Skip to main content
Use this skill
atmos ai skill install atmos-aws-compliance
SKILL.md2.7 KB
View on GitHub

Atmos AWS Compliance

Use this skill for compliance posture reporting through AWS Security Hub. It owns atmos aws compliance report.

Command Model

atmos aws compliance report retrieves enabled Security Hub standard controls, maps failing controls to Atmos stacks/components where possible, and writes reports for humans or automation.

atmos aws compliance report --framework cis-aws --stack prod-us-east-1
atmos aws compliance report --framework pci-dss --format json --file compliance.json
atmos aws compliance report --controls CIS.1.1,CIS.1.2 --format markdown
atmos aws compliance report --ai

Supported report formats are markdown, json, yaml, and csv.

Configuration

Configure defaults in atmos.yaml under aws.security. Route identity setup to atmos-auth.

aws:
security:
enabled: true
identity: security-readonly
region: us-east-2
frameworks:
- cis-aws
- pci-dss

Use --identity to override the configured identity for a run.

Frameworks

FrameworkUse
cis-awsCIS AWS Foundations Benchmark
pci-dssPayment Card Industry Data Security Standard
soc2SOC 2 trust service criteria
hipaaHIPAA controls for protected health information
nistNIST 800-53 controls

Agent Guidance

  • Prefer --framework for targeted checks. Omit it only when the user explicitly wants all enabled frameworks.
  • Use --stack when the report should map compliance status to a specific Atmos stack.
  • Use --format json or --format yaml for automation and CI gates; use markdown for human reports.
  • Use --file for durable artifacts. Parent directories are created by the command.
  • Use --ai only when the user asks for AI-generated summary or remediation guidance.
  • For detailed per-finding remediation output, route to atmos-aws-security.
  • Do not invent compliance mappings. If component mapping is missing or low-confidence, say so and use Atmos introspection before proposing component changes.

Routing

NeedSkill
Detailed security finding analysis and remediation formatatmos-aws-security
AWS identity/provider setup, SSO, SAML, OIDC, assume role/rootatmos-auth
AI provider setup for --ai summariesatmos-ai
Stack/component lookup before remediationatmos-introspection, atmos-components