CLOUD SECURITY — BOOKING DEPT.

ROAST MY
IAM POLICY

Paste your AWS IAM policy. We'll pull its priors, file the charges, and tell you exactly how bad it is — with jokes.

⚠️ For fun and learning — not a security audit. A real review needs your CloudTrail data and someone who knows your architecture.

SAMPLE CASE FILE
THREAT LEVEL 10/10 AKA: The All-You-Can-Eat Buffet
"You gave a Lambda function full account admin. That's not a function, that's a toddler with the nuclear launch codes and a snack."
EXHIBIT A — SUBMITTED POLICY
🔒 No login, no database, no tracking. Your policy is analyzed right here in your browser — the AI sees only issue types, AWS action names and scope shapes, never your account IDs, resource names or ARNs, and your policy text reaches AWS's own validator with every account ID swapped for a placeholder.
For fun and learning — not a security audit.
Your real security tool is still out there doing the actual work (and definitely judging you less).
Report a bad roast · How it works