{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security"}],"enrichment":{"capability":"Cloudsplaining scans AWS IAM policies to identify violations of least privilege and generates a risk-prioritized HTML report highlighting dangerous permissions without resource constraints.","skillfed_tags":["aws-security","iam-audit","policy-analysis"],"use_cases":["Audit existing IAM policies in production AWS accounts to find permissions that violate least privilege before they cause a breach.","Scan a policy file during infrastructure-as-code review to catch overly permissive statements before deployment.","Identify EC2 or Lambda roles that could be exploited if the compute service is compromised or exposed to the internet.","Generate a prioritized remediation backlog across dozens of AWS accounts by flagging the highest-risk policies first.","Detect data exfiltration vectors (unrestricted s3:GetObject, secretsmanager:GetSecretValue) in your account's role definitions."],"what_it_does":"Cloudsplaining is an AWS IAM security assessment tool that identifies overly permissive IAM policies\u2014specifically actions that lack resource constraints. It flags risky permission patterns including data exfiltration (s3:GetObject, ssm:GetParameter, secretsmanager:GetSecretValue), infrastructure modification, resource exposure, privilege escalation, and credentials exposure. The tool generates an HTML report that prioritizes findings by risk level, making it easy to identify which policies need remediation first.\n\nYou can scan a single policy file, all policies in one AWS account, or across multiple accounts. It also identifies IAM roles assumable by AWS compute services (EC2, ECS, EKS, Lambda) that may pose elevated risk if those services are internet-exposed. The tool supports custom exclusion files to filter false positives based on your organization's architecture and multi-account strategy.","worth_installing":"Yes. Cloudsplaining is actively maintained, has no known vulnerabilities, uses a permissive MIT license, and solves a concrete security problem\u2014finding least-privilege violations in IAM policies. If you manage AWS accounts and need to audit or improve IAM security posture, this tool directly addresses that need with low install friction and clear, actionable output."},"id":"cloudsplaining","links":{"html":"https://skillfed.io/packages/cloudsplaining","md":"https://skillfed.io/packages/cloudsplaining.md","pypi":"https://pypi.org/project/cloudsplaining/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-06-14","license_spdx":"MIT","license_treatment":"permissive","name":"cloudsplaining","python_support":"supports_current","summary":"AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized HTML report"},"popularity":{"monthly_downloads":4603019,"position":2276,"tier":"top_5000"},"security":{"n_vulnerabilities":0},"version":"0.9.1"}
