Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add EvilFreelancer/secs --skill investigating-aws-incidentsgit clone --depth 1 https://github.com/EvilFreelancer/secsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/evilfreelancer/secs/investigating-aws-incidents)<a href="https://agentmods.dev/skills/evilfreelancer/secs/investigating-aws-incidents"><img src="https://agentmods.dev/badge/skills/evilfreelancer/secs/investigating-aws-incidents/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/evilfreelancer/secs/investigating-aws-incidents"><img src="https://agentmods.dev/badge/skills/evilfreelancer/secs/investigating-aws-incidents.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00101 | $0.01538 |
| Opus 5 | $0.00051 | $0.00769 |
| Sonnet 5 | $0.00020 | $0.00308 |
| Haiku 4.5 | $0.00010 | $0.00154 |
Grade A, and why
investigating-aws-incidents scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 114 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Investigating AWS Incidents
In AWS the crime scene is the API log, not the disk. Almost every action — assuming a role, minting an access key, reading a bucket, turning off the trail — is a CloudTrail event with an identity, a source IP, a user agent, and a timestamp. The investigator reconstructs the intrusion from that record. The urgency is that the record is itself a target: an attacker who reaches the logging configuration can stop the trail or shorten retention, so preservation comes before analysis.
Confirm the account is in scope per AGENTS.md, and treat findings as sensitive cloud data kept in the engagement store. This skill is read-only investigation; containment actions (revoking keys, isolating a role) are the operator's call and belong to the wider incident.
When to Use
- A suspected AWS compromise where the evidence is control-plane logs
- Tracing IAM/STS abuse: AssumeRole chains, new users/keys, console logins
- Confirming data access or exfiltration from S3 and other services
- Finding cloud persistence (new principals, trust-policy edits) and log tampering
- Building an AWS attack timeline for an incident
When NOT to Use
- On-host artifacts of an EC2 instance — use
investigating-windows-endpoints(or acquire the disk/memory); this skill is the control plane - Azure or GCP — use
investigating-azure-incidentsorinvestigating-gcp-incidents - Proactive search with no incident yet — use
hunting-threats - Offensive cloud testing — use
exploiting-cloud-platforms - Proactive hardening — use
hardening-cloud-posture - Running the whole incident — use
responding-to-incidents - Packaging IOCs into a product — use
producing-threat-intelligence
Preserve First
Copy the relevant CloudTrail logs out of the account (or into a
forensics/logging account) and snapshot affected EBS volumes before anything can
be altered. Confirm whether CloudTrail log-file validation is on. If a
StopLogging or DeleteTrail appears in the timeline, note the gap it created —
absence of events after that point is evidence, not all-clear.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 114 lines · 101 tokens per session scan A b18adde550bc
investigating-aws-incidents is a skill published in the GitHub repository EvilFreelancer/secs (10 stars, last pushed 1mo ago), licensed Apache-2.0. It adds 101 tokens to every session and 1,538 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
auditing-gcp-iam-permissions
Auditing Google Cloud Platform IAM permissions to identify overly permissive bindings, primitive role usage, service account key proliferation, and cross-project access risks using gcloud CLI, Policy Analyzer, and IAM Recommender.
configuring-identity-aware-proxy-with-google-iap
Configuring Google Cloud Identity-Aware Proxy (IAP) to enforce per-request identity verification for Compute Engine, App Engine, Cloud Run, and GKE services using access levels, context-aware policies, and programmatic access with service accounts.
building-red-team-c2-infrastructure-with-havoc
Deploy and configure the Havoc C2 framework with teamserver, HTTPS listeners, redirectors, and Demon agents for authorized red team operations.
configuring-pfsense-firewall-rules
Configures pfSense firewall rules, NAT policies, VPN tunnels, and traffic shaping to enforce network segmentation, control traffic flow, and protect internal network zones in enterprise and small-to-medium business environments.
deploying-palo-alto-prisma-access-zero-trust
Deploying Palo Alto Networks Prisma Access for SASE-based zero trust network access using GlobalProtect agents, ZTNA Connectors, security policy enforcement, and integration with Strata Cloud Manager for unified security management.
conducting-cloud-penetration-testing
This skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud environments. It covers understanding the shared responsibility model for testing scope, leveraging cloud-specific attack tools like Pacu and ScoutSuite, exploiting IAM misconfigurations, testing for SSRF…