Skip to content
Back to skills

Ovhcloud Iam Policy Review

ASecurity

Review OVHcloud IAM policies for overly permissive allow rules, missing deny blocks, unscoped URNs, absent condition blocks (IP CIDR, resource tag, expiration), and identity-group hygiene. Use when the user needs to audit access control, review `ovh_iam_policy` Terraform resources, assess OAuth2 service account scopes, or validate conditional access configuration against the principle of least privilege.

  • 23 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added May 29, 2026
devopsgoterraformgitsecurity

Works with

  • mcp

Security analysis

A100/100

Pro scans all 4 files and shows the line behind each finding

Scanned May 29, 2026

npx -y skills add Raishin/vanguard-frontier-agentic --skill ovhcloud-iam-policy-review --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ovhcloud Iam Policy Review?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ovhcloud Iam Policy Review
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/raishin-ovhcloud-iam-policy-review/badge)](https://www.skillsdirectory.com/skills/raishin-ovhcloud-iam-policy-review)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: ovhcloud-iam-policy-review
description: Review OVHcloud IAM policies for overly permissive allow rules, missing deny blocks, unscoped URNs, absent condition blocks (IP CIDR, resource tag, expiration), and identity-group hygiene. Use when the user needs to audit access control, review `ovh_iam_policy` Terraform resources, assess OAuth2 service account scopes, or validate conditional access configuration against the principle of least privilege.
allowed-tools: Read Grep Glob
metadata:
  author: "github: Raishin"
  version: "0.1.0"
  updated: "2026-05-10"
  category: security
---

# OVHcloud IAM Policy Review

## Purpose

Audit OVHcloud IAM policies for over-permissive access, missing conditional controls, and identity-group hygiene gaps. Produce an evidence-backed verdict with least-privilege recommendations.

## When to use

Use this skill for:

- Auditing `ovh_iam_policy` Terraform resources for scope and condition gaps
- Reviewing OAuth2 service account permissions against the principle of least privilege
- Assessing identity groups for membership sprawl or excessive aggregated permissions
- Evaluating conditional access blocks: IP CIDR restrictions, resource tag conditions, expiration dates
- Pre-deployment review of new IAM policies or policy changes

## Lean operating rules

- Prefer OVHcloud IAM docs and Terraform provider docs; if MCP tooling is unavailable, fall back to https://help.ovhcloud.com/ and Context7.
- Separate confirmed policy state from inference. If the policy was not shown, say so.
- Challenge policies with wildcarded URNs (`urn:v1:eu:resource:*`), missing condition blocks, or allow rules that supersede deny rules unexpectedly.
- Recommend least-privilege: scope to narrowest URN prefix, add IP condition, set expiration where supported.
- Keep recommendations reversible and explicit about blast radius.

## References

Load these only when needed:

- [Workflow and output contract](references/workflow-and-output.md) — use when executing the full IAM audit or formatting the final answer.
- [Safety checklist](references/safety-checklist.md) — use before privileged, access-granting, or production-impacting recommendations.
- [Official sources](references/official-sources.md) — use when grounding OVHcloud IAM service behavior or checking the source list.

## Response minimum

Return, at minimum:

- the policy verdict and evidence level,
- specific URN scope and condition gaps found,
- the blast radius of the current policy,
- safe remediation recommendations with rollback notes,
- blockers or unknowns that prevent stronger conclusions.

Files in this skill

  • SKILL.md2.6 KB
  • references/official-sources.md810 B
  • references/safety-checklist.md1.6 KB
  • references/workflow-and-output.md2.4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…