Permissions for @turbot/aws-sqs

Taking a look at permissions and associated grant levels for each permission for SQS:

PermissionGrant LevelHelp
sqs:AddPermissionAdminAllows cross-account access.
sqs:ChangeMessageVisibilityOperator
sqs:ChangeMessageVisibilityBatchOperator
sqs:CreateQueueAdmin
sqs:DeleteMessageOperator
sqs:DeleteMessageBatchOperator
sqs:DeleteQueueAdmin
sqs:GetQueueAttributesMetadata
sqs:GetQueueUrlMetadata
sqs:ListDeadLetterSourceQueuesMetadata
sqs:ListQueueTagsMetadata
sqs:ListQueuesMetadata
sqs:PurgeQueueAdmin
sqs:ReceiveMessageReadOnly
sqs:RemovePermissionAdmin
sqs:SendMessageOperator
sqs:SendMessageBatchOperator
sqs:SetQueueAttributesAdminAllows management of many attributes which are fine and necessary. Also allows managmenet of the queue policy which may include sharing across accounts - checked with a detective control.
sqs:TagQueueOperator
sqs:UntagQueueOperator