# Cloud CLI packages

Cloud CLIs often hold access to accounts, deploys, registries, state, and production infrastructure from a local shell.

- **Packages:** 702
- **Protected tools:** 0
- **Approval gates:** 2
- **Non-low risk:** 289
- **Updated:** 2026-08-03

## Why this package group is here

Cloud CLI packages currently includes 702 package catalog entries. 0 have protected-tool coverage, 2 have approval-gate metadata, and 289 have non-low Geiger classifier findings. The grouping comes from package metadata, so it can stay current as that metadata changes.

## Generated source

This hub uses the same local package data as individual package pages: Nucleus package metadata, Homebrew enrichment, Geiger classifier output, secret-handling manifests, and approval-gate seeds where available.

## Review model

Use the hub to find command families that need tighter secret injection, approval gates, or manual review before agents run them.

## Indexed package pages

- [awscli](https://pkg.so/pkg/brew/awscli/) - 8 approval-gate rules are present.
- [docker](https://pkg.so/pkg/brew/docker/) - 6 approval-gate rules are present.
- [crun](https://pkg.so/pkg/brew/crun/) - generalized runtime or code generation signal
- [apache-spark](https://pkg.so/pkg/brew/apache-spark/) - broad file, network, media, or database tool signal
- [gitlab-ci-local](https://pkg.so/pkg/brew/gitlab-ci-local/) - generalized runtime or code generation signal
- [aws-shell](https://pkg.so/pkg/brew/aws-shell/) - generalized runtime or code generation signal
- [docker-agent](https://pkg.so/pkg/brew/docker-agent/) - generalized runtime or code generation signal
- [gimme](https://pkg.so/pkg/brew/gimme/) - generalized runtime or code generation signal
- [shellz](https://pkg.so/pkg/brew/shellz/) - generalized runtime or code generation signal
- [bubblewrap](https://pkg.so/pkg/brew/bubblewrap/) - narrow executable package without higher-risk signals
- [docker-compose](https://pkg.so/pkg/brew/docker-compose/) - no executable entrypoint in the package index
- [glab](https://pkg.so/pkg/brew/glab/) - no executable entrypoint in the package index
- [ansible](https://pkg.so/pkg/brew/ansible/) - no executable entrypoint in the package index
- [terragrunt](https://pkg.so/pkg/brew/terragrunt/) - no executable entrypoint in the package index
- [flyctl](https://pkg.so/pkg/brew/flyctl/) - no executable entrypoint in the package index
- [k3d](https://pkg.so/pkg/brew/k3d/) - narrow executable package without higher-risk signals
- [oras](https://pkg.so/pkg/brew/oras/) - narrow executable package without higher-risk signals
- [docker-buildx](https://pkg.so/pkg/brew/docker-buildx/) - no executable entrypoint in the package index
- [aws-sam-cli](https://pkg.so/pkg/brew/aws-sam-cli/) - no executable entrypoint in the package index
- [jfrog-cli](https://pkg.so/pkg/brew/jfrog-cli/) - narrow executable package without higher-risk signals
- [terraform-docs](https://pkg.so/pkg/brew/terraform-docs/) - no executable entrypoint in the package index
- [act](https://pkg.so/pkg/brew/act/) - narrow executable package without higher-risk signals
- [azcopy](https://pkg.so/pkg/brew/azcopy/) - no executable entrypoint in the package index
- [firebase-cli](https://pkg.so/pkg/brew/firebase-cli/) - no executable entrypoint in the package index
- [mongodb-atlas-cli](https://pkg.so/pkg/brew/mongodb-atlas-cli/) - narrow executable package without higher-risk signals
- [kubectx](https://pkg.so/pkg/brew/kubectx/) - narrow executable package without higher-risk signals
- [openshift-cli](https://pkg.so/pkg/brew/openshift-cli/) - no executable entrypoint in the package index
- [railway](https://pkg.so/pkg/brew/railway/) - no executable entrypoint in the package index
- [aws-vault](https://pkg.so/pkg/brew/aws-vault/) - no executable entrypoint in the package index
- [lazydocker](https://pkg.so/pkg/brew/lazydocker/) - narrow executable package without higher-risk signals
- [doctl](https://pkg.so/pkg/brew/doctl/) - no executable entrypoint in the package index
- [podman-compose](https://pkg.so/pkg/brew/podman-compose/) - narrow executable package without higher-risk signals
- [docker-credential-helper-ecr](https://pkg.so/pkg/brew/docker-credential-helper-ecr/) - narrow executable package without higher-risk signals
- [docker-credential-helper](https://pkg.so/pkg/brew/docker-credential-helper/) - no executable entrypoint in the package index
- [fuse-overlayfs](https://pkg.so/pkg/brew/fuse-overlayfs/) - narrow executable package without higher-risk signals
- [tfsec](https://pkg.so/pkg/brew/tfsec/) - narrow executable package without higher-risk signals
- [istioctl](https://pkg.so/pkg/brew/istioctl/) - no executable entrypoint in the package index
- [crane](https://pkg.so/pkg/brew/crane/) - no executable entrypoint in the package index
- [kubelogin](https://pkg.so/pkg/brew/kubelogin/) - narrow executable package without higher-risk signals
- [cdk8s](https://pkg.so/pkg/brew/cdk8s/) - no executable entrypoint in the package index
- [heroku](https://pkg.so/pkg/brew/heroku/) - no executable entrypoint in the package index
- [logcli](https://pkg.so/pkg/brew/logcli/) - no executable entrypoint in the package index
- [snowflake-cli](https://pkg.so/pkg/brew/snowflake-cli/) - no executable entrypoint in the package index
- [render](https://pkg.so/pkg/brew/render/) - no executable entrypoint in the package index
- [saml2aws](https://pkg.so/pkg/brew/saml2aws/) - narrow executable package without higher-risk signals
- [ramalama](https://pkg.so/pkg/brew/ramalama/) - no executable entrypoint in the package index
- [netlify-cli](https://pkg.so/pkg/brew/netlify-cli/) - no executable entrypoint in the package index
- [akamai](https://pkg.so/pkg/brew/akamai/) - narrow executable package without higher-risk signals
- [dagger](https://pkg.so/pkg/brew/dagger/) - narrow executable package without higher-risk signals
- [buildkit](https://pkg.so/pkg/brew/buildkit/) - no executable entrypoint in the package index
- [aws-elasticbeanstalk](https://pkg.so/pkg/brew/aws-elasticbeanstalk/) - no executable entrypoint in the package index
- [awscli-local](https://pkg.so/pkg/brew/awscli-local/) - no executable entrypoint in the package index
- [aws-nuke](https://pkg.so/pkg/brew/aws-nuke/) - no executable entrypoint in the package index
- [s3cmd](https://pkg.so/pkg/brew/s3cmd/) - narrow executable package without higher-risk signals
- [kubecolor](https://pkg.so/pkg/brew/kubecolor/) - narrow executable package without higher-risk signals
- [cmctl](https://pkg.so/pkg/brew/cmctl/) - narrow executable package without higher-risk signals
- [podman-tui](https://pkg.so/pkg/brew/podman-tui/) - narrow executable package without higher-risk signals
- [openstackclient](https://pkg.so/pkg/brew/openstackclient/) - no executable entrypoint in the package index
- [awscurl](https://pkg.so/pkg/brew/awscurl/) - no executable entrypoint in the package index
- [runme](https://pkg.so/pkg/brew/runme/) - narrow executable package without higher-risk signals
- [gimme-aws-creds](https://pkg.so/pkg/brew/gimme-aws-creds/) - no executable entrypoint in the package index
- [okta-aws-cli](https://pkg.so/pkg/brew/okta-aws-cli/) - narrow executable package without higher-risk signals
- [scw](https://pkg.so/pkg/brew/scw/) - no executable entrypoint in the package index
- [ethereum](https://pkg.so/pkg/brew/ethereum/) - no executable entrypoint in the package index
- [tfmigrate](https://pkg.so/pkg/brew/tfmigrate/) - narrow executable package without higher-risk signals
- [apko](https://pkg.so/pkg/brew/apko/) - no executable entrypoint in the package index
- [tf-summarize](https://pkg.so/pkg/brew/tf-summarize/) - narrow executable package without higher-risk signals
- [kubie](https://pkg.so/pkg/brew/kubie/) - narrow executable package without higher-risk signals
- [aws-sso-cli](https://pkg.so/pkg/brew/aws-sso-cli/) - no executable entrypoint in the package index
- [kics](https://pkg.so/pkg/brew/kics/) - narrow executable package without higher-risk signals
- [aws-sso-util](https://pkg.so/pkg/brew/aws-sso-util/) - no executable entrypoint in the package index
- [kops](https://pkg.so/pkg/brew/kops/) - narrow executable package without higher-risk signals
