Master 1Password: vaults, Watchtower, passkeys, SSH agent, CLI, and family/team administration. Use when getting full value from 1Password personally or administering it for others.
日本語の概要は準備中です。原文の説明を表示しています。
Secure cloud environments — IAM, posture management, logging, and multi-account architecture across providers.
インストールする前に、エージェントに与えられる指示の中身を確認できます。
Cloud security is identity security plus configuration discipline at API speed: the control plane is an API, misconfigurations deploy in seconds, and the blast radius of an over-permissioned role is the whole account. The shared-responsibility model means the provider secures the cloud, you secure what you put in it — and most cloud breaches are the customer's configuration, not the provider's infrastructure.
This skill covers the defensive program: account architecture, identity hardening, posture management (CSPM), detective controls, and data protection in AWS/Azure/GCP-style environments.
Design the account structure before the workloads: separate accounts/projects per environment and blast-radius boundary, centralized logging and security tooling, and SCP-style guardrails that make the dangerous thing hard. Retrofitting account architecture onto 200 workloads is ten times the cost of doing it on day one.
Account/project architecture. Separate by environment and sensitivity; centralize security tooling and logging; apply preventive guardrails (SCPs, organization policies) that block the worst misconfigurations by default.
Cloud IAM least privilege. No long-lived access keys where roles/instance identities work; permission boundaries and conditions (MFA, source IP, time); regularly audit wildcard permissions — cloud IAM is where breaches start.
CSPM continuous posture. Automated checks for public buckets, open security groups, unencrypted storage, disabled logging, and exposed admin consoles — with auto-remediation for the clear-cut cases and tickets for the rest.
Control-plane logging. CloudTrail / Activity Logs / Audit Logs are non-negotiable: multi-region, immutable storage, alerting on key events (console logins, IAM changes, network modifications, data exports).
Network design. Private subnets by default, no public IPs without justification, security groups as least-privilege firewalls, VPC flow logs for the sensitive segments, and no flat "everything talks to everything" VPCs.
Data protection. Encryption at rest (with customer-managed keys for sensitive data), TLS in transit, backup with tested restore, and lifecycle policies so data does not accumulate forever.
Workload identity. Prefer native workload identities (instance roles, workload identity federation) over static credentials — eliminate the secrets that get leaked from code and CI.
Anomaly detection. Native threat detection (GuardDuty, Defender, Security Command Center) plus custom alerts on control-plane anomalies — tuned, triaged, and fed to the SOC.
Tagging and ownership. Mandatory tags (owner, environment, data classification) make every other control — cost, incident response, compliance — actually work. Enforce at provisioning.
Cross-account role trust policies. Trust policies with overly broad principals (entire orgs, external accounts without external IDs) are privilege-escalation paths. Constrain and review them.
Ephemeral environment hygiene. Short-lived dev/test environments accumulate with production-grade access and no ownership. Tag, time-box, and auto-clean them.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Master 1Password: vaults, Watchtower, passkeys, SSH agent, CLI, and family/team administration. Use when getting full value from 1Password personally or administering it for others.
日本語の概要は準備中です。原文の説明を表示しています。
Create 3D visuals with modeling, texturing, lighting, rendering, and optimization for web and product.
日本語の概要は準備中です。原文の説明を表示しています。
Create 3D web experiences: scene setup, models, materials, lighting, animation, scroll-driven scenes, and performance budgets. Use when adding 3D to websites beyond basic demos.
日本語の概要は準備中です。原文の説明を表示しています。
Writing abstracts that get papers read — structured content, the 5-sentence core, and journal-specific constraints.
日本語の概要は準備中です。原文の説明を表示しています。
Learn effectively from courses and academies: choosing programs, studying actively, and converting courses into skills. Use when investing time/money in structured learning.
日本語の概要は準備中です。原文の説明を表示しています。
Audit designs for accessibility with WCAG checklists covering color, type, focus, motion, and content.
日本語の概要は準備中です。原文の説明を表示しています。