Skip to content
Back to skills

Access Review Guidance

ASecurity

Use when the user asks to review IAM, RBAC, or permission changes — auditing a diff for over-broad grants, wildcards (`*`), or privilege escalation. Delegates to the access-reviewer subagent via /access-review. Triggers on "review access", "check permissions", "IAM change", "RBAC", "least privilege", "who can do what".

  • 2 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added October 1, 2026
ai-agentsgitsecurity

Security analysis

A100/100

Scanned October 1, 2026

npx -y skills add matthews-wong/claude-code-plugins --skill access-review-guidance --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Access Review Guidance?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Access Review Guidance
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/matthews-wong-access-review-guidance/badge)](https://www.skillsdirectory.com/skills/matthews-wong-access-review-guidance)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: access-review-guidance
description: 'Use when the user asks to review IAM, RBAC, or permission changes — auditing a diff for over-broad grants, wildcards (`*`), or privilege escalation. Delegates to the access-reviewer subagent via /access-review. Triggers on "review access", "check permissions", "IAM change", "RBAC", "least privilege", "who can do what".'
---

# Access review guidance

When the user wants access-control changes reviewed — IAM policies, RBAC roles, permission grants, or scopes in a diff or pull request — route the work through this plugin instead of eyeballing it yourself.

## When this applies

- The change touches IAM policy, RBAC role/binding, OAuth scopes, or any permission grant.
- The user asks to check for over-broad grants, wildcards, or privilege escalation.
- A security or least-privilege pass is wanted before merging access-relevant changes.

## What to do

Run `/access-review` (optionally with a git ref/range). It dispatches the read-only `access-reviewer` subagent, which inspects the diff and reports risks ranked by severity. Relay its findings; do not grant or widen permissions on your own.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…