A security auditing skill that identifies misconfigured S3 buckets and generates hardened policies using your exported AWS data.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install s3-exposure-auditor
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install s3-exposure-auditor using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The AWS S3 Exposure Auditor is a specialized security tool within the Openclaw Skills ecosystem designed to prevent data breaches caused by misconfigured cloud storage. It functions as an instruction-only expert that analyzes bucket permissions, ACLs, and account-level settings to uncover critical vulnerabilities. By leveraging this Openclaw Skills resource, developers and security engineers can audit their infrastructure without granting the AI direct access to their AWS account, ensuring a privacy-first security review.
This skill is particularly valuable for teams managing large-scale AWS environments where manual auditing of every bucket policy is impractical. It bridges the gap between raw AWS CLI data and actionable security intelligence by providing prioritized findings and remediation code.
To use this skill from the Openclaw Skills collection, ensure you have the AWS CLI configured with read-only permissions. You will need to run the following commands to provide the necessary data for analysis:
# List all buckets and account public access settings
aws s3api list-buckets --output json
aws s3control get-public-access-block --account-id $(aws sts get-caller-identity --query Account --output text)
# Get details for a specific bucket of concern
aws s3api get-bucket-acl --bucket YOUR_BUCKET_NAME
aws s3api get-bucket-policy --bucket YOUR_BUCKET_NAME
aws s3api get-public-access-block --bucket YOUR_BUCKET_NAME
The skill organizes its analysis based on the following data points extracted from your AWS environment:
| Data Point | Source Command | Description |
|---|---|---|
| Bucket List | list-buckets | Inventory of all S3 buckets in the account to check for scope. |
| Public Access Block | get-public-access-block | Global and local override settings that prevent public exposure. |
| Bucket ACLs | get-bucket-acl | Access control lists defining legacy permissions for users or groups. |
| Bucket Policies | get-bucket-policy | Resource-based JSON policies that define fine-grained access control. |
| Security Findings | Security Hub | (Optional) Integrated alerts for S3 resources if Security Hub is active. |
Loading
An AI-driven financial advisor that analyzes AWS usage data to recommend the most cost-effective Reserved Instance and Savings Plan strategies.

An AI-driven advisor that analyzes Azure usage data to recommend optimal Reservation and Hybrid Benefit stacking for maximum cost savings.

A specialized security analysis tool for auditing Azure Network Security Groups and Firewall policies to eliminate dangerous internet exposure.

An expert analytical framework to identify and eliminate unnecessary GCP networking and egress expenses through data-driven insights.

A specialized security analysis tool for detecting hardcoded secrets, API keys, and credential misconfigurations within Infrastructure as Code (IaC) and configuration files.

An instruction-based security auditor that analyzes AWS security group exports to identify dangerous internet exposure and provide hardened remediation rules.








































