All skills
aws avatar

/securing-s3-buckets

@803cbf4

Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations. Use when the user wants to secure a new bucket, audit an existing bucket, fix a security finding, configure encryption, or enable logging and monitoring. Do NOT use for general S3 data operations, S3 Tables setup, or discovering existing data assets.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/securing-s3-buckets

This session only. Nothing lands on disk.

referencesaudit-checklist.md

≈601 tokens on demand. Your agent reads this file only when SKILL.md points to it.

S3 Security Audit Checklist

Critical (fix immediately)

Control Check command Pass condition
Block Public Access get-public-access-block All 4 flags true
No public bucket policy get-bucket-policy No "Principal": "*" or "Principal": {"AWS": "*"} with Allow
HTTPS enforced get-bucket-policy DenyInsecureTransport statement present
ACLs disabled get-bucket-ownership-controls BucketOwnerEnforced

High

Control Check command Pass condition
Default encryption enabled get-bucket-encryption SSEAlgorithm set
S3 Bucket Keys enabled get-bucket-encryption BucketKeyEnabled: true
SSE-C blocked get-bucket-encryption BlockedEncryptionTypes.EncryptionType contains SSE-C
Not using AWS managed key get-bucket-encryption KMSMasterKeyID is NOT aws/s3

Medium

Control Check command Pass condition
Versioning enabled get-bucket-versioning Status: Enabled
Logging enabled get-bucket-logging + cloudtrail get-event-selectors PASS if either S3 server access logging OR CloudTrail data events is configured; NOT CONFIGURED if neither
GuardDuty S3 Protection list-detectors + get-detector S3_DATA_EVENTS feature is ENABLED

Prerequisites

IAM Access Analyzer: The audit checklist requires an active analyzer. Before running list-findings, verify one exists:

aws accessanalyzer list-analyzers --region <region>

If the result is empty, report as a finding: "No IAM Access Analyzer configured in <region>". Creating the analyzer is a remediation action (Workflow C), not part of the audit.

Low / Compliance

Control Check command Pass condition
Object Lock (WORM) get-object-lock-configuration Enabled if compliance required
Cross-region replication get-bucket-replication Configured if DR required
Bucket in account namespace bucket name Ends with -<account-id>-<region>-an

AWS Config Rules

Core (always enable):

s3-bucket-public-read-prohibited
s3-bucket-ssl-requests-only
s3-bucket-versioning-enabled
s3-bucket-logging-enabled

Optional (enable if compliance requires):

s3-bucket-public-write-prohibited
s3-account-level-public-access-blocks
s3-bucket-replication-enabled
cloudtrail-s3-dataevents-enabled

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill implements AWS S3 security best practices for access control, encryption, and monitoring. It includes robust safety mechanisms such as policy backups, JSON validation, and permission simulation. While it interacts with infrastructure via command execution and processes external data, these are handled within a secure framework.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at 803cbf4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 5 months ago
version
1

README badge

README badge for aws/agent-toolkit-for-aws/securing-s3-buckets