All skills
aws avatar

/aws-security

@21be518

Covers AWS security services and workflows — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, and security posture summaries; Security Hub CSPM (V1/ASFF) controls and compliance standards; GuardDuty threat findings; Inspector vulnerability findings; Macie sensitive data findings; Detective investigation; and Security Lake configuration and data aggregation. Applicable when questions involve security posture, Exposure findings, CSPM failed controls, threat findings, vulnerability findings, sensitive data findings, automation rules, or cross-service security configuration across AWS environments. Procedures use standard AWS CLI syntax and work with or without the AWS MCP server.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/aws-security

This session only. Nothing lands on disk.

referencessecurity-lake-sources.md

≈919 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Summarizing Security Lake Sources

Overview

Produces structured summaries of Amazon Security Lake source configuration, subscriber status, and data lake exceptions. Gives operators a rapid view of data lake health without performing data queries.

Works from both standalone and delegated administrator accounts.

Classify the Request

User intent Workflow
"What sources are configured?" A: Sources & Ingestion Summary
"Show subscribers" / "Any data lake issues?" B: Subscriber & Exception Overview

Workflow A: Sources & Ingestion Summary

  1. Get configured sources:

    aws securitylake get-data-lake-sources
  2. List log sources for detail:

    aws securitylake list-log-sources
  3. Check data lake regions:

    aws securitylake list-data-lakes
  4. Present source summary per region:

    Region Source Status Account Count
    us-east-1 CLOUD_TRAIL_MGMT ACTIVE 12
    us-east-1 VPC_FLOW ACTIVE 12
    us-east-1 ROUTE53 ACTIVE 8
  5. MUST list all regions where Security Lake is enabled.

  6. SHOULD note any source with non-ACTIVE status.

  7. MAY include custom sources if present.

  8. (ONLY if user asks about volume or ingestion size) Query CloudWatch:

    aws cloudwatch get-metric-statistics --namespace AWS/SecurityLake --metric-name ProcessedSize --dimensions Name=Source,Value=<SOURCE_NAME> --start-time <7-days-ago> --end-time <now> --period 86400 --statistics Sum

    Repeat for each source. Shows total stored bytes per source per day — useful for identifying sources that stopped ingesting.

Workflow B: Subscriber & Exception Overview

  1. List subscribers:

    aws securitylake list-subscribers
  2. For each subscriber:

    aws securitylake get-subscriber --subscriber-id <id>
  3. List exceptions:

    aws securitylake list-data-lake-exceptions
  4. Present subscriber summary:

    Subscriber Access Type Status Sources Subscribed
    SIEM-Integration S3 ACTIVE ALL
    Analytics-Team LAKEFORMATION ACTIVE VPC_FLOW, CLOUD_TRAIL_MGMT
  5. Present exception summary:

    Account Region Source Exception
    111122223333 eu-west-1 VPC_FLOW INTERNAL_ERROR
  6. MUST report total subscriber count and access type breakdown.

  7. MUST report exception count — zero exceptions is healthy.

  8. SHOULD note subscribers in non-ACTIVE status.

Constraints

  • MUST NOT perform data queries against Security Lake
  • MUST NOT modify configuration, subscribers, or sources
  • MUST NOT query CloudWatch metrics by default — only if user explicitly asks about volume
  • MUST present data as-is in structured tables
  • SHOULD handle AccessDeniedException gracefully

Troubleshooting

Symptom Resolution
get-data-lake-sources returns empty Security Lake not enabled or no sources configured
AccessDeniedException Caller is not Security Lake delegated admin or not enabled
UnauthorizedException Same as above
Subscriber DEACTIVATED Note in summary — may have been disabled
High exception count Summarize by account/region — may indicate rollout issues

Output Sensitivity

Source summary reveals data lake regions, per-source ingestion status across accounts, subscriber identities and access configurations, and exception details (account IDs, failure reasons). Present source status table and subscriber overview first. Display full configuration details only when the caller explicitly requests raw output.

Source: SKILL.md on GitHub

No alerts1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill provides a structured framework for auditing AWS security services using read-only CLI commands. It covers configuration reviews and findings summarization for services like GuardDuty, Inspector, and Security Hub, emphasizing data sensitivity and least-privilege principles.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: LOW · No issues

Signed by skilld at 21be518. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "version": "1"
}

README badge

README badge for aws/agent-toolkit-for-aws/aws-security