s3-estate-calibration-auditor
anyshift-io/sre-skillsAudit an estate of AWS S3 buckets for the one bucket that is genuinely publicly or cross-account exposed, without over-flagging the many buckets that READ as…
Scores out of 100 · grade B+
2026-08-15Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score100/100
- no commits in the last 12 weeks
Adopted
20% of the score17/100
- 17 stars on the source repo.
Documented
15% of the score83/100
- 3,266 words with worked examples.
- Ships 19 bundled files.
Install
npx skills add anyshift-io/sre-skills/s3-estate-calibration-auditorWhat it says it does
Audit an estate of AWS S3 buckets for the one bucket that is genuinely publicly or cross-account exposed, without over-flagging the many buckets that READ as exposed but are neutralised. Resolves each bucket's EFFECTIVE verdict by composing four layers (Block Public Access x bucket policy x bucket ACL x access points), never one layer alone, then rolls the per-bucket verdicts up into an estate verdict. Its discipline is symmetric: BPA (RestrictPublicBuckets / BlockPublicPolicy) neutralises a Principal '*' policy but NOT a cross-account grant; IgnorePublicAcls kills a public-group ACL grant but NOT a cross-account canonical-user grant; a narrowing Condition (org id, ExternalId, SourceIp, access-point delegation) scopes a Principal '*' so it is not public. On a needle estate it names the ONE live bucket as the primary finding; on a clean estate it reports NO live exposure and does not manufacture findings. Then it states what the bucket configs alone cannot answer (per-object ACLs, CloudFront/CDN fronting, the trusted principals' identity policies, account-level BPA dependency, data sensitivity). Use when asked to review an S3 bucket fleet for public exposure, cross-account access, or whether the estate is clean. Vendor-neutral; runs offline against describe-bucket / get-bucket-policy / get-bucket-acl / list-access-points JSON with no Anyshift account.
Also in anyshift-io/sre-skills
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| iam-deceptive-escalation-auditoranyshift-io/sre-skills | clean | Skill | 17 stars | today | |
| kubectl-investigatoranyshift-io/sre-skills | clean | Skill | 17 stars | today | |
| sg-deceptive-reachability-auditoranyshift-io/sre-skills | clean | Skill | 17 stars | today | |
| sqs-queue-auditoranyshift-io/sre-skills | clean | Skill | 17 stars | today | |
| sre-skillsanyshift-io/sre-skills | No version | Plugin | 17 stars | today |
Other ai & agents skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| mcp-builderanthropics/skills | No license | AI & agents | 104,949 installs | today | |
| agent-developmentanthropics/claude-plugins-official | clean | AI & agents | 5,901 installs | today | |
| plugin-settingsanthropics/claude-plugins-official | clean | AI & agents | 5,465 installs | today | |
| skill-creatoranthropics/claude-plugins-official | clean | AI & agents | 5,836 installs | today | |
| microsoft-foundrymicrosoft/azure-skills | clean | AI & agents | 544,819 installs | today | |
| claude-apianthropics/skills | No license | AI & agents | 59,236 installs | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=anyshift-io%2Fsre-skills)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
