AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
anyshift-io avatar

anyshift-io

5 listings · 0 installs

Open-source publisher. Listings imported from github.com/anyshift-io — credited to the original author with their license.

↗ github.com/anyshift-io
5 results
Self-run
SKILL

Iam Deceptive Escalation Auditor

Audit the union of every IAM policy attached to one principal for privilege-escalation paths that no single statement reveals, and for apparent escalations that are already neutralised. Resolves the effective permission set across all attached policies (Allow minus blanket Deny), then checks the cross-statement escalation combos (iam:PassRole + a compute-launch action, policy-rewrite-in-place, fu…

0
41
Free
Self-run
SKILL

Sqs Queue Auditor

Audit a single AWS SQS queue's configuration for the misconfigurations that silently drop or re-deliver messages while every attribute reads as fine. Parses the GetQueueAttributes output (and the referenced dead-letter queue), checks the redrive path (DLQ present, maxReceiveCount band, DLQ-vs-source retention ordering), the message lifecycle (poison messages aging out before they reach the DLQ, d…

0
31
Free
Self-run
SKILL

Kubectl Investigator

Investigate a live or recent incident in a Kubernetes cluster. Anchor the window, bisect the change surface (rollouts, ConfigMaps/Secrets, RBAC, HPA/cluster changes, CronJobs), classify against four reference failure paths (OOM, DNS, cascading-failure, deploy-correlator), confirm the hypothesis with three independent signals, quantify blast radius, and propose mitigation before root cause. Use wh…

0
36
Free
Self-run
SKILL

S3 Estate Calibration Auditor

Audit an estate of AWS S3 buckets for the one bucket that is genuinely publicly or cross-account exposed, without over-flagging the many buckets that READ as exposed but are neutralised. Resolves each bucket's EFFECTIVE verdict by composing four layers (Block Public Access x bucket policy x bucket ACL x access points), never one layer alone, then rolls the per-bucket verdicts up into an estate ve…

0
35
Free
Self-run
SKILL

Sg Deceptive Reachability Auditor

Audit a fleet of AWS security groups for the multi-hop lateral-movement path that no single ingress rule reveals. Builds a directed reachability graph from the SG-to-SG references (an ingress rule on SG B naming SG A means a host in A can reach B), adds an internet edge for every 0.0.0.0/0 rule, then composes those edges into the transitive closure from a named entry point (the internet, or a com…

0
40
Free
You've reached the end · 5 loaded