# Ops Aws Audit

> Read-only AWS account hygiene audit — security baseline, unused/orphaned resources, and cost optimization across all configured regions. Produces severity-ranked findings (CRITICAL→LOW) plus a machine-readable findings.json. Cleanup actions are always human-gated, never automatic. Use for cost reviews, security sweeps, recurring account hygiene, or "audit my AWS".

- **Type:** Skill
- **Install:** `agentstack add skill-lifecycle-innovations-limited-claude-ops-ops-aws-audit`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [Lifecycle-Innovations-Limited](https://agentstack.voostack.com/s/lifecycle-innovations-limited)
- **Installs:** 0
- **Category:** [Cloud & Infrastructure](https://agentstack.voostack.com/c/cloud-infrastructure)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [Lifecycle-Innovations-Limited](https://github.com/Lifecycle-Innovations-Limited)
- **Source:** https://github.com/Lifecycle-Innovations-Limited/claude-ops/tree/main/claude-ops/skills/ops-aws-audit
- **Website:** https://github.com/Lifecycle-Innovations-Limited/claude-ops/wiki

## Install

```sh
agentstack add skill-lifecycle-innovations-limited-claude-ops-ops-aws-audit
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

## What this does

Runs `scripts/ops-aws-audit.sh` — a **read-only** sweep that never mutates AWS.
It inventories and analyses, then writes a severity-ranked report.

Checks include (2026 baseline):

- **IAM / credentials** — root access key + root MFA, access keys older than
  `AUDIT_KEY_AGE_DAYS` (default 90), console users without MFA, and whether an
  **IAM Access Analyzer (UNUSED_ACCESS)** is configured.
- **EC2 / EBS** — unattached volumes, `gp2`→`gp3` candidates, unencrypted
  volumes, unassociated Elastic IPs, security groups open to `0.0.0.0/0` on
  SSH/RDP.
- **RDS** — unencrypted or publicly-accessible instances, and **orphaned manual
  snapshots** whose source DB no longer exists.
- **S3** — account-level Block Public Access, per-bucket default encryption and
  lifecycle policies.
- **CloudWatch Logs** — log groups with no retention (billed forever).
- **Lambda** — deprecated/old runtimes.
- **Security posture** — GuardDuty, Security Hub standards, Cost Anomaly
  Detection monitors, Compute Optimizer enrollment.
- **Cost** — per-service spend over the last `AUDIT_COST_DAYS` with the Δ vs the
  prior window (surfaces spend spikes, per ops cost-leak doctrine).

## Configuration (env, all optional)

| Var                  | Default                           | Meaning                                                                     |
| -------------------- | --------------------------------- | --------------------------------------------------------------------------- |
| `AUDIT_PROFILE`      | _(unset)_                         | Named AWS profile. Unset ⇒ standard chain (env keys / instance role / SSO). |
| `AUDIT_REGIONS`      | `$AWS_REGION` or `us-east-1`      | Comma-separated regions.                                                    |
| `AUDIT_OUTPUT_DIR`   | `~/.aws-audit-history/audit-` | Where reports land.                                                         |
| `AUDIT_KEY_AGE_DAYS` | `90`                              | Active access-key age threshold.                                            |
| `AUDIT_COST_DAYS`    | `7`                               | Cost comparison window.                                                     |

## How to run

```bash
# one region, current account
bash "${CLAUDE_PLUGIN_ROOT}/scripts/ops-aws-audit.sh"

# multi-region + named profile
AUDIT_PROFILE=prod AUDIT_REGIONS=us-east-1,eu-central-1 \
  bash "${CLAUDE_PLUGIN_ROOT}/scripts/ops-aws-audit.sh"
```

Outputs in `AUDIT_OUTPUT_DIR`: `report.md` (human), `findings.json`
(machine), `raw/` (per-service snapshots + `cost-delta.tsv`), `audit.log`.

After the run, read `findings.json` and summarise CRITICAL/HIGH first.

## Recurring schedule

`--schedule` installs a daily `systemd --user` timer via
`scripts/install-aws-audit-cron.sh` (Linux; this box uses systemd, not launchd):

```bash
bash "${CLAUDE_PLUGIN_ROOT}/scripts/install-aws-audit-cron.sh"
systemctl --user list-timers ops-aws-audit.timer
```

Dispatch to the background fleet instead:

```bash
claude --bg --name aws-audit -- bash "${CLAUDE_PLUGIN_ROOT}/scripts/ops-aws-audit.sh" --quiet
```

## Cleanup is human-gated (never automatic)

This skill **only audits**. To act on a finding:

1. Show the user the specific finding(s) and the exact `aws` command(s).
2. Get explicit per-batch approval (`ok` / `yes` / `proceed`).
3. For any deletion/rotation, snapshot state first; log resource IDs after.
4. **Root access keys can only be removed from a root console login** — flag it,
   do not attempt to "rotate root" from an IAM-user CLI session (that only
   rotates the IAM user's own key, not the root key).

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [Lifecycle-Innovations-Limited](https://github.com/Lifecycle-Innovations-Limited)
- **Source:** [Lifecycle-Innovations-Limited/claude-ops](https://github.com/Lifecycle-Innovations-Limited/claude-ops)
- **License:** MIT
- **Homepage:** https://github.com/Lifecycle-Innovations-Limited/claude-ops/wiki

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-lifecycle-innovations-limited-claude-ops-ops-aws-audit
- Seller: https://agentstack.voostack.com/s/lifecycle-innovations-limited
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
