Cognito pool with a weak password policy
Six characters, no symbols, no MFA — defaults nobody revisited.
Press Run. The stack loaded here fails in a way worth seeing.
▸What the engine finds5 findings
Not examples — Cognito pool with a weak password policy was run through the real engine when this page was built, and this is what it returned.
MfaConfiguration is OFF.INTENT
MinimumLength is below 8.INTENT
▸ 3 informational findings — password policy is, mfa is not, advanced security mode
Password policy is too weakAwsSolutions-COG1Users
A short password policy makes credential-stuffing cheap, and this pool is the front door to every account.
Full rule text
The Cognito user pool does not have a password policy that minimally specify a password length of at least 8 characters, as well as requiring uppercase, numeric, and special characters. Strong password policies increase system security by encouraging users to create reliable and secure passwords. AwsSolutions-COG1 guide →
MFA is not requiredAwsSolutions-COG2Users
The Cognito user pool does not require MFA. Multi-factor authentication (MFA) increases security for the application by adding another authentication method, and not relying solely on user name and password.
Full rule text
The Cognito user pool does not require MFA. Multi-factor authentication (MFA) increases security for the application by adding another authentication method, and not relying solely on user name and password.
Advanced security mode is offAwsSolutions-COG3Users
The Cognito user pool does not have AdvancedSecurityMode set to ENFORCED. Advanced security features enable the system to detect and act upon malicious sign-in attempts.
Full rule text
The Cognito user pool does not have AdvancedSecurityMode set to ENFORCED. Advanced security features enable the system to detect and act upon malicious sign-in attempts.
Or start from a stack that fails interestingly
The single most common AI-generated CDK mistake: a bucket left open to the world.
SSH open to the entire internet — the classic copy-paste ingress rule.
Website hosting straight off a bucket — no CDN, no TLS, no access logging.
A database with storage encryption off and backups barely configured.
Action "*" on Resource "*" — the permission grant that ends incident reviews.
A REST API wired to Lambda, wide open, with no access logging.
Fast to write, impossible to restore — no PITR, no encryption choice.
A CDN that will happily serve your site unencrypted, with no logging.
A queue with no server-side encryption and no dead-letter queue.
Network traffic no one can reconstruct after the fact.
Six characters, no symbols, no MFA — defaults nobody revisited.
The one that passes. Encrypted, recoverable, with a dead-letter queue — what good looks like.