用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/andrewyng/openworker --skill aws-posture命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
| name | aws-posture |
| description | Read-only AWS posture check — public exposure, IAM blast radius, hygiene |
Check the live AWS account's security posture using strictly read-only CLI calls, then fix root causes in the IaC.
HARD RULE: read-only means read-only — describe/list/get/simulate calls only. No
create/put/update/delete/attach, no terraform apply, ever. If a fix is needed, it goes
into Terraform for the team to apply.
aws sts get-caller-identity (mask the account id to its
last 4 digits in anything you write). Ask which regions matter; default to the ones
the Terraform state uses.get-public-access-block, bucket policies),
security groups open to 0.0.0.0/0 on sensitive ports, public RDS/ES endpoints,
ALB listeners without TLS.Action/Resource
in customer-managed policies, stale access keys (iam get-credential-report),
roles with overly broad trust policies.基于 SOC 职业分类