Skip to main content Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
直接コマンドでは確認用 Prompt が省略されます。実行前にソースを確認してください。
npx skills add https://github.com/phoroth/AGENTIC --skill aws-compliance-checkerコマンドは1行のまま表示されます。コピー前に横へスクロールして全体を確認してください。
ローカルで確認しますか?SkillsMP が現在取得できるファイルをダウンロードできます。
| name | aws-compliance-checker |
| description | Automated compliance checking against CIS, PCI-DSS, HIPAA, and SOC 2 benchmarks |
| category | security |
| risk | safe |
| source | community |
| tags | [aws, compliance, audit, cis, pci-dss, hipaa, kiro-cli] |
| date_added | 2026-02-27 |
AWS Compliance Checker
Automated compliance validation against industry standards including CIS AWS Foundations, PCI-DSS, HIPAA, and SOC 2.
When to Use
Use this skill when you need to validate AWS compliance against industry standards, prepare for audits, or maintain continuous compliance monitoring.
Supported Frameworks
CIS AWS Foundations Benchmark
- Identity and Access Management
- Logging and Monitoring
- Networking
- Data Protection
PCI-DSS (Payment Card Industry)
- Network security
- Access controls
- Encryption
- Monitoring and logging
HIPAA (Healthcare)
- Access controls
- Audit controls
- Data encryption
- Transmission security
SOC 2
- Security
- Availability
- Confidentiality
- Privacy
CIS AWS Foundations Checks
Identity & Access Management (1.x)
#!/bin/bash
echo "=== CIS IAM Compliance Checks ==="
echo "1.1: Checking root account usage..."
root_usage=$(aws iam get-credential-report --output text | \
awk -F, 'NR==2 {print $5,$11}')
echo " Root password last used: $root_usage"
echo "1.2: Checking root MFA..."
root_mfa=$(aws iam get-account-summary \
--query 'SummaryMap.AccountMFAEnabled' --output text)
echo " Root MFA enabled: $root_mfa"
echo "1.3: Checking for unused credentials (>90 days)..."
aws iam get-credential-report --output text | \
awk -F, 'NR>1 {
if ($5 != "N/A" && $5 != "no_information") {
cmd = "date -d \"" $5 "\" +%s"
cmd | getline last_used
close(cmd)
now = systime()
days = (now - last_used) / 86400
if (days > 90) print " ⚠️ " $1 ": " int(days) " days inactive"
}
}'
echo "1.4: Checking access key age..."
aws iam list-users --query 'Users[*].UserName' --output text | \
while read user; do
aws iam list-access-keys --user-name "$user" \
--query 'AccessKeyMetadata[*].[AccessKeyId,CreateDate]' \
--output text | \
while read key_id create_date; do
age_days=$(( ($(date +%s) - $(date -d "$create_date" +%s)) / 86400 ))
if [ $age_days -gt 90 ]; then
policy=$(aws iam get-account-password-policy 2>&1)
| grep -q ;
| jq
aws iam get-credential-report --output text | \
awk -F,
Logging (2.x)
#!/bin/bash
echo "=== CIS Logging Compliance Checks ==="
echo "2.1: Checking CloudTrail..."
trails=$(aws cloudtrail describe-trails \
--query 'trailList[*].[Name,IsMultiRegionTrail,LogFileValidationEnabled]' \
--output text)
if [ -z "$trails" ]; then
echo " ❌ No CloudTrail configured"
else
echo "$trails" | while read name multi_region validation; do
echo " Trail: $name"
echo " Multi-region: $multi_region"
echo " Log validation: $validation"
status=$(aws cloudtrail get-trail-status --name "$name" \
--query 'IsLogging' --output text)
echo " Is logging: $status"
done
fi
echo "2.2: Checking log file validation..."
aws cloudtrail describe-trails \
--query 'trailList[?LogFileValidationEnabled==`false`].Name' \
--output text | \
while read trail; do
echo
aws cloudtrail describe-trails \
--query --output text | \
bucket;
public=$(aws s3api get-bucket-acl --bucket 2>&1 | \
grep -c )
[ -gt 0 ];
aws cloudtrail describe-trails \
--query \
--output text | \
name log_group;
[ = ];
recorders=$(aws configservice describe-configuration-recorders \
--query --output text)
[ -z ];
aws s3api list-buckets --query --output text | \
bucket;
logging=$(aws s3api get-bucket-logging --bucket 2>&1)
! | grep -q ;
aws ec2 describe-vpcs --query --output text | \
vpc;
flow_logs=$(aws ec2 describe-flow-logs \
--filter \
--query --output text)
[ -z ];
Monitoring (3.x)
#!/bin/bash
echo "=== CIS Monitoring Compliance Checks ==="
required_filters=(
"unauthorized-api-calls"
"no-mfa-console-signin"
"root-usage"
"iam-changes"
"cloudtrail-changes"
"console-signin-failures"
"cmk-changes"
"s3-bucket-policy-changes"
"aws-config-changes"
"security-group-changes"
"nacl-changes"
"network-gateway-changes"
"route-table-changes"
"vpc-changes"
)
log_group=$(aws cloudtrail describe-trails \
--query 'trailList[0].CloudWatchLogsLogGroupArn' \
--output text | cut -d: -f7)
if [ -z "$log_group" ] || [ "$log_group" = "None" ]; then
echo " ❌ CloudTrail not integrated with CloudWatch Logs"
else
echo "Checking metric filters for log group: $log_group"
existing_filters=$(aws logs describe-metric-filters \
--log-group-name "$log_group" \
--query 'metricFilters[*].filterName' --output text)
for filter in "${required_filters[@]}"; do
if echo "$existing_filters" | grep -q ;
Networking (4.x)
#!/bin/bash
echo "=== CIS Networking Compliance Checks ==="
echo "4.1: Checking SSH access (port 22)..."
aws ec2 describe-security-groups \
--query 'SecurityGroups[*].[GroupId,GroupName,IpPermissions]' \
--output json | \
jq -r '.[] | select(.[2][]? |
select(.FromPort == 22 and .IpRanges[]?.CidrIp == "0.0.0.0/0")) |
" ⚠️ \(.[0]): \(.[1]) allows SSH from 0.0.0.0/0"'
echo "4.2: Checking RDP access (port 3389)..."
aws ec2 describe-security-groups \
--query 'SecurityGroups[*].[GroupId,GroupName,IpPermissions]' \
--output json | \
jq -r '.[] | select(.[2][]? |
select(.FromPort == 3389 and .IpRanges[]?.CidrIp == "0.0.0.0/0")) |
" ⚠️ \(.[0]): \(.[1]) allows RDP from 0.0.0.0/0"'
echo "4.3: Checking default security groups..."
aws ec2 describe-security-groups \
--filters Name=group-name,Values=default \
--query 'SecurityGroups[*].[GroupId,IpPermissions,IpPermissionsEgress]' \
--output json | \
jq -r '.[] | select((.[1] | length) > 0 or (.[2] | length) > 1) |
" ⚠️ \(.[0]): Default SG has rules"'
PCI-DSS Compliance Checks
import boto3
def check_pci_compliance():
"""Check PCI-DSS requirements"""
ec2 = boto3.client('ec2')
rds = boto3.client('rds')
s3 = boto3.client('s3')
issues = []
sgs = ec2.describe_security_groups()
for sg in sgs['SecurityGroups']:
for perm in sg.get('IpPermissions', []):
for ip_range in perm.get('IpRanges', []):
if ip_range.get('CidrIp') == '0.0.0.0/0':
issues.append(f"PCI 1.2: {sg['GroupId']} open to internet")
volumes = ec2.describe_volumes()
for vol in volumes['Volumes']:
if not vol['Encrypted']:
issues.append(f"PCI 3.4: Volume {vol['VolumeId']} not encrypted")
iam = boto3.client('iam')
users = iam.list_users()
for user in users[]:
mfa = iam.list_mfa_devices(UserName=user[])
mfa[]:
issues.append()
cloudtrail = boto3.client()
trails = cloudtrail.describe_trails()
trails[]:
issues.append()
issues
__name__ == :
()
( * )
issues = check_pci_compliance()
issues:
()
:
()
issue issues:
()
HIPAA Compliance Checks
#!/bin/bash
echo "=== HIPAA Compliance Checks ==="
echo "Access Controls:"
aws iam get-credential-report --output text | \
awk -F, 'NR>1 && $4=="false" {print " ⚠️ " $1 ": No MFA (164.312(a)(2)(i))"}'
echo ""
echo "Audit Controls:"
trails=$(aws cloudtrail describe-trails --query 'trailList[*].Name' --output text)
if [ -z "$trails" ]; then
echo " ❌ No CloudTrail (164.312(b))"
else
echo " ✓ CloudTrail enabled"
fi
echo ""
echo "Encryption at Rest:"
aws ec2 describe-volumes \
--query 'Volumes[?Encrypted==`false`].VolumeId' \
--output text | \
while read vol; do
echo " ⚠️ $vol: Not encrypted (164.312(a)(2)(iv))"
done
aws rds describe-db-instances \
--query 'DBInstances[?StorageEncrypted==`false`].DBInstanceIdentifier' \
--output text | \
while read db; do
echo " ⚠️ $db: Not encrypted (164.312(a)(2)(iv))"
done
Automated Compliance Reporting
import boto3
import json
from datetime import datetime
def generate_compliance_report(framework='cis'):
"""Generate comprehensive compliance report"""
report = {
'framework': framework,
'generated': datetime.now().isoformat(),
'checks': [],
'summary': {
'total': 0,
'passed': 0,
'failed': 0,
'score': 0
}
}
if framework == 'cis':
checks = run_cis_checks()
elif framework == 'pci':
checks = run_pci_checks()
elif framework == 'hipaa':
checks = run_hipaa_checks()
report['checks'] = checks
report['summary']['total'] = len(checks)
report['summary']['passed'] = sum(1 for c in checks if c['status'] == 'PASS')
report['summary']['failed'] = report['summary']['total'] - report[][]
report[][] = (report[][] / report[][]) *
report
():
[]
():
[]
():
[]
__name__ == :
sys
framework = sys.argv[] (sys.argv) >
report = generate_compliance_report(framework)
()
( * )
()
()
()
(, ) f:
json.dump(report, f, indent=)
Example Prompts
- "Run CIS AWS Foundations compliance check"
- "Generate a PCI-DSS compliance report"
- "Check HIPAA compliance for my AWS account"
- "Audit against SOC 2 requirements"
- "Create a compliance dashboard"
Best Practices
- Run compliance checks weekly
- Automate with Lambda/EventBridge
- Track compliance trends over time
- Document exceptions with justification
- Integrate with AWS Security Hub
- Use AWS Config Rules for continuous monitoring
Kiro CLI Integration
kiro-cli chat "Use aws-compliance-checker to run CIS benchmark"
kiro-cli chat "Generate PCI-DSS report with aws-compliance-checker"
Additional Resources
Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for enprojectnment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.
echo
" ⚠️ $user: Key $key_id is $age_days days old"
fi
done
done
echo
"1.5-1.11: Checking password policy..."
if
echo
"$policy"
"NoSuchEntity"
then
echo
" ❌ No password policy configured"
else
echo
" ✓ Password policy exists"
echo
"$policy"
'.PasswordPolicy | {
MinimumPasswordLength,
RequireSymbols,
RequireNumbers,
RequireUppercaseCharacters,
RequireLowercaseCharacters,
MaxPasswordAge,
PasswordReusePrevention
}'
fi
echo
"1.12-1.14: Checking IAM user MFA..."
'NR>1 && $4=="false" {print " ⚠️ " $1 ": No MFA"}'
" ⚠️ $trail: Log validation disabled"
done
echo
"2.3: Checking CloudTrail S3 bucket access..."
'trailList[*].S3BucketName'
while
read
do
"$bucket"
"AllUsers"
if
"$public"
then
echo
" ❌ $bucket: Publicly accessible"
else
echo
" ✓ $bucket: Not public"
fi
done
echo
"2.4: Checking CloudWatch Logs integration..."
'trailList[*].[Name,CloudWatchLogsLogGroupArn]'
while
read
do
if
"$log_group"
"None"
then
echo
" ⚠️ $name: Not integrated with CloudWatch Logs"
else
echo
" ✓ $name: Integrated with CloudWatch"
fi
done
echo
"2.5: Checking AWS Config..."
'ConfigurationRecorders[*].name'
if
"$recorders"
then
echo
" ❌ AWS Config not enabled"
else
echo
" ✓ AWS Config enabled: $recorders"
fi
echo
"2.6: Checking S3 bucket logging..."
'Buckets[*].Name'
while
read
do
"$bucket"
if
echo
"$logging"
"LoggingEnabled"
then
echo
" ⚠️ $bucket: Access logging disabled"
fi
done
echo
"2.7: Checking VPC Flow Logs..."
'Vpcs[*].VpcId'
while
read
do
"Name=resource-id,Values=$vpc"
'FlowLogs[*].FlowLogId'
if
"$flow_logs"
then
echo
" ⚠️ $vpc: No flow logs enabled"
else
echo
" ✓ $vpc: Flow logs enabled"
fi
done
"$filter"
then
echo
" ✓ $filter: Configured"
else
echo
" ⚠️ $filter: Missing"
fi
done
fi
'Users'
'UserName'
if
not
'MFADevices'
f"PCI 8.3: {user['UserName']} no MFA"
'cloudtrail'
if
not
'trailList'
"PCI 10.1: No CloudTrail enabled"
return
if
"__main__"
print
"PCI-DSS Compliance Check"
print
"="
50
if
not
print
"✓ No PCI-DSS issues found"
else
print
f"Found {len(issues)} issues:\n"
for
in
print
f" ⚠️ {issue}"
echo
""
echo
"Transmission Security:"
echo
" Check: All data in transit uses TLS 1.2+"
'summary'
'passed'
'summary'
'score'
'summary'
'passed'
'summary'
'total'
100
return
def
run_cis_checks
return
def
run_pci_checks
return
def
run_hipaa_checks
return
if
"__main__"
import
1
if
len
1
else
'cis'
print
f"\n{framework.upper()} Compliance Report"
print
"="
50
print
f"Score: {report['summary']['score']:.1f}%"
print
f"Passed: {report['summary']['passed']}/{report['summary']['total']}"
print
f"Failed: {report['summary']['failed']}/{report['summary']['total']}"
with
open
f'compliance-{framework}-{datetime.now().strftime("%Y%m%d")}.json'
'w'
as
2