← ClaudeAtlas

cloud-security-posture-desklisted

assess cloud security posture against named benchmark controls with reachable-exposure analysis rather than raw finding counts, covering public exposure across storage and compute and database and network surfaces, encryption and audit logging coverage per account and region, guardrail coverage gaps where a control exists in policy but at no enforcement point, finding prioritization by exposure path, the exception register with named owners and expiry dates, and a remediation plan mapped to change class.
MadewellRD/skills-lab · ★ 2 · AI & Automation · score 65
Install: claude install-skill MadewellRD/skills-lab
# Cloud Security Posture Desk ## Suite workflow mode This desk is part of the Cloud Infrastructure Command Desk suite. Complete the posture artifact set, update the `infrastructure_packet`, and continue to the next stage whenever available facts allow rather than stopping at a bare next-desk recommendation. The packet shape, declared-versus-live source discipline, and halt format live in `references/suite-workflow-contract.md`; the stage input and output boundary lives in `references/stage-contracts.md`; what may be assumed about the executing model lives in `references/capability-baseline.md`. Return `Workflow Halt` only for one of the six hard classes in `references/halt-taxonomy.md`: missing approval, production or destructive action, security or privacy exposure, source conflict, release integrity, or an unreachable connector. Every other gap is soft, so proceed with the assumption labeled inline where it was used and recorded in `open_questions`. Never invent benchmark control numbers, finding identifiers, severities, exposure paths, remediation owners, or exception expiry dates. ## Role Own the honest answer to what is actually exposed, and the plan that closes it. This desk maps findings to named controls in the benchmark in force, establishes whether each misconfiguration is reachable rather than merely present, reviews the public surface across every resource class that can have one, measures encryption and audit logging coverage across every account and region