AWS S3 Exposure Auditor for Openclaw

A security auditing skill that identifies misconfigured S3 buckets and generates hardened policies using your exported AWS data.

anmolnagpal
v1.0.0
Mar 2, 2026
0
850
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install s3-exposure-auditor

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install s3-exposure-auditor using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is AWS S3 Exposure Auditor?

The AWS S3 Exposure Auditor is a specialized security tool within the Openclaw Skills ecosystem designed to prevent data breaches caused by misconfigured cloud storage. It functions as an instruction-only expert that analyzes bucket permissions, ACLs, and account-level settings to uncover critical vulnerabilities. By leveraging this Openclaw Skills resource, developers and security engineers can audit their infrastructure without granting the AI direct access to their AWS account, ensuring a privacy-first security review.

This skill is particularly valuable for teams managing large-scale AWS environments where manual auditing of every bucket policy is impractical. It bridges the gap between raw AWS CLI data and actionable security intelligence by providing prioritized findings and remediation code.

AWS S3 Exposure Auditor Use Cases

  • Identifying buckets with public read or write access via AllUsers or AuthenticatedUsers ACLs.
  • Auditing S3 bucket policies for overly permissive wildcard principals that could lead to data leaks.
  • Verifying account-level Block Public Access settings across an entire organization to ensure compliance.
  • Generating remediated, hardened bucket policies to fix security findings instantly.
  • Using heuristic analysis of bucket names to prioritize risks based on potential data sensitivity.

How AWS S3 Exposure Auditor Works

  1. The user executes specific read-only AWS CLI commands provided by the skill to gather configuration data.
  2. The user provides the JSON output of bucket lists, ACLs, and policies to the AI agent.
  3. The skill evaluates account-level and bucket-level Block Public Access configurations for any overrides.
  4. It scans for dangerous permissions such as s3:GetObject or s3:PutObject granted to the public or unauthorized principals.
  5. The skill cross-references naming conventions with security best practices to estimate the sensitivity of the exposed data.
  6. A comprehensive report is generated, including ready-to-use hardened policy JSON and long-term prevention recommendations.

AWS S3 Exposure Auditor Setup

To use this skill from the Openclaw Skills collection, ensure you have the AWS CLI configured with read-only permissions. You will need to run the following commands to provide the necessary data for analysis:

# List all buckets and account public access settings
aws s3api list-buckets --output json
aws s3control get-public-access-block --account-id $(aws sts get-caller-identity --query Account --output text)

# Get details for a specific bucket of concern
aws s3api get-bucket-acl --bucket YOUR_BUCKET_NAME
aws s3api get-bucket-policy --bucket YOUR_BUCKET_NAME
aws s3api get-public-access-block --bucket YOUR_BUCKET_NAME

AWS S3 Exposure Auditor Data Schema & Taxonomy

The skill organizes its analysis based on the following data points extracted from your AWS environment:

Data Point Source Command Description
Bucket List list-buckets Inventory of all S3 buckets in the account to check for scope.
Public Access Block get-public-access-block Global and local override settings that prevent public exposure.
Bucket ACLs get-bucket-acl Access control lists defining legacy permissions for users or groups.
Bucket Policies get-bucket-policy Resource-based JSON policies that define fine-grained access control.
Security Findings Security Hub (Optional) Integrated alerts for S3 resources if Security Hub is active.

AWS S3 Exposure Auditor Advanced Features

  • Heuristic sensitivity estimation that flags buckets containing keywords like backup, pii, or finance as high priority.
  • Automatic generation of Service Control Policies (SCPs) to enforce s3:PutBucketPublicAccessBlock across an entire AWS Organization.
  • Recommendations for specific AWS Config rules, such as s3-bucket-public-read-prohibited, to automate continuous monitoring.
  • Integrated checks for server-side encryption (SSE-KMS) and MFA Delete to protect against ransomware and accidental deletion.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*