All skills
aws avatar

/aws-security

@21be518

Covers AWS security services and workflows — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, and security posture summaries; Security Hub CSPM (V1/ASFF) controls and compliance standards; GuardDuty threat findings; Inspector vulnerability findings; Macie sensitive data findings; Detective investigation; and Security Lake configuration and data aggregation. Applicable when questions involve security posture, Exposure findings, CSPM failed controls, threat findings, vulnerability findings, sensitive data findings, automation rules, or cross-service security configuration across AWS environments. Procedures use standard AWS CLI syntax and work with or without the AWS MCP server.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-security

This session only. Nothing lands on disk.

referencesguardduty-findings.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Summarizing GuardDuty Findings

Overview

Produces structured summaries of active GuardDuty findings — severity distribution, type breakdown, and affected resources. Does NOT perform triage, investigation, or remediation.

Works from both standalone accounts and delegated administrator accounts.

Classify the Request

User intent Workflow
Summarize my GuardDuty findings A: Account Findings Summary
What threats is GuardDuty detecting A: Account Findings Summary
Show findings across my org B: Organization Findings Overview
Which accounts have the most findings B: Organization Findings Overview

Workflow A: Account Findings Summary

  1. Get the detector ID:

    aws guardduty list-detectors
  2. Get finding statistics (active findings only):

    aws guardduty get-findings-statistics --detector-id <DETECTOR_ID> --groupBy SEVERITY --finding-criteria '{"Criterion":{"service.archived":{"Eq":["false"]}}}'

    Severity mapping: 9.0+ = Critical, 7.0–8.9 = High, 4.0–6.9 = Medium, 1.0–3.9 = Low

  3. List findings sorted by severity (most severe first):

    aws guardduty list-findings --detector-id <DETECTOR_ID> --sort-criteria '{"AttributeName":"severity","OrderBy":"DESC"}' --finding-criteria '{"Criterion":{"service.archived":{"Eq":["false"]}}}'
  4. Get finding details in batches (max 50 per call):

    aws guardduty get-findings --detector-id <DETECTOR_ID> --finding-ids <IDS>
  5. Group findings by:

    • Attack Sequences first — findings with type prefix AttackSequence: MUST be surfaced in a separate section at the top. These represent correlated multi-step attacks and are the most actionable findings.
    • Severity (CRITICAL, HIGH, MEDIUM, LOW)
    • Type prefix (e.g., Recon:, UnauthorizedAccess:, CryptoCurrency:)
    • Resource type (Instance, AccessKey, S3Bucket, EKSCluster, Lambda, RDSDBInstance)
  6. Present summary:

    Attack Sequences (always first):

    Finding Type Severity Affected Resources
    AttackSequence:... CRITICAL ...

    Severity Breakdown:

    Severity Count
    Critical N
    High N
    Medium N
    Low N
    Finding Type Prefix Count Highest Severity
    UnauthorizedAccess: N HIGH
    Recon: N MEDIUM
    Resource Type Count Top Finding Types
    Instance N ...
    AccessKey N ...

Workflow B: Organization Findings Overview

  1. Get the detector ID:

    aws guardduty list-detectors
  2. List findings across organization (delegated admin sees all member findings):

    aws guardduty list-findings --detector-id <DETECTOR_ID> --sort-criteria '{"AttributeName":"severity","OrderBy":"DESC"}' --finding-criteria '{"Criterion":{"service.archived":{"Eq":["false"]}}}'
  3. Get finding details in batches:

    aws guardduty get-findings --detector-id <DETECTOR_ID> --finding-ids <IDS>
  4. Group by account ID, then by severity and type.

  5. Present summary:

    Account ID Critical High Medium Low Total
    111111111111 N N N N N

    MUST identify the top 5 accounts by critical+high findings count.

Constraints

  • MUST filter to non-archived (active) findings only
  • MUST batch get-findings calls (max 50 IDs per request)
  • MUST NOT perform triage, investigation, or root cause analysis
  • MUST NOT make recommendations about suppression or remediation
  • SHOULD limit detail retrieval to top 200 findings for performance

Troubleshooting

Symptom Resolution
list-findings returns empty No active findings or all archived — report zero active findings
get-findings-statistics unavailable Use list-findings and count client-side
Only sees own account findings Not a delegated admin — note: showing single-account view only

Output Sensitivity

Finding details contain IP addresses, network connections, DNS queries, process details, and resource identifiers. Present the severity/type summary table first. Display full finding JSON bodies only when the caller explicitly requests raw output.

Source: SKILL.md on GitHub

No alerts1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides a structured framework for auditing AWS security services using read-only CLI commands. It covers configuration reviews and findings summarization for services like GuardDuty, Inspector, and Security Hub, emphasizing data sensitivity and least-privilege principles.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: LOW · No issues

Signed by skilld at 21be518. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "version": "1"
}

README badge

README badge for aws/agent-toolkit-for-aws/aws-security