Back to skill

Security audit

Compliance Analyzer

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent AWS compliance helper, but its documented “minimum” IAM policy is broader than the shown workflow needs and could expose sensitive AWS security posture data.

Review the IAM policy before using the skill. Prefer a short-lived, read-only role with only the exact AWS Config and Security Hub actions needed for the exports, and avoid adding the unused IAM policy-listing permissions unless you separately need them.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:38
Finding

Overly Broad AWS Read Permissions Presented as Minimum Required Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 38–49
Vulnerability Type: Excessive IAM permissions and violation of least privilege
Risk Level: Medium

The Skill presents the following IAM policy as the minimum permissions required to run its documented AWS CLI commands:

json
{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": ["config:Describe*", "config:Get*", "config:Select*", "securityhub:GetFindings", "iam:GetPolicy", "iam:ListPolicies"],
    "Resource": "*"
  }]
}

Technical Analysis

The wildcard permissions config:Describe*, config:Get*, and config:Select* authorize substantially more AWS Config read operations than the three documented commands require. In addition, iam:GetPolicy and iam:ListPolicies are not used by any command documented in the Skill.

The stated workflows require only the actions corresponding to these operations:

  • config:DescribeComplianceByConfigRule
  • securityhub:GetFindings
  • config:SelectResourceConfig

Presenting broader permissions as the minimum required policy violates the principle of least privilege. Although these are read-only permissions, they can expose extensive account configuration, compliance posture, resource metadata, and IAM policy information. Such information can facilitate security reconnaissance and help identify weak controls, sensitive resources, or potential privilege-escalation paths.

Attack Path

  1. A user trusts the Skill's assertion that the supplied policy represents the minimum required access.
  2. The user attaches the policy to an IAM principal, role, or automation environment.
  3. That principal receives wildcard AWS Config read permissions and unnecessary IAM policy-enumeration permissions.
  4. If the principal's credentials or execution context are compromised, an attacker can invoke additional permitted APIs beyond the documented workflow.
  5. The attacker ...[truncated 1210 chars]
Remediation
View remediation

Remediation Suggestions

Replace wildcard action families with the exact permissions used by the documented commands:

json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "ExportComplianceAnalysisData",
      "Effect": "Allow",
      "Action": [
        "config:DescribeComplianceByConfigRule",
        "config:SelectResourceConfig",
        "securityhub:GetFindings"
      ],
      "Resource": "*"
    }
  ]
}

Additional hardening measures:

  1. Remove iam:GetPolicy and iam:ListPolicies from the baseline policy because the documented commands do not use them.
  2. If IAM policy analysis is later added, document that workflow separately and provide an optional, narrowly scoped policy.
  3. Retain "Resource": "*" only for API actions that do not support resource-level IAM restrictions; otherwise, restrict access to explicit resource ARNs.
  4. Apply permission boundaries and AWS Organizations service control policies where appropriate.
  5. Use a dedicated short-lived role for data exports rather than attaching these permissions to a persistent user.
  6. Restrict Security Hub access to required regions and export only the fields needed for the compliance assessment.
  7. Validate the effective permissions with IAM Access Analyzer or policy simulation before deployment.
  8. Update the documentation so that permissions are described accurately as required or optional rather than collectively labeled as minimum access.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.