Auditing Cross Account Role Trust Boundaries

Audit cross-account IAM role assumption for trust policies that let the wrong principal assume a role: a trust policy with a wildcard or overbroad principal, a missing or unverifiable external ID on a third-party role, a confused-deputy path where a vendor assumes your role on any customer's behalf, and a role chain that reaches privileges the origin principal should never hold. Covers AWS assume-role trust policies, condition keys that should scope who may assume, and the transitive reach of one assumption into the next. Use when roles in one account can be assumed from another account, a partner, or a service, and the trust policy is the boundary. The external principal permitted by the trust policy is the source, the assume-role grant is the sink, and the trust scope wider than the intended relationship is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-cross-account-role-trust-boundaries commit 39eece9be8

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-cross-account-role-trust-boundaries