AWS Agent Identity Guard

Static IAM policy linter for AI agent workloads · Source repo ↗
Static analysis tool — not a live IAM scanner. This linter checks policy JSON files for wildcards, PassRole, trust boundary issues, and privilege escalation paths that are common in agentic AI workloads. The findings below are from the bundled example policy test suite.
25
Deterministic rule IDs
AIG001–021 · TP001–003 · PB001
235
Passing tests
238 collected
3
Skipped tests
Live scan · AWS credentials required
2.1.0
SARIF output
GitHub Code Scanning compatible
Example findings — bundled test policies
Severity Check Policy Detail
CriticalWildcard action + resourceagent-role-v1.jsonAction: "*" on Resource: "*" — unrestricted access
Criticaliam:PassRole to *agent-role-v1.jsonPassRole scoped to * allows privilege escalation
CriticalTrust policy: any principaltrust-policy-v2.jsonPrincipal: * with no condition
Highs3:* on bucketdata-access.jsonFull S3 access including DeleteObject, DeleteBucket
Highsts:AssumeRole without MFA conditionagent-role-v2.jsonNo aws:MultiFactorAuthPresent condition
HighLambda:InvokeFunction on *agent-role-v2.jsonCan invoke any Lambda — lateral movement risk
Highsecretsmanager:GetSecretValue on *data-access.jsonAll secrets readable — credential theft risk
Highec2:* without resource constraintcompute-role.jsonFull EC2 control including instance termination