# cloud-security-scanner

> Use this tool when you need to identify security misconfigurations in your AWS environment, such as public access, missing encryption, or weak password policies, across services like S3, IAM, EC2, and more. It provides 7 purpose-built scanners that output JSONL results, helping you solve security and compliance issues. Use its search and get tools to find and download scanners by capability, and integrate them into your workflow to ensure cloud security.

Canonical page: https://skillsregistry.net/skills/kloudle-cloud-security-scanner  
JSON: https://api.skillsregistry.net/v1/skills/kloudle-cloud-security-scanner

## Description

Cloud security scanning tools for AI agents. 7 purpose-built AWS scanners that check for misconfigurations across S3, IAM, EC2, EKS, RDS, CloudTrail, and CloudWatch Logs.          
                                                                                                                                                                                      
  Each scanner is a static ~2MB binary that outputs JSONL. Checks include public access, missing encryption, stale credentials, weak password policies, disabled logging, and more.   
                                                                                                                                                                                      
  ## Tools                                                                                                                                                                            
                                         
  - **search** — Find scanners by capability (e.g. "encryption", "public access", "iam")                                                                                              
  - **get** — Get download URL, SHA256 hash, and a ready-to-run shell command for any scanner
                                                                                                                                                                                      
  ## Scanners                    
                                                                                                                                                                                      
  | Scanner | Service | Checks |                                                                                                                                                      
  |---|---|---|                          
  | k5e-aws-s3 | S3 | encryption, public access, versioning, logging, lifecycle |                                                                                                     
  | k5e-aws-iam | IAM | root MFA, stale access keys, password policy |                                                                                                                
  | k5e-aws-ec2 | EC2 | public SSH, security groups, EBS encryption, IMDSv2 |                                                                                                         
  | k5e-aws-eks | EKS | public endpoint, logging, secrets encryption |                                                                                                                
  | k5e-aws-rds | RDS | public access, encryption, backups |                                                                                                                          
  | k5e-aws-cloudtrail | CloudTrail | multi-region, log validation, KMS encryption |                                                                                                  
  | k5e-aws-cloudwatch-logs | CloudWatch Logs | retention, encryption, metric filters |                                                                                               
                                                                                                                                                                                      
  Built by [Kloudle](https://kloudle.com).

## Trust

- **Trust score (0–1):** 0.30
- **Verification tier:** unverified
- **Last scanned:** 2026-08-30

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** cloud-infra
- **Updated:** 2026-08-30

## Source

- **Source listing:** [Smithery](https://smithery.ai/server/kloudle/cloud-security-scanner)

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "kloudle-cloud-security-scanner"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/kloudle-cloud-security-scanner` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/kloudle-cloud-security-scanner/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
