Verified corrections for IAM behaviors that AI agents frequently get\
AWS IAM — Common Pitfalls About This Skill This skill contains verified corrections for things that AI agents frequently get wrong about IAM. It is not a comprehensive IAM guide — for full IAM guidance, search AWS documentation. When answering IAM questions, verify specific claims (limits, quotas, exact API names, edge-case behaviors) against official AWS documentation rather than relying on pre-training. Prefer fetching known documentation URLs over broad searches. Trust official documentation over memory when they conflict. Verified Edge Cases CloudTrail: AcceptHandshake/DeclineHandshake logged in ACTING account ONLY, not management account. Organization trail required for centralization. ConsoleLogin region varies by endpoint/cookies, NOT always us-east-1. ?region= forces specific region. STS:
don't have the plugin yet? install it then click "run inline in claude" again.