All skills
aws avatar

/securing-s3-buckets

@803cbf4

Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations. Use when the user wants to secure a new bucket, audit an existing bucket, fix a security finding, configure encryption, or enable logging and monitoring. Do NOT use for general S3 data operations, S3 Tables setup, or discovering existing data assets.

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/securing-s3-buckets

This session only. Nothing lands on disk.

referencesiam-permissions.md

≈352 tokens on demand. Your agent reads this file only when SKILL.md points to it.

IAM Permissions by Workflow

Minimum IAM permissions required for each workflow. Use aws iam simulate-principal-policy to validate effective permissions before write operations.

Workflow Minimum permissions needed
A — Secure New Bucket s3:CreateBucket, s3:PutBucketVersioning, s3:PutEncryptionConfiguration, s3:PutBucketLogging, s3:PutBucketPolicy, s3:GetBucketPolicy, s3:PutBucketAbacStatus, cloudtrail:DescribeTrails, cloudtrail:PutEventSelectors
B — Audit s3:GetBucketPublicAccessBlock, s3:GetBucketAcl, s3:GetBucketOwnershipControls, s3:GetEncryptionConfiguration, s3:GetBucketVersioning, s3:GetBucketLogging, s3:GetBucketPolicy, s3:GetBucketObjectLockConfiguration, accessanalyzer:ListAnalyzers, accessanalyzer:ListFindings, cloudtrail:GetEventSelectors, cloudtrail:DescribeTrails, guardduty:ListDetectors, guardduty:GetDetector
C — Remediate s3:PutBucketPublicAccessBlock, s3:GetBucketPolicy, s3:PutBucketPolicy, s3:PutEncryptionConfiguration, kms:CreateKey, kms:PutKeyPolicy, kms:DescribeKey, iam:SimulatePrincipalPolicy
D — Encryption s3:PutEncryptionConfiguration, kms:CreateKey, kms:PutKeyPolicy, kms:DescribeKey
E — Monitoring cloudtrail:DescribeTrails, cloudtrail:PutEventSelectors, guardduty:ListDetectors, guardduty:CreateDetector, config:PutConfigRule

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill implements AWS S3 security best practices for access control, encryption, and monitoring. It includes robust safety mechanisms such as policy backups, JSON validation, and permission simulation. While it interacts with infrastructure via command execution and processes external data, these are handled within a secure framework.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at 803cbf4. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 5 months ago
version
1

README badge

README badge for aws/agent-toolkit-for-aws/securing-s3-buckets