Check pending invitations (from member perspective):

    aws detective list-invitations

    Security check: Verify CloudTrail is enabled and logging Detective API calls (detective:* events) for audit purposes.

  5. Present results:

    Check Status
    Behavior Graph Exists Configured / Not Configured
    CloudTrail Logs Enabled / Disabled / Not Configured
    EKS Audit Logs Enabled / Disabled / Not Configured
    Security Hub Findings Enabled / Disabled / Not Configured
    Member Count X members
    Members Enabled X/Y enabled

Workflow B: Review Organization Coverage

  1. Identify admin:

    aws detective list-organization-admin-accounts
  2. Check organization configuration:

    aws detective describe-organization-configuration --graph-arn <graph-arn>

    Configured: autoEnable is true.

  3. For quick membership signal, describe-organization-configuration confirms auto-enable for new accounts. Full member enumeration requires list-members pagination — expensive for large organizations.

  4. (ONLY if user explicitly requests per-account detail):

    aws detective list-members --graph-arn <graph-arn>

    Evaluate: ENABLED, VERIFICATION_FAILED, INVITED (not accepted), DISABLED.

  5. Check data source packages on admin graph (step 3 from Workflow A).

  6. Present results:

    Check Status
    Delegated Admin Configured Configured / Not Configured
    Auto-Enable New Accounts Enabled / Not Enabled
    Member Accounts Enrolled (details on request)
    Data Sources Enabled X/Y packages

Constraints

  • MUST NOT modify any Detective configuration
  • MUST NOT perform entity investigation or finding analysis
  • MUST NOT paginate through all member accounts by default
  • MUST only enumerate individual member status if user explicitly requests it
  • SHOULD check all available data source packages
  • MAY report graph creation date for context

Troubleshooting

Error Resolution
AccessDeniedException on list-graphs Detective not enabled — report as NOT_CONFIGURED
ValidationException on list-members Invalid graph ARN — re-fetch from list-graphs
Empty list-graphs response Detective not enabled in region
AccessDeniedException on describe-organization-configuration Not an org admin — switch to Workflow A

Output Sensitivity

Configuration output reveals behavior graph ARNs, member account IDs and invitation status, enabled data source packages, and organization auto-enable settings. Present configuration summary first; offer raw API responses on request.

Source: SKILL.md on GitHub

No alerts1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides a structured framework for auditing AWS security services using read-only CLI commands. It covers configuration reviews and findings summarization for services like GuardDuty, Inspector, and Security Hub, emphasizing data sensitivity and least-privilege principles.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: LOW · No issues

Signed by skilld at 21be518. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "version": "1"
}

README badge

README badge for aws/agent-toolkit-for-aws/aws-security