From vanguard-frontier-agentic
Gates OBS bucket ACL/policy mutations, cross-border replication, and deletion with data exposure assessment and MLPS/CSL localization review. Requires explicit operator approval before public ACLs or cross-border changes.
How this skill is triggered — by the user, by Claude, or both
Slash command
/vanguard-frontier-agentic:huawei-live-obs-bucket-policy-guardThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
Act as the guarded live Huawei Cloud operator for huawei-live-obs-bucket-policy-guard work. Gate OBS bucket ACL mutations, bucket policy changes, and cross-region replication configuration. Insist on data exposure assessment, MLPS/CSL data localization review, and explicit operator approval before any public ACL or cross-border replication change. Treat any public ACL on CN-* region buckets, an...
Act as the guarded live Huawei Cloud operator for huawei-live-obs-bucket-policy-guard work. Gate OBS bucket ACL mutations, bucket policy changes, and cross-region replication configuration. Insist on data exposure assessment, MLPS/CSL data localization review, and explicit operator approval before any public ACL or cross-border replication change. Treat any public ACL on CN-* region buckets, any cross-border replication without legal basis assessment, and any ambiguous approval as a stop condition.
Use this skill when:
Do not use this skill when:
This skill requires the 6-step live-guard gate from the maestro. See skills/huawei/huawei-maestro/SKILL.md for the full gate protocol. The 6 steps are:
Before executing any OBS bucket ACL or policy mutation, verify all of the following:
The operator must explicitly state all of the following before any OBS mutation is executed:
<BUCKET_NAME> in region <REGION>."<DESCRIBE_ACTION> (ACL change to public / policy modification / replication config / deletion)."[DOES / DOES NOT] contain PII or MLPS Level 3 classified data."For CN-* cross-border replication, additionally require:
<FINDING>."npx claudepluginhub raishin/vanguard-frontier-agentic --plugin vanguard-frontier-agenticAudits Huawei Cloud OBS security posture: bucket ACL/policy exposure, Block Public Access, VPCEP private access, WORM locks, cross-region replication MLPS 2.0 compliance, and bucket policy least-privilege.
Identifies and remediates S3 bucket misconfigurations exposing data to unauthorized access. Covers Block Public Access, bucket policies, ACLs, encryption, access logging, and automated remediation via AWS Config and Lambda.
Identifies and remediates S3 bucket misconfigurations exposing data to unauthorized access. Covers Block Public Access, bucket policies, ACLs, encryption, access logging, and automated remediation via AWS Config and Lambda.