🔒
DevOpsTypeScript

AWS Lambda Least Privilege

by CyberStrikeus

AWS Lambda Least Privilege is a DevOps skill for Claude Code, published by CyberStrikeus in CyberStrike.

1.7K stars253 forkson CyberStrikeus/CyberStrikeAdded 2026/07/20+4% in starsRepository updated 2026/08/05
aiai-agentai-securitybug-bountycybersecuritydevsecopsethical-hackinghackinghacking-toolllmmcpmcp-servermitre-attackoffensive-securityowasppenetration-testingpentestred-teamsecuritysecurity-tools
Install in seconds
Install AWS Lambda Least Privilege
Copy AWS Lambda Least Privilege into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/CyberStrikeus/CyberStrike/tree/main/.cyberstrike/skill/CIS_benchmarks/Cloud_Providers/AWS/CIS_AWS_Compute_Services_Benchmark_v1.1.0/cis-aws-compute-12.4 ~/.claude/skills/cis-aws-compute-12.4

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/CyberStrikeus/CyberStrike.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
.cyberstrike/skill/CIS_benchmarks/Cloud_Providers/AWS/CIS_AWS_Compute_Services_Benchmark_v1.1.0/cis-aws-compute-12.4/SKILL.md in CyberStrikeus/CyberStrike
Installs to
~/.claude/skills/cis-aws-compute-12.4
Collection
One of 51 skills cataloged from this repository
Category
DevOps1075 skills

What AWS Lambda Least Privilege does

Audits and enforces least-privilege IAM permissions for AWS Lambda functions, ensuring each function has only the minimal required access, in line with CIS benchmarks.

AWS Lambda Least Privilege is cataloged under DevOps on DirSkills. AWS Lambda Least Privilege comes from a repository tagged ai, ai-agent, ai-security, bug-bounty and cybersecurity.

Documentation

README

Ensure least privilege is used with Lambda function access

Description

Lambda is fully integrated with IAM, allowing you to control precisely what each Lambda function can do within the AWS Cloud. As you develop a Lambda function, you expand the scope of this policy to enable access to other resources. For example, for a function that processes objects put into an S3 bucket, it requires read access to objects stored in that bucket. Do not grant the function broader permissions to write or delete data, or operate in other buckets.

Rationale

This is the opening of the README. Read the full README on GitHub.

Frequently asked about AWS Lambda Least Privilege

  • What else does CyberStrikeus publish alongside AWS Lambda Least Privilege?

    AWS Lambda Least Privilege is one of 51 skills that DirSkills catalogs from CyberStrikeus/CyberStrike, the repository it ships in. Its siblings there include AMI Age Compliance, AMI Encryption Check and AMI Naming Convention Compliance. Each one is a separate skill with its own page in this directory, installs the same way AWS Lambda Least Privilege does, and is maintained by CyberStrikeus in that same repository. The rest of the collection is listed on the CyberStrikeus/CyberStrike page.

  • How does AWS Lambda Least Privilege compare to other DevOps skills?

    AWS Lambda Least Privilege ranks #315 by stars among the 1075 DevOps skills in this catalog. The most-starred ones next to it are Backend Patterns, API Connector Builder and Migration. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of AWS Lambda Least Privilege against them. Open each page to compare what they document and how they install.

More from CyberStrikeus/CyberStrike

AWS Lambda Least Privilege is one of 51 skills cataloged on DirSkills from CyberStrikeus/CyberStrike.

See all 51 skills