All loops
SecurityMedium 14 min· claude-sonnet-4-5
Permissions least-privilege coach
Permissions least-privilege coach with audit-grade logs.
Read the full Security build guide →NOT DEPLOYEDNOT DEPLOYED
0164ms
Trigger
cron(0 7 * * *) fired · every day · 07:00
021064ms
Agent
claude-sonnet-4-5 · in 1364 tok · out 413 tok
03334ms
Tools
aws-mcp/anthropic:messages.create → 200 OK · 304ms
0454ms
Verify
schema check · pydantic v2 passed
0584ms
Output
linear ticket · SOC2 evidence stored
0644ms
Notify
audit log written · runbook link attached
SUCCESS
0%
0 runs
P50
0ms
median
P95
0ms
tail
AVG COST
—
per run
LAST OK
never
—
LAST FAIL
never
none
Latency · last 30 runs0 samples
no runs yet
Latest output · what your users see
SEC-1084CWE-798
Hardcoded AWS access key in `packages/worker/env.ts`
// press Test to run once · Watch live to keep streaming · Deploy to make it real
The problem
Security tasks are tedious, easy to skip, and dangerous to skip.
The outcome
Tedium is automated; humans review summaries and approve.
Ingredients & skills
Secrets
- ANTHROPIC_API_KEY
Providers
- Anthropic
MCP servers
- aws-mcp
- github-mcp
#security#audit#claude
How it works
Permissions least-privilege coach with audit-grade logs.
Step 1
1 — Read-only scan
All cloud + repo calls are scoped read-only by the locker.
Step 2
2 — Summarise
Claude ranks findings by blast radius, not raw severity.
Step 3
3 — Ticket
Top findings open tickets with owner + suggested fix.
One-line deploy
The button above runs the same command with your saved config. This is the raw CLI form.
bash
npx claudeloops deploy permissions-least-privilege-coach