cloudsplaining
AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized HTML report
Decision gist · record as of 2026-08-14
Yes. Cloudsplaining is actively maintained, has no known vulnerabilities, uses a permissive MIT license, and solves a concrete security problem—finding least-privilege violations in IAM policies. If you manage AWS accounts and need to audit or improve IAM security posture, this tool directly addresses that need with low install friction and clear, actionable output.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python >=3.10.
- For account-wide scanning, AWS credentials must be configured (boto3/botocore will use standard AWS credential chain).
- Low friction: pure Python wheel with 8 runtime dependencies (boto3, botocore, click, jinja2, policy-sentry, pyyaml, schema, click-option-group).
License · maintenance · safety
MIT (permissive) — MIT license (permissive) allows unrestricted use, modification, and distribution in both open and closed-source projects.
last release 2026-06-14 (61 days) · last repo commit 2026-08-11 · 2,243 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 4,603,019 downloads/mo, #2,276 on PyPI
Alternatives
Verify before relying
pip install cloudsplaining
cloudsplaining scan-policy-file --input-file policy.json- Whether the tool can scan multiple AWS accounts in a single run or requires separate invocations per account.
- Performance characteristics when scanning large numbers of policies or accounts.
What it is and what it does
Cloudsplaining is an AWS IAM security assessment tool that identifies overly permissive IAM policies—specifically actions that lack resource constraints. It flags risky permission patterns including data exfiltration (s3:GetObject, ssm:GetParameter, secretsmanager:GetSecretValue), infrastructure modification, resource exposure, privilege escalation, and credentials exposure. The tool generates an HTML report that prioritizes findings by risk level, making it easy to identify which policies need remediation first.
You can scan a single policy file, all policies in one AWS account, or across multiple accounts. It also identifies IAM roles assumable by AWS compute services (EC2, ECS, EKS, Lambda) that may pose elevated risk if those services are internet-exposed. The tool supports custom exclusion files to filter false positives based on your organization's architecture and multi-account strategy.
Use it for
- Audit existing IAM policies in production AWS accounts to find permissions that violate least privilege before they cause a breach.
- Scan a policy file during infrastructure-as-code review to catch overly permissive statements before deployment.
- Identify EC2 or Lambda roles that could be exploited if the compute service is compromised or exposed to the internet.
- Generate a prioritized remediation backlog across dozens of AWS accounts by flagging the highest-risk policies first.
- Detect data exfiltration vectors (unrestricted s3:GetObject, secretsmanager:GetSecretValue) in your account's role definitions.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Cloudsplaining is actively maintained, has no known vulnerabilities, uses a permissive MIT license, and solves a concrete security problem—finding least-privilege violations in IAM policies. If you manage AWS accounts and need to audit or improve IAM security posture, this tool directly addresses that need with low install friction and clear, actionable output.
Install
cloudsplaining on PyPI
Before you install
Low friction: pure Python wheel with 8 runtime dependencies (boto3, botocore, click, jinja2, policy-sentry, pyyaml, schema, click-option-group). Actively maintained—last commit 2026-08-11, 2243 GitHub stars, no known vulnerabilities.
Requires Python >=3.10. For account-wide scanning, AWS credentials must be configured (boto3/botocore will use standard AWS credential chain).
License in practice
MIT license (permissive) allows unrestricted use, modification, and distribution in both open and closed-source projects.
Quickstart
pip install cloudsplaining
cloudsplaining scan-policy-file --input-file policy.json
Verify before relying
- Whether the tool can scan multiple AWS accounts in a single run or requires separate invocations per account.
- Performance characteristics when scanning large numbers of policies or accounts.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 8 packagesboto3botocoreclickclick-option-groupjinja2policy-sentrypyyamlschema |
| Maintenance | Actively maintained 61 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 4,603,019 / month, #2,276 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Operating System :: OS IndependentProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Typing :: Typed |
Evidence: cloudsplaining-0.9.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “AWS IAM policy security audit”
- cloudsplainingCloudsplaining scans AWS IAM policies to identify violations of least…
- policyuniverseParses and analyzes AWS IAM and Resource Policies, extracts…
- py-iam-expandExpands and deobfuscates AWS IAM action patterns, resolving wildcards…
Give your agent the search over MCP, or paste the wish link into any chat.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also cloudsec-audit · policy-sentry · py-iam-expand · policyuniverse · aws-cdk.aws-iam · c7n-org · c7n · iamdata · awacs · pulumi-policy