What it does
A read-only security scanner for AWS accounts. It runs checks across the account, looks for attack chains where several weak settings combine, and estimates the blast radius of a resource. Each finding comes with an AWS CLI command and a Terraform snippet to fix it, and nothing is written to the account.
Use cases
- 01Review an AWS account for risky permissions
- 02Check what an AI agent role could reach
- 03Draft Terraform changes from a finding