$npx skillfedfor your agent

policy-sentry

Generate locked-down AWS IAM Policies

Worth itPyPI SecurityReleased Apr 20264.6M downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — policy_sentry-0.15.2-py3-none-any.whl
v0.15.2 · released 2026-04-14 · Python >=3.10 · 6 runtime deps: beautifulsoup4, click, orjson, pyyaml, requests, schema

Yes. Policy Sentry is actively maintained, has no known vulnerabilities, low install friction, and solves a real security problem—automating least-privilege IAM policy generation. It's appropriate for teams that want to enforce security best practices without manual AWS documentation review. The MIT license and broad Python version support (3.10–3.14) make it suitable for most environments.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later; AWS IAM knowledge helpful but the tool abstracts most complexity.
  • Low install friction with a pure Python wheel and six common dependencies.
  • The package is actively maintained with recent releases, supports current Python versions (3.10–3.14), and has been in development since 2019 with steady community engagement.

License · maintenance · safety

MIT (permissive) — MIT license permits unrestricted use, modification, and distribution with minimal restrictions—suitable for both open-source and commercial projects.

last release 2026-04-14 (122 days) · last repo commit 2026-08-09 · 2,166 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 4,637,897 downloads/mo, #2,267 on PyPI

Verify before relying

pip install policy_sentry

# Create a CRUD template
policy_sentry create-template --output-file crud.yml --template-type crud

# Edit crud.yml with your ARNs, then generate policy
policy_sentry write-policy --input-file crud.yml
  • Whether the embedded AWS IAM action database is kept current with new AWS services and actions.
  • Performance characteristics when processing large numbers of ARNs or complex access-level combinations.
  • Integration points with existing IaC workflows (Terraform, CloudFormation) beyond what the description mentions.
Same gist for agents: .md · .json

What it is and what it does

Policy Sentry is a command-line tool and Python library that generates AWS IAM policies by mapping resource ARNs and access levels (Read, Write, List, Tagging, Permissions Management) to the specific IAM actions that support them. Instead of manually reviewing AWS documentation and writing policy JSON, you describe what resources you need access to and at what level, and the tool outputs a complete, least-privilege policy statement. It maintains an internal database of AWS actions, their access levels, and supported resource types, then queries that database to produce policies scoped to exactly what you specify.

The tool is designed for infrastructure-as-code developers and security teams who want to enforce least-privilege principles without the tedium of hand-crafting policies. It supports both CLI workflows (create templates, fill in ARNs, generate policies) and Python library usage for programmatic policy generation. The package depends on click for CLI handling, beautifulsoup4 and requests for fetching AWS documentation, orjson for fast JSON serialization, pyyaml for template parsing, and schema for validation.

Use it for

  • Generate least-privilege IAM policies for Lambda functions, EC2 roles, or service accounts by specifying only the resources and access levels needed.
  • Automate policy creation in CI/CD pipelines to enforce security standards without manual policy review bottlenecks.
  • Create CRUD-based policy templates for teams unfamiliar with AWS IAM action names and resource constraints.
  • Reduce policy blast radius in breach scenarios by ensuring roles have only the minimum permissions required.
  • Validate or regenerate existing IAM policies to ensure they follow least-privilege principles.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

Policy Sentry is actively maintained, has no known vulnerabilities, low install friction, and solves a real security problem—automating least-privilege IAM policy generation. It's appropriate for teams that want to enforce security best practices without manual AWS documentation review. The MIT license and broad Python version support (3.10–3.14) make it suitable for most environments.

Install

policy-sentry on PyPI

Before you install

Low install friction with a pure Python wheel and six common dependencies. The package is actively maintained with recent releases, supports current Python versions (3.10–3.14), and has been in development since 2019 with steady community engagement.

Requires Python 3.10 or later; AWS IAM knowledge helpful but the tool abstracts most complexity.

License in practice

MIT license permits unrestricted use, modification, and distribution with minimal restrictions—suitable for both open-source and commercial projects.

Quickstart

pip install policy_sentry

# Create a CRUD template
policy_sentry create-template --output-file crud.yml --template-type crud

# Edit crud.yml with your ARNs, then generate policy
policy_sentry write-policy --input-file crud.yml

Verify before relying

  • Whether the embedded AWS IAM action database is kept current with new AWS services and actions.
  • Performance characteristics when processing large numbers of ARNs or complex access-level combinations.
  • Integration points with existing IaC workflows (Terraform, CloudFormation) beyond what the description mentions.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
6 packages
beautifulsoup4clickorjsonpyyamlrequestsschema
MaintenanceActively maintained 122 days since the last release
Last repo commit
First released
Downloads4,637,897 / month, #2,267 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Operating System :: OS IndependentProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Typing :: Typed

Evidence: policy_sentry-0.15.2-py3-none-any.whl

Tags

Capabilities
aws iam policy generatorleast privilege iam automationiam policy from arnaws access control generatoriam crud policy builderaws security policy automationiam policy template generator
Topics
aws-iampolicy-generationsecurity-automation
PyPI keywords
awsiampoliciespolicyprivilegesrolessecurity

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “aws iam policy generator”

  • policy-sentryPolicy Sentry generates least-privilege AWS IAM policies from…
  • awacsawacs generates AWS IAM policy JSON from Python code, with built-in…
  • cdk-iam-floydGenerates AWS IAM policy statements with a fluent interface,…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also awacs · cloudsplaining · policyuniverse · aws-cdk.aws-iam · py-iam-expand · kappa · cedarpy · sentry-cli · aws-cdk.aws-secretsmanager · arn