All skills
aws avatar

/aws-security

@21be518

Covers AWS security services and workflows — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, and security posture summaries; Security Hub CSPM (V1/ASFF) controls and compliance standards; GuardDuty threat findings; Inspector vulnerability findings; Macie sensitive data findings; Detective investigation; and Security Lake configuration and data aggregation. Applicable when questions involve security posture, Exposure findings, CSPM failed controls, threat findings, vulnerability findings, sensitive data findings, automation rules, or cross-service security configuration across AWS environments. Procedures use standard AWS CLI syntax and work with or without the AWS MCP server.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-security

This session only. Nothing lands on disk.

referencesorganization-policies.md

≈770 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Organization Policies

Overview

AWS Organizations supports service-specific policy types for centralized configuration enforcement across member accounts. Multiple security services use this mechanism, each with its own policy type. Organization policies allow administrators to define and enforce service configurations from the management account or delegated administrator, ensuring consistent security posture across the organization.

Available Policy Types

Policy Type Service Documentation
SECURITYHUB_POLICY Security Hub https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_security_hub.html
INSPECTOR_POLICY Inspector https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_inspector.html

Common Discovery Pattern

The same CLI pattern applies to all policy types — substitute the appropriate POLICY_TYPE value:

# List policies of a given type
aws organizations list-policies --filter <POLICY_TYPE>

# Get policy document details
aws organizations describe-policy --policy-id <id>

# Check which roots, OUs, or accounts a policy targets
aws organizations list-targets-for-policy --policy-id <id>

These are organizations namespace APIs — not service-specific APIs like securityhub or inspector2.

Execution environment: The AWS MCP server is recommended for running these API calls but is not required — standard AWS CLI access is sufficient.

Read-Only APIs

API Purpose
organizations:ListPolicies List policies by type
organizations:DescribePolicy Get policy document and metadata
organizations:ListTargetsForPolicy List OUs/accounts a policy applies to
organizations:ListPoliciesForTarget List policies applied to a specific OU/account

Operator Prerequisites

Organization policy APIs are organizations namespace APIs. Access requires one of:

  • A role in the Organizations management account with organizations:List* and organizations:Describe* permissions, OR
  • A role in a delegated administrator account where the management account has configured the delegation policy to grant Organization policy API access to the service's delegated administrator. The standard service onboarding flow configures this delegation.

If list-policies returns AccessDeniedException, the current role lacks Organizations access. This typically means either:

  • The account is not the management account or delegated administrator
  • The delegation policy has not been configured to grant these permissions

Report policy status as Not checked - Organizations access unavailable and continue with service-specific checks that do not require Organizations permissions.

Output Sensitivity

Policy documents may reveal organizational structure (OU hierarchy, account assignments), security configuration enforcement rules, and service-specific settings applied across the organization. Present policy summary first; offer full policy document JSON on request.

Source: SKILL.md on GitHub

No alerts1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides a structured framework for auditing AWS security services using read-only CLI commands. It covers configuration reviews and findings summarization for services like GuardDuty, Inspector, and Security Hub, emphasizing data sensitivity and least-privilege principles.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: LOW · No issues

Signed by skilld at 21be518. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "version": "1"
}

README badge

README badge for aws/agent-toolkit-for-aws/aws-security