Analyze AWS IAM policies and CloudFormation templates as you write them, without leaving your editor. Inline risk squiggles, a security score in the status bar, and a full results panel. Powered by Shieldly.
Search "Shieldly" in the VS Code Marketplace, or:
ext install shieldly.shieldly
- Open any
.json,.yaml, or.ymlfile containing an IAM policy or CloudFormation template. - Run Shieldly: Run AI-Powered Analysis from the editor toolbar, the right-click menu, or the Command Palette.
- See inline squiggles on risky lines plus a full results panel.
| Command | Description |
|---|---|
Shieldly: Run AI-Powered Analysis |
Analyze the current file |
Shieldly: Set API Key |
Store your sk_live_... key |
Shieldly: Clear API Key (reset to demo) |
Remove the stored key |
Shieldly: Show Last Result |
Reopen the last results panel |
Without an API key, the extension runs in limited demo mode. Get a key at shieldly.io/app/api.
| Setting | Default | Description |
|---|---|---|
shieldly.apiUrl |
https://api.shieldly.io |
API base URL (override for dev). |
shieldly.autoAnalyze |
false |
Automatically analyze JSON files on open. |
Shieldly does not log your policy input. Cache keys are one-way SHA-256 hashes.
- Web app & demo: https://www.shieldly.io
- API reference: https://www.shieldly.io/docs/api
No account required — these run in your browser or document the risks:
- IAM Privilege Escalation Cheat Sheet — every common escalation path on one page, with fixes
- Free browser tools — IAM policy linter, trust policy explainer, S3 bucket policy checker, CloudFormation IAM checker, ARN parser, policy diff, CloudTrail least-privilege generator
- Awesome AWS IAM Security — curated list of IAM security tools and references
- IAM privilege escalation reference — each method with a vulnerable policy, the exploit, and the fix
MIT © Shieldly
Amazon Web Services (AWS) is a trademark of Amazon.com, Inc. Shieldly is not affiliated with, endorsed by, or sponsored by Amazon Web Services.