All skills
aws avatar

/aws-security

@21be518

Covers AWS security services and workflows — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, and security posture summaries; Security Hub CSPM (V1/ASFF) controls and compliance standards; GuardDuty threat findings; Inspector vulnerability findings; Macie sensitive data findings; Detective investigation; and Security Lake configuration and data aggregation. Applicable when questions involve security posture, Exposure findings, CSPM failed controls, threat findings, vulnerability findings, sensitive data findings, automation rules, or cross-service security configuration across AWS environments. Procedures use standard AWS CLI syntax and work with or without the AWS MCP server.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-security

This session only. Nothing lands on disk.

referencessecurity-hub-cspm-findings.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Summarizing Security Hub CSPM Findings

Overview

Summarizes Security Hub CSPM compliance findings — standards-based posture results in ASFF format. Groups by standard (FSBP, CIS, PCI-DSS, NIST), control status (PASSED/FAILED/NOT_AVAILABLE), severity, and account.

Also covers third-party ASFF findings for customers using Security Hub CSPM as their primary hub.

This skill works from both standalone accounts and delegated administrator accounts.

API constraint: MUST use V1 APIs (no -v2 suffix) only. MUST NOT use V2 APIs.

Classify the Request

Signal Workflow
Compliance summary per standard, pass/fail rates A: Standards Compliance Summary
Worst controls, most-failed checks B: Failed Controls Summary
Third-party/integrated service findings (GuardDuty, Inspector, Macie in ASFF) C: Third-Party ASFF Findings

Workflow A: Standards Compliance Summary

  1. Get active compliance findings:

    aws securityhub get-findings --filters '{"ProductName":[{"Value":"Security Hub","Comparison":"EQUALS"}],"RecordState":[{"Value":"ACTIVE","Comparison":"EQUALS"}]}' --max-items 100
  2. Get FAILED findings:

    aws securityhub get-findings --filters '{"ProductName":[{"Value":"Security Hub","Comparison":"EQUALS"}],"RecordState":[{"Value":"ACTIVE","Comparison":"EQUALS"}],"ComplianceStatus":[{"Value":"FAILED","Comparison":"EQUALS"}]}' --max-items 100
  3. Get PASSED findings:

    aws securityhub get-findings --filters '{"ProductName":[{"Value":"Security Hub","Comparison":"EQUALS"}],"RecordState":[{"Value":"ACTIVE","Comparison":"EQUALS"}],"ComplianceStatus":[{"Value":"PASSED","Comparison":"EQUALS"}]}' --max-items 100
  4. List enabled standards for context:

    aws securityhub get-enabled-standards
  5. Summarize:

    • Per standard: PASSED / FAILED / NOT_AVAILABLE counts
    • Overall compliance percentage
    • Severity breakdown of failed findings

Workflow B: Failed Controls Summary

  1. Get FAILED findings sorted by severity:

    aws securityhub get-findings --filters '{"ProductName":[{"Value":"Security Hub","Comparison":"EQUALS"}],"RecordState":[{"Value":"ACTIVE","Comparison":"EQUALS"}],"ComplianceStatus":[{"Value":"FAILED","Comparison":"EQUALS"}]}' --sort-criteria '{"Field":"SeverityNormalized","SortOrder":"desc"}' --max-items 100
  2. Get CRITICAL failed findings:

    aws securityhub get-findings --filters '{"ProductName":[{"Value":"Security Hub","Comparison":"EQUALS"}],"RecordState":[{"Value":"ACTIVE","Comparison":"EQUALS"}],"ComplianceStatus":[{"Value":"FAILED","Comparison":"EQUALS"}],"SeverityLabel":[{"Value":"CRITICAL","Comparison":"EQUALS"}]}' --max-items 100
  3. Summarize by:

    • Control ID (ComplianceSecurityControlId)
    • Severity
    • Resource type
    • Account (for org view)

Workflow C: Third-Party ASFF Findings

For customers using Security Hub CSPM as their primary hub:

  1. Get findings from integrated services:

    aws securityhub get-findings --filters '{"ProductName":[{"Value":"GuardDuty","Comparison":"EQUALS"}],"RecordState":[{"Value":"ACTIVE","Comparison":"EQUALS"}]}' --max-items 100
  2. Repeat for Inspector and Macie:

    aws securityhub get-findings --filters '{"ProductName":[{"Value":"Inspector","Comparison":"EQUALS"}],"RecordState":[{"Value":"ACTIVE","Comparison":"EQUALS"}]}' --max-items 100
    aws securityhub get-findings --filters '{"ProductName":[{"Value":"Macie","Comparison":"EQUALS"}],"RecordState":[{"Value":"ACTIVE","Comparison":"EQUALS"}]}' --max-items 100
  3. Summarize by ProductName, severity, and finding type.

Constraints

  • MUST filter ProductName='Security Hub' to isolate CSPM findings from integrations (Workflows A, B)
  • MUST report compliance status counts (PASSED, FAILED, NOT_AVAILABLE)
  • MUST include overall compliance rate as percentage
  • MUST prioritize CRITICAL and HIGH severity failed controls
  • MUST filter RecordState=ACTIVE to exclude archived findings
  • SHOULD break down by standard (use GeneratorId prefix)
  • SHOULD note pagination — report sampled vs total when applicable

Troubleshooting

Symptom Check
No compliance findings Confirm standards are enabled
All controls NOT_AVAILABLE Resource types may not exist in account
Only from one account Confirm delegated admin and cross-region aggregation
Stale compliance status Controls evaluate periodically — check UpdatedAt

Output Sensitivity

Compliance findings contain resource ARNs, account IDs, control failure details, security group rules, IAM policy excerpts, and third-party integration data (GuardDuty, Inspector, Macie in ASFF). Present compliance pass/fail rates and severity breakdown first. Display full ASFF finding bodies only when the caller explicitly requests raw output.

Source: SKILL.md on GitHub

No alerts1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides a structured framework for auditing AWS security services using read-only CLI commands. It covers configuration reviews and findings summarization for services like GuardDuty, Inspector, and Security Hub, emphasizing data sensitivity and least-privilege principles.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: LOW · No issues

Signed by skilld at 21be518. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "version": "1"
}

README badge

README badge for aws/agent-toolkit-for-aws/aws-security