$npx skillfedfor your agent

cloudsplaining

AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized HTML report

Worth itPyPI SecurityReleased Jun 20264.6M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — cloudsplaining-0.9.1-py3-none-any.whl
v0.9.1 · released 2026-06-14 · Python >=3.10 · 8 runtime deps: boto3, botocore, click, click-option-group, jinja2, policy-sentry, pyyaml, schema

Yes. Cloudsplaining is actively maintained, has no known vulnerabilities, uses a permissive MIT license, and solves a concrete security problem—finding least-privilege violations in IAM policies. If you manage AWS accounts and need to audit or improve IAM security posture, this tool directly addresses that need with low install friction and clear, actionable output.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python >=3.10.
  • For account-wide scanning, AWS credentials must be configured (boto3/botocore will use standard AWS credential chain).
  • Low friction: pure Python wheel with 8 runtime dependencies (boto3, botocore, click, jinja2, policy-sentry, pyyaml, schema, click-option-group).

License · maintenance · safety

MIT (permissive) — MIT license (permissive) allows unrestricted use, modification, and distribution in both open and closed-source projects.

last release 2026-06-14 (61 days) · last repo commit 2026-08-11 · 2,243 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 4,603,019 downloads/mo, #2,276 on PyPI

Verify before relying

pip install cloudsplaining
cloudsplaining scan-policy-file --input-file policy.json
  • Whether the tool can scan multiple AWS accounts in a single run or requires separate invocations per account.
  • Performance characteristics when scanning large numbers of policies or accounts.
Same gist for agents: .md · .json

What it is and what it does

Cloudsplaining is an AWS IAM security assessment tool that identifies overly permissive IAM policies—specifically actions that lack resource constraints. It flags risky permission patterns including data exfiltration (s3:GetObject, ssm:GetParameter, secretsmanager:GetSecretValue), infrastructure modification, resource exposure, privilege escalation, and credentials exposure. The tool generates an HTML report that prioritizes findings by risk level, making it easy to identify which policies need remediation first.

You can scan a single policy file, all policies in one AWS account, or across multiple accounts. It also identifies IAM roles assumable by AWS compute services (EC2, ECS, EKS, Lambda) that may pose elevated risk if those services are internet-exposed. The tool supports custom exclusion files to filter false positives based on your organization's architecture and multi-account strategy.

Use it for

  • Audit existing IAM policies in production AWS accounts to find permissions that violate least privilege before they cause a breach.
  • Scan a policy file during infrastructure-as-code review to catch overly permissive statements before deployment.
  • Identify EC2 or Lambda roles that could be exploited if the compute service is compromised or exposed to the internet.
  • Generate a prioritized remediation backlog across dozens of AWS accounts by flagging the highest-risk policies first.
  • Detect data exfiltration vectors (unrestricted s3:GetObject, secretsmanager:GetSecretValue) in your account's role definitions.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

Cloudsplaining is actively maintained, has no known vulnerabilities, uses a permissive MIT license, and solves a concrete security problem—finding least-privilege violations in IAM policies. If you manage AWS accounts and need to audit or improve IAM security posture, this tool directly addresses that need with low install friction and clear, actionable output.

Install

cloudsplaining on PyPI

Before you install

Low friction: pure Python wheel with 8 runtime dependencies (boto3, botocore, click, jinja2, policy-sentry, pyyaml, schema, click-option-group). Actively maintained—last commit 2026-08-11, 2243 GitHub stars, no known vulnerabilities.

Requires Python >=3.10. For account-wide scanning, AWS credentials must be configured (boto3/botocore will use standard AWS credential chain).

License in practice

MIT license (permissive) allows unrestricted use, modification, and distribution in both open and closed-source projects.

Quickstart

pip install cloudsplaining
cloudsplaining scan-policy-file --input-file policy.json

Verify before relying

  • Whether the tool can scan multiple AWS accounts in a single run or requires separate invocations per account.
  • Performance characteristics when scanning large numbers of policies or accounts.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
8 packages
boto3botocoreclickclick-option-groupjinja2policy-sentrypyyamlschema
MaintenanceActively maintained 61 days since the last release
Last repo commit
First released
Downloads4,603,019 / month, #2,276 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Operating System :: OS IndependentProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Typing :: Typed

Evidence: cloudsplaining-0.9.1-py3-none-any.whl

Tags

Capabilities
AWS IAM policy security auditleast privilege violation detectionIAM privilege escalation riskAWS security assessment toolIAM policy analysis reportdata exfiltration risk finderAWS account permission audit
Topics
aws-securityiam-auditpolicy-analysis
PyPI keywords
awsiamrolespolicypoliciesprivilegessecurity

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “AWS IAM policy security audit”

  • cloudsplainingCloudsplaining scans AWS IAM policies to identify violations of least…
  • policyuniverseParses and analyzes AWS IAM and Resource Policies, extracts…
  • py-iam-expandExpands and deobfuscates AWS IAM action patterns, resolving wildcards…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also cloudsec-audit · policy-sentry · py-iam-expand · policyuniverse · aws-cdk.aws-iam · c7n-org · c7n · iamdata · awacs · pulumi-policy