AWS CDK Analyzer for Openclaw

A comprehensive auditing tool for AWS CDK applications that ensures security compliance, cost efficiency, and deployment safety.

charlie-morrison
v1.0.1
May 1, 2026
0
734
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install aws-cdk-analyzer

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install aws-cdk-analyzer using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is AWS CDK Analyzer?

The AWS CDK Analyzer is a specialized tool designed for developers and DevOps engineers who want to maintain high-quality Infrastructure as Code (IaC). By leveraging Openclaw Skills, this analyzer performs deep inspection of CDK construct patterns, IAM policies, and resource configurations. It helps teams transition from raw code to production-ready infrastructure by identifying vulnerabilities and optimization opportunities before they reach the cloud.

This skill goes beyond simple linting by synthesizing CloudFormation output and verifying the logical integrity of your stacks. Whether you are performing a routine audit or preparing for a major production deployment, using Openclaw Skills like this analyzer ensures your AWS environment remains secure, cost-effective, and compliant with industry standards.

AWS CDK Analyzer Use Cases

  • Reviewing IAM policies to enforce the principle of least privilege.
  • Preparing for production deployments by verifying stack safety and rollback configurations.
  • Auditing existing infrastructure for cost-saving opportunities like right-sizing instances.
  • Identifying security vulnerabilities such as public S3 buckets or hardcoded secrets.
  • Migrating CDK projects from v1 to v2 or updating construct libraries.

How AWS CDK Analyzer Works

  1. Project Discovery: The skill maps the application structure, identifying the CDK version, language, stack definitions, and construct files.
  2. Security Audit: It analyzes IAM policies for wildcards, checks network ingress rules, and verifies data protection settings like encryption and logging.
  3. Cost Analysis: The analyzer scans for oversized resources, missing auto-scaling, and expensive architectural choices like unnecessary NAT Gateways.
  4. Best Practice Validation: It checks for the use of L2/L3 constructs over L1, proper removal policies, and clean code standards.
  5. Synthesis & Verification: The skill runs a cdk synth to inspect the final CloudFormation templates for sensitive data leakage.
  6. Report Generation: A detailed breakdown of critical issues, warnings, and cost optimization recommendations is provided.

AWS CDK Analyzer Setup

To start using this analyzer within the Openclaw Skills ecosystem, ensure you have the AWS CDK CLI installed and your environment authenticated. Run the following in your project root:

# Install CDK dependencies if not present
npm install

# Ensure you are authenticated with AWS
aws sts get-caller-identity

# Invoke the analyzer via your AI agent
# "Analyze my CDK app for security issues"

AWS CDK Analyzer Data Schema & Taxonomy

The skill organizes its findings into a structured report categorized by severity and impact. Key data points include:

Data Category Details Included
Critical Issues Security holes, hardcoded secrets, and data loss risks (with file paths).
Warnings Best practice deviations and non-breaking configuration errors.
Cost Table Comparison of current vs. optimized resource costs and estimated monthly savings.
Project Metadata Detected CDK version, total stack count, and resource inventory.

AWS CDK Analyzer Advanced Features

  • Multi-stack dependency mapping to identify complex cross-stack reference issues.
  • Automated drift detection using cdk diff to compare local code against deployed infrastructure.
  • Secret leakage scanning within synthesized CloudFormation templates.
  • Aspect-oriented analysis for cross-cutting concerns across all constructs in an application.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*