Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add rules/jimmypocock/cursor-rules/aws-iamgit clone --depth 1 https://github.com/jimmypocock/cursor-rulesWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00005 | $0.00859 |
| Opus 5 | $0.00003 | $0.00430 |
| Sonnet 5 | $0.00001 | $0.00172 |
| Haiku 4.5 | $0.00001 | $0.00086 |
Grade A, and why
aws-iam scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 113 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Description: AWS IAM Security Best Practices Globs: /iam//.ts, /iam//.json, /cdk//.ts, /sam//.yaml, /cloudformation//*.yaml
AWS IAM Development Standards
@base.mdc @typescript.mdc
IAM Policy Design
- Apply the principle of least privilege for all IAM roles and policies
- Grant only the minimum permissions necessary for the required task
- Use specific ARNs instead of wildcards when possible
- Add conditions to further restrict access when appropriate
- Separate permissions by function or service
- Review and audit IAM policies regularly
- Use policy variables to make policies more precise
- Implement resource-based policies where applicable
IAM Role Structure
- Create purpose-specific roles for different functions
- Assign appropriate trust relationships to roles
- Set appropriate session durations for assumed roles
- Use role paths to organize roles by application or service
- Implement proper cross-account role access patterns
- Document purpose and usage of each role
- Organize roles using proper naming conventions
- Apply strict permission boundaries for delegated permissions
Lambda Function IAM Roles
- Create function-specific IAM roles
- Grant only permissions needed by the specific Lambda function
- Use resource-based conditions for additional security
- Include CloudWatch Logs permissions for proper logging
- Add X-Ray permissions if tracing is enabled
- Implement resource-level permissions when possible
- Document all permissions in comments or metadata
- Follow the same-account principle for resource access
API Gateway IAM Integration
- Use resource policies to control API access
- Implement proper IAM authentication for private APIs
- Create API-specific roles for Lambda integrations
- Separate roles for different API stages
- Include proper CloudWatch Logs permissions
- Implement custom authorizers with appropriate permissions
- Use IAM tags for access control when appropriate
- Apply API key restrictions correctly
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 113 lines · 5 tokens per session scan A 7d2686431912
aws-iam is a cursor rule published in the GitHub repository jimmypocock/cursor-rules (8 stars, last pushed 1y ago), licensed MIT. It adds 5 tokens to every session and 859 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other cursor rules, from other repositories
90-devops-deployment
Docker, CI/CD, AWS, Vercel, and VPS deployment rules.
00-global-architect
Global default behavior for the entire repository.
35-api-contracts
API versioning, contracts, and schema evolution rules.
45-environment-config
Environment configuration and secrets management rules.
50-rag-system
Retrieval-augmented generation rules.
55-data-model-versioning
Dataset versioning, model checkpoint management, and training reproducibility rules.