From cloud-security
Review a cloud environment's security posture (AWS/Azure/GCP) across IAM, network, data protection, logging/monitoring, and workload configuration, mapped to CIS benchmarks, and produce ranked findings. Use for a CSPM-style assessment of an account/subscription/project you're authorized to review.
How this skill is triggered — by the user, by Claude, or both
Slash command
/cloud-security:cloud-posture-reviewThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
A posture assessment across the major control domains, each with findings,
A posture assessment across the major control domains, each with findings, severity, and remediation, anchored to CIS Benchmarks / provider best practice.
reference.md for per-provider checks)cloud-iam-review.)reference.md; for identity use cloud-iam-review, for
exposure quick-wins use cloud-misconfig-scan.security-reporting:cvss) and rank; highlight internet-exposed and
identity findings first.A posture report grouped by domain with a CIS-mapped findings table + ranked top
risks. Confirmed issues → security-reporting:finding; architecture via
security-diagramming:architecture-diagram.
Most cloud breaches trace to identity over-permission and public exposure of data/compute — weight those. Map findings to CIS controls for traceability; verify against the current benchmark version for the provider.
npx claudepluginhub jassics/awesome-claude-security --plugin cloud-securityProvides CDSS development patterns for drug interaction checking, dose validation, clinical scoring (NEWS2, qSOFA), and alert classification integrated into EMR workflows.