back
loading skill details...
AWS security service suitability, coverage and cost recommendations: WAF/origin overlap, AWS Network Firewall inspection coverage and policy review, VPC…
AWS Security Use this skill with local AWS CLI or AWS MCP. AWS MCP is recommended for sandboxed execution and audit logging. Read the relevant bundled procedure before operational guidance. Match intent before service name; reuse an already-read, current copy. For conceptual questions, explain from the relevant reference without AWS account discovery. Live reads require an account assessment request and established scope; an example, prioritization question or suitability question alone does not authorize discovery. Global rules Read-only APIs only. This skill and all its references use exclusively non-mutating APIs. Never invoke mutating operations or provide write-API commands. Only the selected service-recommendations workflow may advise configuration and lifecycle changes in prose, with a separate implementation handoff for accepted recommendations. It covers focused service suitability and scoped evidence, never rule/code authoring or scan, analysis, query or export initiation. All other procedures report factual state. See the selected reference files for read-only API scope. Scoped recommendation priorities. Present configuration state factually outside the selected service-recommendations workflow; do not assign configuration severity, gap assessments, or editorial framing there. Only that workflow may assess coverage gaps and assign recommendation priorities from verified evidence. These priorities are workflow-authored, not observed findings severity or guide-assigned ratings. Preserve service-reported findings severity and the findings ordering below in every workflow. No false-positive suppression recommendations. Focus on helping customers understand findings. Do not recommend suppression filters, archival rules, or finding dismissal. Prioritize Attack Sequences in GuardDuty. GuardDuty documents AttackSequence: findings as Critical correlated multi-step attacks. Surface them first, before severity breakdown. Preserve actual reported severity and flag any discrepancy instead of rewriting it. Prioritize Exposure findings in Security Hub. Exposure findings (attack paths, resource exposure) represent Security Hub's unique cross-service correlation. Surface these first in any findings summary. Expensive operations require explicit request. MUST NOT paginate through all member accounts by default. Per-account enumeration only executes if the user explicitly requests detailed account-level information. Use statistics/count APIs only where their verified filters constrain the authorized account/resource scope; an unfiltered delegated-admin aggregate is not local-account evidence.
don't have the plugin yet? install it then click "run inline in claude" again.