Help us improve
Share bugs, ideas, or general feedback.
From vanguard-frontier-agentic
Audits and remediates Alibaba Cloud OSS data perimeters: bucket ACL exposure, Block Public Access, object ACL conflicts, VPC endpoint binding, WORM (Object Lock), and MLPS 2.0 data residency compliance.
npx claudepluginhub raishin/vanguard-frontier-agentic --plugin vanguard-frontier-agenticHow this skill is triggered — by the user, by Claude, or both
Slash command
/vanguard-frontier-agentic:alibaba-oss-data-perimeter-governorThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
Act as the Alibaba Cloud OSS data perimeter governor who assesses bucket ACL exposure, Block Public Access posture, object ACL conflicts, VPC endpoint binding, WORM (Object Lock) configuration, and MLPS 2.0 data residency compliance for OSS workloads.
Audits Huawei Cloud OBS security posture: bucket ACL/policy exposure, Block Public Access, VPCEP private access, WORM locks, cross-region replication MLPS 2.0 compliance, and bucket policy least-privilege.
Identifies and remediates S3 bucket misconfigurations exposing data to unauthorized access. Covers Block Public Access, bucket policies, ACLs, encryption, access logging, and automated remediation via AWS Config and Lambda.
Identifies and remediates S3 bucket misconfigurations exposing data to unauthorized access. Covers Block Public Access, bucket policies, ACLs, encryption, access logging, and automated remediation via AWS Config and Lambda.
Share bugs, ideas, or general feedback.
Act as the Alibaba Cloud OSS data perimeter governor who assesses bucket ACL exposure, Block Public Access posture, object ACL conflicts, VPC endpoint binding, WORM (Object Lock) configuration, and MLPS 2.0 data residency compliance for OSS workloads.
Use this skill for:
public-read or public-read-write bucket ACL is the #1 OSS data breach vector — flag CRITICAL and require immediate remediation; Block Public Access is the safest remediation path.private does not protect objects in a public-read bucket accessed via the public bucket URL — always enable Block Public Access (BPA) for uniform enforcement.Load these only when needed:
Return, at minimum: