Use this skill
atmos ai skill install atmos-aws-complianceSKILL.md2.7 KB
View on GitHubAtmos AWS Compliance
Use this skill for compliance posture reporting through AWS Security Hub. It owns
atmos aws compliance report.
Command Model
atmos aws compliance report retrieves enabled Security Hub standard controls, maps failing
controls to Atmos stacks/components where possible, and writes reports for humans or automation.
atmos aws compliance report --framework cis-aws --stack prod-us-east-1atmos aws compliance report --framework pci-dss --format json --file compliance.jsonatmos aws compliance report --controls CIS.1.1,CIS.1.2 --format markdownatmos aws compliance report --ai
Supported report formats are markdown, json, yaml, and csv.
Configuration
Configure defaults in atmos.yaml under aws.security. Route identity setup to atmos-auth.
aws:security:enabled: trueidentity: security-readonlyregion: us-east-2frameworks:- cis-aws- pci-dss
Use --identity to override the configured identity for a run.
Frameworks
| Framework | Use |
|---|---|
cis-aws | CIS AWS Foundations Benchmark |
pci-dss | Payment Card Industry Data Security Standard |
soc2 | SOC 2 trust service criteria |
hipaa | HIPAA controls for protected health information |
nist | NIST 800-53 controls |
Agent Guidance
- Prefer
--frameworkfor targeted checks. Omit it only when the user explicitly wants all enabled frameworks. - Use
--stackwhen the report should map compliance status to a specific Atmos stack. - Use
--format jsonor--format yamlfor automation and CI gates; usemarkdownfor human reports. - Use
--filefor durable artifacts. Parent directories are created by the command. - Use
--aionly when the user asks for AI-generated summary or remediation guidance. - For detailed per-finding remediation output, route to
atmos-aws-security. - Do not invent compliance mappings. If component mapping is missing or low-confidence, say so and use Atmos introspection before proposing component changes.
Routing
| Need | Skill |
|---|---|
| Detailed security finding analysis and remediation format | atmos-aws-security |
| AWS identity/provider setup, SSO, SAML, OIDC, assume role/root | atmos-auth |
AI provider setup for --ai summaries | atmos-ai |
| Stack/component lookup before remediation | atmos-introspection, atmos-components |