workspace/skills/aws-security-audit/SKILL.md
AWS security auditing — IAM users/roles/policies, CloudTrail API events, security posture analysis. Use when auditing IAM permissions, investigating security incidents, checking MFA compliance, or tracing API activity in CloudTrail.
npx skillsauth add automateyournetwork/netclaw aws-security-auditInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
uvx awslabs.iam-mcp-server@latest --readonly (stdio transport)uvx awslabs.cloudtrail-mcp-server@latest (stdio transport)AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_REGION (or AWS_PROFILE)--readonly flag prevents any IAM modificationsWhen a user asks "audit our AWS network security":
ec2:* or *:* actionsAuthorizeSecurityGroupIngress, CreateNetworkAcl, ModifyVpcAttribute eventsWhen investigating a security event:
DeleteSecurityGroup, ModifySubnetAttribute?When checking AWS security compliance:
* on sensitive services| Event Name | What It Means |
|------------|---------------|
| AuthorizeSecurityGroupIngress | Security group rule added (inbound) |
| AuthorizeSecurityGroupEgress | Security group rule added (outbound) |
| RevokeSecurityGroupIngress | Security group rule removed (inbound) |
| CreateNetworkAclEntry | NACL rule added |
| CreateRoute | Route table entry added |
| ModifyVpcAttribute | VPC setting changed |
| CreateVpnConnection | New VPN tunnel created |
| AttachInternetGateway | IGW attached to VPC |
| CreateTransitGatewayRoute | TGW route added |
| UpdateFirewallRuleGroupRuleList | Network Firewall rule changed |
| Check | Why It Matters |
|-------|---------------|
| No ec2:* policies | Prevent accidental network changes |
| Separate roles per service | Least privilege for VPC, TGW, Firewall |
| MFA on all humans | Protect against credential theft |
| No root access keys | Root should use MFA console only |
| Key rotation < 90 days | Limit exposure of compromised keys |
| CloudTrail enabled | Audit trail for all API changes |
AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_REGION (or AWS_PROFILE)tools
Zoom meeting intelligence — correlates a live or referenced Zoom meeting discussion against NetClaw's historical meeting record (via the official Zoom Meetings MCP) and today's actual network state. Use when someone in a Zoom meeting references a past discussion or incident ('didn't we have this issue before?'), or asks to search prior meetings for a topic. Does not itself recognize live in-meeting questions — that happens automatically inside zoom-rtms-mcp's own extractor (spec 118) before this skill is ever invoked.
tools
Manage Lantronix out-of-band (OOB) infrastructure via Percepxion central management platform: device inventory, serial port inspection via SLC CLI, firmware compliance, config management, security auditing, and closed-loop incident remediation. Use during outages, maintenance windows, compliance cycles, and AI-assisted automation workflows.
tools
Federate your NetClaw with other NetClaw operators over the BGP mesh — exchange capability inventories and ask your claw what a peer can do. (US1; remote invocation and chat land in later phases.)
tools
Track token consumption, enforce session budgets, and display cost for every NetClaw interaction.