Review IAM Policy
review_iam_policyEvaluate AWS IAM policy risk from structured facts or raw policy JSON. Identify wildcard scope, privilege-escalation actions, and condition constraints without calling AWS.
Instructions
Evaluate AWS IAM policy risk from structured facts or raw policy JSON, including wildcard scope, privilege-escalation actions and conditions. Use this for AWS IAM operational risk; for provider-specific AWS/Azure/GCP policy-pack checks, use review_cloud_identity_policy. It analyzes supplied policy data only and does not call AWS or modify IAM.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| actions | No | Explicit allowed IAM actions when raw policy JSON is not supplied. | |
| resources | No | Explicit IAM resource ARNs or patterns when raw policy JSON is not supplied. | |
| policyJson | No | Raw AWS IAM policy JSON. When supplied, the server derives actions, resources, wildcard scope and privilege-escalation evidence. | |
| policyName | Yes | Name of the AWS IAM policy being assessed. | |
| usedByProduction | No | Whether the policy is attached to or used by production identities or workloads. | |
| hasConditionBlocks | No | Whether policy statements include Condition constraints that narrow access. | |
| hasWildcardActions | No | Whether the policy permits wildcard actions such as * or service:* patterns. | |
| hasWildcardResources | No | Whether the policy grants permissions against wildcard resources. | |
| allowsPrivilegeEscalationActions | No | Whether the policy contains actions that can enable privilege escalation. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| actions | Yes | ||
| evidence | Yes | ||
| findings | Yes | ||
| resources | Yes | ||
| riskLevel | Yes | ||
| riskScore | Yes | ||
| strengths | Yes | ||
| policyName | Yes | ||
| uncertainties | Yes | ||
| recommendedControls | Yes | ||
| assessmentConfidence | Yes |