{"enrichment":{"faq":[{"a":"Securing S3 buckets involves layered controls: enable versioning and MFA Delete, enforce encryption (S3-managed or KMS), block all public access via bucket settings, implement HTTPS-only policies, enable logging to CloudTrail and S3 access logs, and configure attribute-based access control (ABAC). This skill walks through each step aligned with AWS Well-Architected principles to protect data at rest and in transit.","q":"How to secure S3 bucket following AWS best practices?"},{"a":"Securing S3 buckets requires reviewing: encryption status (default or KMS), public access block settings, bucket policies restricting to HTTPS, versioning and MFA Delete enablement, logging destinations, and IAM/resource-based permissions. This skill provides a checklist to identify misconfigurations, verify compliance requirements, and spot gaps in monitoring or access controls.","q":"What are the key steps to audit S3 bucket configuration?"},{"a":"Securing S3 buckets includes enabling default encryption (S3-managed or KMS), configuring S3 access logging to a separate bucket, enabling CloudTrail for API auditing, and optionally setting up CloudWatch alarms. This skill guides you through each configuration, ensuring encrypted data at rest, audit trails for access, and visibility into bucket operations.","q":"How do I enable encryption and monitoring on S3 buckets?"},{"a":"Securing S3 buckets after finding issues means: blocking public access, adding bucket policies to deny insecure transport, enabling versioning and MFA Delete, applying encryption defaults, and updating IAM roles to follow least-privilege principles. This skill provides step-by-step remediation workflows to close gaps identified in audits or security assessments.","q":"How can I remediate S3 security findings and misconfigurations?"},{"a":"Securing S3 buckets with HTTPS-only access means adding a deny policy for requests using insecure transport (aws:SecureTransport = false). This skill shows how to craft and apply bucket policies that reject HTTP connections, ensuring all data in transit is encrypted and meeting compliance requirements for secure communication.","q":"What is S3 bucket policy HTTPS only and how do I enforce it?"},{"a":"Securing S3 buckets with ABAC lets you grant permissions based on tags (environment, team, cost-center) rather than individual identities. This skill demonstrates how to tag resources, define IAM policies using tag conditions, and scale access management across teams while maintaining least-privilege security posture.","q":"How does securing S3 buckets include attribute-based access control?"}],"shadow_tags":["aws-s3-security","encryption-management","compliance-auditing","access-control-policies","misconfiguration-remediation","monitoring-and-logging","infrastructure-hardening","identity-and-access"],"summary_rewrite":"This skill guides you through five core workflows: securing new buckets, auditing existing configurations, remediating findings, configuring encryption, and enabling monitoring. It enforces layered security controls aligned with AWS Well-Architected principles, including versioning, encryption defaults, HTTPS-only policies, and attribute-based access control."},"files":[{"bytes":7852,"path":"skills/specialized-skills/storage-skills/securing-s3-buckets/SKILL.md","sha256":"79a304b00d956dbc2833a53e23b0bd8bd53492cd255e29ee2069679c4f0bdfbd","url":"https://skillfed.io/files/aws/agent-toolkit-for-aws/securing-s3-buckets/d17b6187/SKILL.md"}],"id":"aws/agent-toolkit-for-aws/securing-s3-buckets","links":{"html":"https://skillfed.io/aws/agent-toolkit-for-aws/securing-s3-buckets","md":"https://skillfed.io/aws/agent-toolkit-for-aws/securing-s3-buckets.md","repo":"https://github.com/aws/agent-toolkit-for-aws"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":202,"language":"Python","last_updated":"2026-07-27","license":"Apache-2.0","name":"securing-s3-buckets","publisher":"aws","stars":2148},"relations":{"similar":[{"id":"BagelHole/DevOps-Security-Agent-Skills/aws-s3"},{"id":"itsmostafa/aws-agent-skills/s3"},{"id":"BagelHole/DevOps-Security-Agent-Skills/object-storage"},{"id":"personamanagmentlayer/pcl/aws-expert"},{"id":"BagelHole/DevOps-Security-Agent-Skills/aws-cloudtrail"},{"id":"secondsky/claude-skills/cloudflare-r2"},{"id":"giuseppe-trisciuoglio/developer-kit/aws-cloudformation-s3"},{"id":"aj-geddes/useful-ai-prompts/aws-s3-management"},{"id":"aws/agent-toolkit-for-aws/exporting-rds-to-s3"},{"id":"aws/agent-toolkit-for-aws/querying-aws-s3"}]},"slug":{"owner":"aws","repo":"agent-toolkit-for-aws","skill":"securing-s3-buckets"},"version":"d17b6187"}
