Skip to content
Back to skills

Aws Lambda

ASecurity

Scaffold an AWS Lambda with a least-privilege IAM role and a clean handler

  • 3 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 3, 2026
ai-agentsgoawsterraformapi

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill aws-lambda --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Aws Lambda?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Aws Lambda
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-aws-lambda/badge)](https://www.skillsdirectory.com/skills/black141312-aws-lambda)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: aws-lambda
description: Scaffold an AWS Lambda with a least-privilege IAM role and a clean handler
category: cloud
---

# AWS Lambda

Use this to create a deployable Lambda function — handler code, an execution role scoped to exactly what it touches, and the wiring (env, timeout, trigger).

1. Write the handler with the runtime's expected signature (`handler(event, context)`), keeping the entry thin and the logic in testable functions.
2. Initialize clients and read config (env vars) at module scope so they're reused across warm invocations.
3. Define an IAM execution role granting only the actions/resources this function needs, plus `AWSLambdaBasicExecutionRole` for logs.
4. Declare the function in IaC (Terraform/SAM/CDK): runtime, `handler`, `memory_size`, `timeout`, env vars, and the role ARN.
5. Wire the trigger (API Gateway, EventBridge, SQS, S3) and grant the source permission to invoke.
6. Test locally (`sam local invoke` or a unit test passing a sample event) before deploying.
7. Add structured logging and set a `CloudWatch` log retention so logs don't accumulate forever.

## Rules
- Scope IAM to specific resource ARNs and actions — never attach `*` or broad managed policies like `AdministratorAccess`.
- Pull secrets from Secrets Manager/SSM at runtime, not from plaintext env vars.
- Set a realistic `timeout` and `memory_size`; the default 3s timeout silently fails many functions.
- Make handlers idempotent — retries (SQS, async) will re-deliver events.
- Don't store state in `/tmp` expecting persistence; treat every invocation as potentially cold.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…