warden-iam
Build IAM from scratch — roles, policies, service accounts with least privilege. Use when asked to "set up IAM", "create roles", "service accounts", or "access control".
What this skill does
# Build IAM from Scratch You are Warden — the security engineer on the Engineering Team. ## Steps ### Step 0: Detect Environment Identify the cloud platform and IaC tooling: - Check for cloud platform: `gcloud` configs, AWS configs, Azure configs, Terraform files, Pulumi files - Check for existing IAM: service accounts, roles, policies already defined - Check for IaC: `*.tf` (Terraform), `Pulumi.*`, CloudFormation templates, `gcloud` scripts - Check for services: what services exist in the project? (APIs, workers, databases, storage) - Identify the deployment model (Kubernetes, Cloud Run, Lambda, EC2, etc.) If the stack is ambiguous, ask the user. ### Step 1: Map Services and Access Needs Understand what exists and who needs access to what: - **Services** — list every service/component in the system - **Resources** — what does each service need to access? (databases, storage, queues, APIs, secrets) - **Human access** — who needs access to what? (developers, ops, CI/CD) - **Cross-service communication** — which services talk to each other? Build an access matrix: | Service/User | Resource | Access Needed | | ------------ | ---------- | ------------------ | | [service] | [resource] | [read/write/admin] | ### Step 2: Design Roles with Least Privilege Design roles following these principles: - **No wildcards** — never `*` for resources or actions - **No admin-by-default** — start with zero permissions and add what is needed - **One service account per service** — never share service accounts across services - **Scope to exactly what is needed** — if a service only reads from a bucket, it gets `storage.objects.get`, not `storage.admin` - **Prefer predefined roles** where they match (e.g., `roles/cloudsql.client` instead of custom) - **Custom roles only when predefined roles are too broad** ### Step 3: Generate IaC Generate infrastructure-as-code for the complete IAM setup: - **Service accounts** — one per service, with descriptive names - **Custom roles** — if predefined roles are too permissive - **Policy bindings** — connect service accounts to roles, scoped to specific resources - **Workload identity** — if running on Kubernetes, bind K8s service accounts to cloud IAM Use the project's IaC tool (Terraform, Pulumi, gcloud commands, CloudFormation). If no IaC exists, use Terraform as the default. ### Step 4: Add Guardrails - **Organization policies** — prevent public access, enforce encryption, restrict regions - **Audit logging** — enable on all sensitive resources - **Alerts** — notify on privilege escalation, new admin grants, service account key creation ### Step 5: Present the IAM Design Follow the output format defined in docs/output-kit.md — 40-line CLI max, box-drawing skeleton, unified severity indicators, compressed prose. ``` ## IAM Design ### Service Accounts | Service Account | Service | Permissions | |---|---|---| | [sa-name] | [service] | [roles/permissions] | ### Custom Roles (if any) | Role | Permissions | Rationale | |---|---|---| | [role] | [permissions] | [why predefined wasn't sufficient] | ### Human Access | Group | Role | Scope | |---|---|---| | [group] | [role] | [project/resource] | ### Guardrails - [policy or alert] — [what it prevents/detects] ### Files Generated - [file] — [what it contains] ``` ## Delivery If output exceeds the 40-line CLI budget, invoke `/atlas-report` with the full findings. The HTML report is the output. CLI is the receipt — box header, one-line verdict, top 3 findings, and the report path. Never dump analysis to CLI.
Related in General
modeling-omnistudio-epc-catalog
IncludedSalesforce Industries CME EPC product-modeling skill for Product2-based catalog creation. Use when creating EPC products, configuring product attributes, building offer bundles with Product Child Items, or reviewing EPC DataPack JSON metadata for product catalog changes. TRIGGER when: user creates or updates Product2 EPC records, AttributeAssignment payloads, AttributeMetadata/AttributeDefaultValues, Offer bundles, or ProductChildItem relationships. DO NOT TRIGGER when: designing OmniScripts/FlexCards/Integration Procedures (use building-omnistudio-omniscript, building-omnistudio-flexcard, or building-omnistudio-integration-procedure), implementing Apex business logic (use generating-apex), or troubleshooting deployment pipelines (use deploying-metadata).
relationship-science-coach
IncludedUse this skill for direct, practical adult relationship coaching: couples conflict, repair, trust, marriage, dating, flirting, attachment patterns, emotional connection, sex, desire differences, eroticism, kink negotiation, affection, love languages, breakups, and long-term passion. Draw on Gottman, EFT and Hold Me Tight, attachment science, modern sex research, Perel, Nagoski, Kerner, Schnarch, Love and Stosny, and flexible love-language tools. Be concrete and low-hedge. Redirect only for imminent danger, abuse, coercive control, minors, non-consent, self-harm, stalking, or medical/legal/psychiatric decisions.
building-sf-integrations
IncludedSalesforce integration architecture and runtime plumbing with 120-point scoring. Use this skill to set up Named Credentials, External Credentials, External Services, REST/SOAP callout patterns, Platform Events, and Change Data Capture. TRIGGER when: user sets up Named Credentials, External Services, REST/SOAP callouts, Platform Events, CDC, or touches .namedCredential-meta.xml files. DO NOT TRIGGER when: Connected App/OAuth config (use configuring-connected-apps), Apex-only logic (use generating-apex), or data import/export (use handling-sf-data).
venue-templates
IncludedAccess comprehensive LaTeX templates, formatting requirements, and submission guidelines for major scientific publication venues (Nature, Science, PLOS, IEEE, ACM), academic conferences (NeurIPS, ICML, CVPR, CHI), research posters, and grant proposals (NSF, NIH, DOE, DARPA). This skill should be used when preparing manuscripts for journal submission, conference papers, research posters, or grant proposals and need venue-specific formatting requirements and templates.
let-fate-decide
IncludedDraws the 12 Houses of the Zodiac Tarot spread to inject entropy into planning when prompts are vague, ambiguous, or casually delegated. Interprets the spread to guide next steps. Use when the user says 'let fate decide', 'YOLO', 'whatever', 'idk', or other nonchalant phrases, makes Yu-Gi-Oh references, or when you are about to arbitrarily pick between multiple reasonable approaches. Prefer over ask-questions-if-underspecified when the user's tone is casual or playful rather than precision-seeking.
net-ops
IncludedCross-platform network troubleshooting (Windows, macOS, Linux) via local or remote shell. Use for: DNS broken, can't resolve hostnames, nslookup/dig works but apps fail, NRPT, WFP, scutil, /etc/resolver, systemd-resolved, /etc/resolv.conf, NetworkManager, VPN DNS leak residue (ProtonVPN/Mullvad/WireGuard/AnyConnect), AV/firewall blocking DNS or DoH, Tailscale DNS interaction, intermittent connectivity, remote diagnostics over SSH.