# Sweep the estate for risky configuration

Sweeps AWS, Supabase, Fly, Cloudflare and Kubernetes for public buckets, missing alarms, absent backups and single points of failure.

## The prompt

```
I want to do this: Find the risky configuration: public buckets, missing alarms, single points of failure.

## Setup (skip if Polylane is already set up)

Read and follow https://polylane.com/auth.md for non-interactive signup and setup. Start by checking whether I am already signed in; reuse my account and workspace.

If the CLI is missing, bootstrap it without starting the interactive wizard:

curl -fsSL 'https://polylane.com/setup?ref=prompts' | bash -s -- --install-only

Then follow the guide through email verification, workspace selection, source connections, and MCP authentication. Ask me for an email code or OAuth consent only when needed. Verify each step; report pending setup instead of claiming success from installation alone.

## How to work

Over MCP: searchTools lists what this workspace exposes, with each tool's schema; call it first. runTool runs one tool, runCode chains several in one call and returns just the answer. search and execute cover the full Polylane REST API: threads, issues, investigations, autofixes, memories.
From the terminal: the polylane CLI wraps the same API, with structured output and non-interactive flags everywhere.
Reads always work. Write tools appear only if I have opted in, and every write is screened.

## Task: Sweep the estate for risky configuration

Steps:
1. Sweep every connected account's advisories: misconfigurations, resilience risks, observability gaps
2. Check the critical tier first: the resources whose failure actually hurts
3. For each finding, pull the configuration evidence behind it
4. Rank by blast radius: what breaks if this specific risk fires
5. Deliver the sweep, worst first, each finding citing its config

Ground every claim in data you actually pulled: the query, the log line, the change record. If the data is inconclusive, say so. Ask me before anything that writes.
```

## What it replaces

**Every audit finds the same five skeletons.** The public bucket, the database with no failover, the service with no alarm: everyone suspects they're out there, and confirming it means a manual sweep nobody has budgeted for since the last audit.

- Security reviews that happen once a year, drift that happens daily
- The single-AZ database discovered during the outage
- Findings lists with no evidence attached

## What the agent does

1. Sweep every connected account's advisories: misconfigurations, resilience risks, observability gaps
2. Check the critical tier first: the resources whose failure actually hurts
3. For each finding, pull the configuration evidence behind it
4. Rank by blast radius: what breaks if this specific risk fires
5. Deliver the sweep, worst first, each finding citing its config

## What you get

**The skeletons, enumerated and ranked** Every risky config on one list with its evidence and blast radius, refreshed from the live estate instead of last year's audit. Fix the worst one this week.

Every prompt: https://polylane.com/prompts/

Get started with one command: `curl -fsSL https://polylane.com/setup | bash` installs the CLI, connects your coding agents, and creates the account.
