
from agent-toolkit-for-aws130
Verified corrections and edge-case guidance for IAM, STS, Organizations, SAML, and policy evaluation to avoid common authorization mistakes.
This skill provides concise, verified corrections and edge-case rules for AWS Identity and Access Management (IAM) and related services (STS, Organizations, SAML). It distills gotchas — policy evaluation pitfalls, service-specific trust policy quirks, MFA and SigV4 nuances, and role/pass-role escalation patterns — so agents answer authorization questions more accurately.
Use this skill when an agent must: audit or explain IAM policies, diagnose cross-account AssumeRole behavior, reason about STS session limits, construct or validate SAML/OIDC trust relationships, or assess privilege escalation risks involving iam:PassRole. Prefer it as a fact-checking layer alongside official AWS docs.
Likely useful to agents with AWS SDK and shell access: Copilot/Code assistants, CLI-based agents, and automation bots that can fetch AWS docs.
This skill has not been reviewed by our automated audit pipeline yet.