
cloud-security-scanner
Cloud security scanning tools for AI agents. 7 purpose-built AWS scanners that check for misconfigurations across S3, IAM, EC2, EKS, RDS, CloudTrail, and CloudWatch Logs. Each scanner is a static ~2MB binary that outputs JSONL. Checks include public access, missing encryption, stale credentials, weak password policies, disabled logging, and more. ## Tools - **search** — Find scanners by capability (e.g. "encryption", "public access", "iam") - **get** — Get download URL, SHA256 hash, and a ready-to-run shell command for any scanner ## Scanners | Scanner | Service | Checks | |---|---|---| | k5e-aws-s3 | S3 | encryption, public access, versioning, logging, lifecycle | | k5e-aws-iam | IAM | root MFA, stale access keys, password policy | | k5e-aws-ec2 | EC2 | public SSH, security groups, EBS encryption, IMDSv2 | | k5e-aws-eks | EKS | public endpoint, logging, secrets encryption | | k5e-aws-rds | RDS | public access, encryption, backups | | k5e-aws-cloudtrail | CloudTrail | multi-region, log validation, KMS encryption | | k5e-aws-cloudwatch-logs | CloudWatch Logs | retention, encryption, metric filters | Built by [Kloudle](https://kloudle.com).
First seen 2 Oct 2026. Evidence as of 5 Oct 2026.
Tools
No tool list captured yet.
Change history
No changes since the first observation. The first snapshot is the baseline.
| Source | Listing | First seen | Last seen | Versions |
|---|---|---|---|---|
| Smithery | kloudle/cloud-security-scanner | 2 Oct 2026 | 5 Oct 2026 | 1 |