All skills
aws avatar

/aws-security

@21be518

Covers AWS security services and workflows — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, and security posture summaries; Security Hub CSPM (V1/ASFF) controls and compliance standards; GuardDuty threat findings; Inspector vulnerability findings; Macie sensitive data findings; Detective investigation; and Security Lake configuration and data aggregation. Applicable when questions involve security posture, Exposure findings, CSPM failed controls, threat findings, vulnerability findings, sensitive data findings, automation rules, or cross-service security configuration across AWS environments. Procedures use standard AWS CLI syntax and work with or without the AWS MCP server.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-security

This session only. Nothing lands on disk.

referencessecurity-lake-configuration.md

≈986 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Reviewing Security Lake Configuration

Overview

Produces a configuration summary of Amazon Security Lake reporting current state. Verifies data lake enablement, AWS log source coverage, subscriber setup, and organization-level rollout.

Works from both standalone and delegated administrator accounts.

Classify the Request

Request Pattern Workflow
"Is Security Lake configured correctly?" A: Review Single Account
"Check org-wide Security Lake coverage" B: Review Organization Coverage

Workflow A: Review Single Account

  1. Check data lake status:

    aws securitylake list-data-lakes

    Verify each expected region has a data lake with createStatus = COMPLETED.

    Security check: Verify data lake has KMS encryption configured — check encryptionConfiguration.kmsKeyId in the list-data-lakes output.

  2. Check configured AWS sources:

    aws securitylake get-data-lake-sources

    Verify these source types are present:

    • ROUTE53
    • VPC_FLOW
    • SH_FINDINGS
    • CLOUD_TRAIL_MGMT
    • LAMBDA_EXECUTION
    • S3_DATA
    • EKS_AUDIT
  3. List log sources for detail:

    aws securitylake list-log-sources
  4. Check subscribers:

    aws securitylake list-subscribers

    For each subscriber, note access type (S3, LAKEFORMATION) and status.

  5. Present results:

    Check Status Detail
    Data lake enabled (region) Configured createStatus=COMPLETED
    CloudTrail Management Configured / Not Configured ...
    VPC Flow Logs Configured / Not Configured ...
    Route53 Configured / Not Configured ...
    S3 Data Events Configured / Not Configured ...
    Lambda Execution Configured / Not Configured ...
    EKS Audit Configured / Not Configured ...
    Subscribers Configured N subscribers active
  6. MUST check all standard AWS sources listed above.

  7. SHOULD flag any source with a non-healthy status.

Workflow B: Review Organization Coverage

  1. Get organization configuration:

    aws securitylake get-data-lake-organization-configuration

    Check which sources have auto-enable configured.

  2. List exceptions:

    aws securitylake list-data-lake-exceptions

    Identify accounts/regions with failures.

  3. Present organization summary:

    Check Status Detail
    Org auto-enable (each source) Configured / Not Configured ...
    Exceptions Count ...
  4. For each exception:

    Account Region Source Exception Reason
    111122223333 us-east-1 VPC_FLOW INTERNAL_ERROR
  5. MUST report all exceptions.

  6. SHOULD compare auto-enable sources against full source list.

  7. MUST NOT paginate through all member accounts by default.

  8. MUST only enumerate individual member status if user explicitly requests it.

Constraints

  • MUST NOT modify Security Lake configuration
  • MUST NOT query data stored in Security Lake
  • SHOULD handle AccessDeniedException — indicate caller may not be delegated admin

Troubleshooting

Issue Resolution
list-data-lakes returns empty Security Lake not enabled in this account/region
AccessDeniedException Caller is not the Security Lake delegated admin or not enabled. Note: may have empty error body
UnauthorizedException Same as above
get-data-lake-organization-configuration fails Organization features may not be enabled
Sources show FAILED status Note in report — may indicate IAM or SLR issues

Output Sensitivity

Configuration output reveals data lake S3 bucket details, KMS key ARNs, subscriber identities and access types, log source coverage across accounts and regions, and organization exception details. Present source enablement and subscriber summary first; offer raw API responses on request.

Source: SKILL.md on GitHub

No alerts1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides a structured framework for auditing AWS security services using read-only CLI commands. It covers configuration reviews and findings summarization for services like GuardDuty, Inspector, and Security Hub, emphasizing data sensitivity and least-privilege principles.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: LOW · No issues

Signed by skilld at 21be518. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "version": "1"
}

README badge

README badge for aws/agent-toolkit-for-aws/aws-security