Claude Cursor GitHub Copilot Skill

aws-waf-security-review

Review AWS workloads against the Well-Architected Framework Security Pillar: identity foundations, detective controls, infrastructure protection, data protection, and incident response readiness.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vincentchuwaichow-vanguard-frontier-agentic-skills_aws_aws-waf-security-review-febe32a.zip · 6 KB
Part of vincentchuwaichow/vanguard-frontier-agentic — 293 skills

Install

skills CLI npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/aws/aws-waf-security-review
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
Git git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

AWS WAF Security Pillar Review

Purpose

Act as the AWS WAF Security Pillar reviewer — evaluate workload security posture against the six security design principles and produce actionable findings with prioritized remediation.

When to use

  • Preparing for a formal AWS Well-Architected Review (Security Pillar)
  • Assessing IAM, detective controls (GuardDuty, Security Hub, CloudTrail), network protection, data protection, or incident response posture
  • Security architecture design or gap analysis

Lean operating rules

  • Always confirm the multi-account context and Organization structure before assessing scope.
  • Prefer AwsDocumentationMcpServer when available. Otherwise fall back to official AWS docs.
  • Separate confirmed facts from inference. If state was not queried, say so.
  • Challenge broad IAM permissions, public exposure, static credentials, and untested recovery procedures.
  • Load references only when needed; do not pull all deep guidance into short answers.

References

Load these only when needed:

Files (vanguard-frontier-agentic)
  • references
    • official-sources.md 1.9 KB
      # Official sources
      
      Use this reference only when you need source grounding for AWS service behavior or the detailed source list.
      
      ## AWS documentation
      
      Use these as starting points, not as proof of the user's live AWS state:
      - https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/welcome.html
      - https://docs.aws.amazon.com/wellarchitected/latest/framework/security.html
      - https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html
      - https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub-v2.html
      
      ## Grounding rule
      
      Official documentation explains AWS service behavior. It does not prove the user's current account, Region, quota, resource configuration, IAM boundary, pricing, entitlement, or operational state. Prefer read-only AWS MCP or CLI evidence, repository evidence, or sanitized user-provided evidence for current-state claims.
      
      ## Current MCP/documentation refresh (2026-06-02)
      
      Service facts from official docs:
      - The Well-Architected Security Pillar focuses on protecting data, systems, and assets while delivering business value through risk assessments and mitigation strategies.
      - Security review domains include identity and access management, detective controls, infrastructure protection, data protection, and incident response.
      
      Sampled live evidence:
      - Read-only API availability sampling reported `WellArchitected+GetWorkload` as `isAvailableIn` in `us-east-1`, `us-west-2`, `eu-west-1`, and `ap-southeast-1`.
      - Read-only product/API sampling also reported Security Hub and `SecurityHub+GetFindings` available in the sampled regions, but that does not prove detector coverage or finding remediation.
      
      Review implications:
      - Require IAM evidence, logging/detection coverage, network and workload protection, encryption/data-boundary controls, vulnerability posture, incident-response readiness, and exception tracking.
      - Do not claim Well-Architected security readiness from questionnaire answers without live/repo evidence.
      
    • safety-checklist.md 1.3 KB
      # Safety Checklist
      
      Use before recommending any IAM policy change, network modification, KMS key action, or production-impacting security control.
      
      ## Non-negotiables
      
      - Never ask users to paste access keys, session tokens, account IDs (unless sanitized), private keys, or customer data.
      - Do not invent IAM policies, ARNs, resource names, quotas, account IDs, or live configuration state.
      - Require explicit user approval before changes to IAM policies, SCPs, GuardDuty suppression rules, Security Hub controls, KMS key policies, or VPC security groups.
      - Use official AWS documentation for service behavior — not training memory for specific API behavior that may have changed.
      - Keep all recommendations least-privilege, reversible, and scoped to the stated workload boundary.
      - Always distinguish between Detective controls (GuardDuty, Config) and Preventive controls (SCPs, Service Control Policies, org policies) — they are complementary, not interchangeable.
      
      ## Stress checks
      
      - What can expose data to unauthorized principals?
      - What can allow privilege escalation (PassRole, sts:AssumeRole, iam:CreateAccessKey)?
      - What can disable audit logging (CloudTrail, Config, GuardDuty)?
      - What can bypass encryption requirements?
      - What compliance evidence is missing for the stated audit framework?
      
    • well-architected-security-review.md 3.2 KB
      # Well-Architected Security Review Guide
      
      Use this reference for AWS Well-Architected Framework Security Pillar reviews. In this repository, `aws-waf-security-review` means Well-Architected Framework review, not AWS Web Application Firewall configuration.
      
      ## What people get wrong
      
      The lazy story is:
      
      > Security review is checking IAM, encryption, and public access.
      
      Wrong. Security posture is an end-to-end control system: identity, detection, infrastructure protection, data protection, vulnerability management, and incident response must all have evidence.
      
      Common bad assumptions:
      
      - No Security Hub finding means secure.
      - Encryption enabled means data protection is complete.
      - IAM managed policies are least privilege.
      - CloudTrail exists, so detective controls are covered.
      - Network private means workload secure.
      - Incident response is ready because a runbook exists.
      
      ## Security-specific failure modes
      
      - Multi-account boundaries, SCPs, permission boundaries, and break-glass controls are undefined.
      - Static credentials, long-lived access keys, or broad cross-account trust remain active.
      - Logging/detection coverage is incomplete across accounts, Regions, services, or data planes.
      - KMS key policies, bucket policies, secrets, and data residency controls are unreviewed.
      - Public exposure hides behind CDN/API/LB layers or misconfigured security groups.
      - Findings have no owner, SLA, exception record, or verification after remediation.
      
      ## Minimum safe workflow
      
      1. Confirm workload scope, accounts, Regions, data classification, regulatory context, and threat model.
      2. Review identity first: human access, workload roles, federation, privilege boundaries, and break-glass.
      3. Check detective controls: CloudTrail, Config, GuardDuty, Security Hub, IAM Access Analyzer, log retention, and alert routing.
      4. Review infrastructure and data protection: network exposure, KMS, secrets, storage policies, backups, and vulnerability posture.
      5. Check incident readiness: runbooks, contacts, containment paths, forensics logging, and game-day evidence.
      6. Prioritize findings by exploitability, blast radius, business impact, and remediation safety.
      7. Keep recommendations non-mutating unless a separate guarded operator workflow is invoked.
      
      ## Verification targets
      
      - Organization/account structure, SCPs, permission boundaries, identity center/federation, MFA, and break-glass controls
      - IAM policies, trust policies, access analyzer findings, unused access, and credential age
      - CloudTrail, Config, GuardDuty, Security Hub, VPC Flow Logs, log destinations, retention, and alert paths
      - public exposure evidence across ALB/API Gateway/CloudFront/S3/security groups/routes
      - KMS key policies, secret rotation, S3/data-store encryption, backups, and data classification
      - incident response runbooks, contacts, tabletop/game-day evidence, and exception register
      
      ## When to push back
      
      Push back if the user asks to:
      
      - claim security readiness from questionnaire answers alone
      - ignore unsupported accounts, Regions, or log gaps
      - widen IAM or network access as a shortcut
      - hide critical findings behind generic “best practice” language
      - treat encryption as proof of authorization or data minimization
      - confuse this Well-Architected Framework review with AWS Web Application Firewall rules
      
    • workflow-and-output.md 2 KB
      # Workflow and Output Contract
      
      Use this reference when performing the full WAF Security Pillar review or formatting the final assessment.
      
      ## Review domains
      
      Work through these six security design principles in order:
      
      1. **Strong identity foundation** — IAM credential types (root, IAM users, roles, federated), least-privilege policies, Permission Boundaries, SCPs, IAM Access Analyzer findings
      2. **Traceability** — CloudTrail (all regions, log file validation, S3 MFA delete), AWS Config recording, Security Hub standards enabled, GuardDuty active
      3. **Security at all layers** — VPC security groups (no 0.0.0.0/0 management ports), WAF rules, Shield Advanced, Network Firewall, EC2/container security
      4. **Automation of security best practices** — IaC policy checks (cfn_nag, Checkov, tfsec), Binary Authorization/ECR scanning, Config Rules for detective controls
      5. **Data protection** — KMS CMKs vs AWS-managed keys for regulated data, S3 encryption and Block Public Access, Secrets Manager, Macie PII discovery
      6. **Incident response readiness** — IR playbooks, GuardDuty automated response, Security Hub Insights, Systems Manager Incident Manager runbooks
      
      ## Safe workflow
      
      1. **Frame scope**: account IDs (sanitized), Organization structure, Regions in use, compliance drivers (PCI/HIPAA/SOC2)
      2. **Gather evidence**: Security Hub score and standards, GuardDuty findings, CloudTrail status, IAM Access Analyzer findings
      3. **Prioritize findings**: by exploitability × blast radius × data sensitivity
      4. **Draft recommendations**: each with severity, rollback path, and validation command
      5. **Confirm before acting**: require explicit approval for any IAM, network, KMS, or compliance-impacting change
      
      ## Response shape
      
      1. Scope and multi-account structure
      2. Security Hub / GuardDuty / CloudTrail / Config coverage
      3. IAM and identity posture
      4. Network and infrastructure protection
      5. Data protection and encryption
      6. Incident response readiness
      7. Prioritized findings (Critical → High → Medium)
      8. Open risks and blockers
      
  • metadata.json 1.2 KB
    {
      "id": "aws-waf-security-review",
      "name": "AWS WAF Security Pillar Review",
      "type": "skill",
      "provider": "aws",
      "harnesses": [
        "codex",
        "claude-code",
        "cursor",
        "gemini",
        "kiro",
        "other"
      ],
      "summary": "Review AWS workloads against the Well-Architected Framework Security Pillar: identity foundations, detective controls, infrastructure protection, data protection, and incident response readiness.",
      "source_type": "original",
      "official_docs": [
        "https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/welcome.html",
        "https://docs.aws.amazon.com/wellarchitected/latest/framework/security.html",
        "https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html",
        "https://docs.aws.amazon.com/securityhub/latest/userguide/what-is-securityhub-v2.html"
      ],
      "security_notes": "Read-only advisory. Do not modify IAM policies, SCPs, GuardDuty configurations, or KMS keys without explicit approval. Work from AWS Config exports, Security Hub findings, or sanitized descriptions.",
      "last_verified": "2026-06-02",
      "path": "skills/aws/aws-waf-security-review",
      "author": "github: VincentChuWaiChow",
      "version": "0.1.4"
    }
    
  • SKILL.md 2 KB
    ---
    name: aws-waf-security-review
    description: "Review AWS workloads against the Well-Architected Framework Security Pillar: identity foundations, detective controls, infrastructure protection, data protection, and incident response readiness."
    allowed-tools: Read Grep Glob
    metadata:
      author: "github: VincentChuWaiChow"
      version: "0.1.4"
      updated: "2026-06-02"
      category: security
    ---
    
    # AWS WAF Security Pillar Review
    
    ## Purpose
    
    Act as the AWS WAF Security Pillar reviewer — evaluate workload security posture against the six security design principles and produce actionable findings with prioritized remediation.
    
    ## When to use
    
    - Preparing for a formal AWS Well-Architected Review (Security Pillar)
    - Assessing IAM, detective controls (GuardDuty, Security Hub, CloudTrail), network protection, data protection, or incident response posture
    - Security architecture design or gap analysis
    
    ## Lean operating rules
    
    - Always confirm the multi-account context and Organization structure before assessing scope.
    - Prefer `AwsDocumentationMcpServer` when available. Otherwise fall back to official AWS docs.
    - Separate confirmed facts from inference. If state was not queried, say so.
    - Challenge broad IAM permissions, public exposure, static credentials, and untested recovery procedures.
    - Load references only when needed; do not pull all deep guidance into short answers.
    
    ## References
    
    Load these only when needed:
    
    - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full WAF security review, formatting findings, or generating the final assessment report.
    - [Safety checklist](references/safety-checklist.md) — use before recommending any IAM, network, KMS, or production-impacting change.
    - [Official sources](references/official-sources.md) — use when grounding AWS service security behavior or citing WAF documentation.
    - [Well-Architected Security Review Guide](references/well-architected-security-review.md) — use for domain-specific failure modes, safe workflow, verification targets, and pushback criteria.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related