| Severity | Check | Policy | Detail |
|---|---|---|---|
| Critical | Wildcard action + resource | agent-role-v1.json | Action: "*" on Resource: "*" — unrestricted access |
| Critical | iam:PassRole to * | agent-role-v1.json | PassRole scoped to * allows privilege escalation |
| Critical | Trust policy: any principal | trust-policy-v2.json | Principal: * with no condition |
| High | s3:* on bucket | data-access.json | Full S3 access including DeleteObject, DeleteBucket |
| High | sts:AssumeRole without MFA condition | agent-role-v2.json | No aws:MultiFactorAuthPresent condition |
| High | Lambda:InvokeFunction on * | agent-role-v2.json | Can invoke any Lambda — lateral movement risk |
| High | secretsmanager:GetSecretValue on * | data-access.json | All secrets readable — credential theft risk |
| High | ec2:* without resource constraint | compute-role.json | Full EC2 control including instance termination |