Auditing S3 Object Ownership Trust

Audit object-storage ownership and per-object access for trust the bucket policy does not cover: an object uploaded by another account that keeps that uploader's ownership and ACL, a bucket where object ACLs still grant access despite a restrictive bucket policy, a cross-account write that lands an object the bucket owner cannot read or that carries a public grant, and a policy that scopes by prefix while an ACL on the object overrides it. Covers S3 and compatible stores where object ownership, object ACLs, and the bucket policy interact to decide who reads and controls each object. Use when a bucket receives objects from more than one principal and access is meant to be governed centrally. The cross-account or ACL-granted principal is the source, the object read or control is the sink, and the access the bucket policy did not intend is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-s3-object-ownership-trust commit 3e72e1a132

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-s3-object-ownership-trust