AI-Powered Security Analysis for AWS — as a GitHub CLI extension.
Analyze AWS IAM policies and CloudFormation templates for security risks without leaving
the gh CLI. Thin wrapper around @shieldly/cli,
powered by Shieldly.
gh extension install shieldly-io/gh-shieldlyRequires Node.js 22+ (the extension runs @shieldly/cli via npx).
# Analyze an IAM policy (works without an account — free demo analyses)
gh shieldly analyze-iam policy.json
# Analyze a CloudFormation template
gh shieldly analyze-cf template.yml
# Scan AI-agent configs for blast radius
gh shieldly agent-scan
# All @shieldly/cli commands and flags work
gh shieldly --helpThe CLI works without an API key using free demo analyses (rate-limited).
For higher limits, create a free account at shieldly.io
and set SHIELDLY_API_KEY.
Shieldly does not log your policy content. Cache keys are one-way SHA-256 hashes. See shieldly.io/privacy.
MIT