CFM TipsSAFE
A MCP Server that's built on top of AWS Cloud Financial Management (CFM) Technical Implementation Playbooks (TIPs) - our proven collection of cost optimization best practices
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A comprehensive Model Context Protocol (MCP) server for AWS cost analysis and optimization recommendations, designed to work seamlessly with Kiro CLI and other MCP-compatible clients.
✅ Features
Core AWS Services Integration
- Cost Explorer - Retrieve cost data and usage metrics
- Cost Optimization Hub - Get AWS cost optimization recommendations
- Compute Optimizer - Right-sizing recommendations for compute resources
- Trusted Advisor - Cost optimization checks and recommendations
- Performance Insights - RDS performance metrics and analysis
Cost Optimization Playbooks
- 🔧 EC2 Right Sizing - Identify underutilized EC2 instances with 12 specialized analysis tools
- 💾 EBS Optimization - Find unused and underutilized volumes
- 🗄️ RDS Optimization - Identify idle and underutilized databases
- ⚡ Lambda Optimization - Find overprovisioned and unused functions
- 🪣 S3 Optimization - Comprehensive S3 cost analysis and storage class optimization with 11 specialized tools
- 📋 CloudTrail Optimization - Analyze and optimize CloudTrail configurations
- 📊 CloudWatch Optimization - Optimize monitoring costs across logs, metrics, alarms, and dashboards
- 💰 Database Savings Plans - Analyze and optimize database commitment plans for Aurora, RDS, DynamoDB, and more
- 🌐 NAT Gateway Optimization - Identify underutilized, redundant, and unused NAT Gateways
- 📈 Comprehensive Analysis - Multi-service cost analysis
Advanced Features
- Real CloudWatch Metrics - Uses actual AWS metrics for analysis
- Multiple Output Formats - JSON and Markdown report generation
- Cost Calculations - Estimated savings and cost breakdowns
- Actionable Recommendations - Priority-based optimization suggestions
📁 Project Structure
sample-cfm-tips-mcp/ ├── playbooks/ # CFM Tips optimization playbooks engine │ ├── ec2/
7dff05b2981bOBSERVED · 2026-10-08Exposed tools (54)
40 read · 14 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
cloudwatch_alarms_and_dashboards_optimization | write | Run CloudWatch alarms and dashboards optimization analysis to identify monitoring efficiency improvements. Provide Well-Architected recommendations for Operational Excellence and Cost Optimization. |
cloudwatch_comprehensive_optimization_tool | write | Run comprehensive CloudWatch optimization using the unified optimization tool with intelligent orchestration. Returns aggregate summary by default to avoid token overflow. Use detail_level= |
cloudwatch_general_spend_analysis | write | Run CloudWatch general spend analysis to understand cost breakdown across logs, metrics, alarms, and dashboards. Provide Well-Architected recommendations for Cost Optimization and Operational Excellence. |
cloudwatch_logs_optimization | write | Run CloudWatch logs optimization analysis to identify log retention and ingestion cost optimization opportunities. Provide Well-Architected recommendations for Cost Optimization and Operational Excellence. |
cloudwatch_metrics_optimization | write | Run CloudWatch metrics optimization analysis to identify custom metrics cost optimization opportunities. Provide Well-Architected recommendations for Cost Optimization and Performance Efficiency. |
ebs_optimization | write | Run comprehensive EBS optimization analysis to identify unused and underutilized volumes. Use results to suggest AWS Well-Architected Framework improvements for Cost Optimization (unused resources), Performance Efficiency (volume types), and Reliability (backup strategies) pillars. |
ebs_report | read | Generate detailed EBS optimization report with cost savings |
ebs_unused | read | Identify unused EBS volumes that can be deleted. Provide Well-Architected recommendations for Cost Optimization. |
ec2_burstable_analysis | read | Analyze burstable instances for credit usage optimization. Provide Well-Architected recommendations for Performance Efficiency and Cost Optimization. |
ec2_commitment_plans | read | Analyze instances for Reserved Instance and Savings Plans opportunities. Provide Well-Architected recommendations for Cost Optimization. |
ec2_comprehensive_report | read | Generate comprehensive EC2 optimization report covering all playbooks. Provide holistic Well-Architected recommendations across all pillars. |
ec2_detailed_monitoring | read | Identify instances without detailed monitoring enabled. Provide Well-Architected recommendations for Operational Excellence. |
ec2_governance_violations | read | Detect EC2 governance violations and policy non-compliance. Provide Well-Architected recommendations for Security and Operational Excellence. |
ec2_graviton_compatible | read | Identify instances compatible with Graviton processors. Provide Well-Architected recommendations for Cost Optimization and Performance Efficiency. |
ec2_old_generation | read | Identify old generation EC2 instances that should be upgraded. Provide Well-Architected recommendations for Performance Efficiency and Cost Optimization. |
ec2_report | read | Generate detailed EC2 right-sizing report with recommendations |
ec2_rightsizing | write | Run comprehensive EC2 right-sizing analysis to identify underutilized instances. Based on findings, provide AWS Well-Architected Framework recommendations for Cost Optimization (right-sizing), Performance Efficiency (instance types), and Reliability (availability zones) pillars. |
ec2_scheduling_opportunities | read | Identify instances suitable for scheduling optimization. Provide Well-Architected recommendations for Cost Optimization and Operational Excellence. |
ec2_spot_opportunities | read | Identify instances suitable for Spot pricing. Provide Well-Architected recommendations for Cost Optimization and Reliability. |
ec2_stopped_instances | read | Identify stopped EC2 instances that could be terminated. Provide Well-Architected recommendations for Cost Optimization and Operational Excellence. |
ec2_unattached_eips | read | Identify unattached Elastic IP addresses. Provide Well-Architected recommendations for Cost Optimization. |
ec2_unused_reservations | read | Identify unused On-Demand Capacity Reservations. Provide Well-Architected recommendations for Cost Optimization. |
generate_cloudtrail_report | read | Generate CloudTrail optimization report. Use findings to suggest AWS Well-Architected Framework improvements for Security (logging, monitoring), Operational Excellence (observability), and Cost Optimization (log retention) pillars. |
get_cloudwatch_cost_estimate | read | Get detailed cost estimate for CloudWatch optimization analysis based on enabled features. Provide Well-Architected recommendations for Cost Optimization. |
get_coh_recommendations | read | Get cost optimization recommendations from AWS Cost Optimization Hub. Analyze these recommendations and provide additional AWS Well-Architected Framework insights for Cost Optimization, Performance Efficiency, and Operational Excellence pillars. |
get_compute_optimizer_recommendations | read | Get recommendations from AWS Compute Optimizer. Use these findings to suggest AWS Well-Architected Framework improvements for Performance Efficiency, Cost Optimization, and Reliability pillars. |
get_cost_explorer_data | read | Retrieve cost data from AWS Cost Explorer. Use this data to analyze spending patterns and provide AWS Well-Architected Framework Cost Optimization pillar recommendations. |
get_management_trails | read | Get CloudTrail management trails. Provide Well-Architected recommendations for Security and Operational Excellence. |
get_performance_insights_metrics | read | Get Performance Insights metrics for an RDS instance. Provide Well-Architected recommendations for Performance Efficiency and Cost Optimization. |
get_trusted_advisor_checks | read | Get AWS Trusted Advisor check results. Provide Well-Architected recommendations across all pillars based on findings. |
lambda_optimization | write | Run comprehensive Lambda optimization analysis to identify overprovisioned functions. Use findings to suggest AWS Well-Architected Framework improvements for Cost Optimization (memory sizing), Performance Efficiency (execution time), and Operational Excellence (monitoring) pillars. |
lambda_report | read | Generate detailed Lambda optimization report with cost savings |
lambda_unused | read | Identify unused Lambda functions with minimal invocations. Provide Well-Architected recommendations for Cost Optimization. |
list_coh_enrollment | read | List Cost Optimization Hub enrollment statuses |
nat_gateway_optimization | write | Run comprehensive NAT Gateway optimization analysis to identify underutilized, redundant, and unused NAT Gateways. Provide Well-Architected recommendations for Cost Optimization and Network Architecture. |
nat_gateway_redundant | read | Identify potentially redundant NAT Gateways in the same availability zone. Provide Well-Architected recommendations for Cost Optimization and Reliability. |
nat_gateway_underutilized | write | Identify underutilized NAT Gateways based on data transfer metrics with cost optimization. Provide Well-Architected recommendations for Cost Optimization. |
nat_gateway_unused | read | Identify NAT Gateways that are not referenced by any route tables. Provide Well-Architected recommendations for Cost Optimization. |
query_cloudwatch_analysis_results | read | Query stored CloudWatch analysis results using SQL queries. Provide Well-Architected recommendations based on historical analysis data. |
rds_idle | read | Identify idle RDS instances with minimal activity. Provide Well-Architected recommendations for Cost Optimization. |
rds_optimization | write | Run comprehensive RDS optimization analysis to identify underutilized databases. Analyze findings to provide AWS Well-Architected Framework recommendations for Cost Optimization (right-sizing), Performance Efficiency (instance classes), Reliability (Multi-AZ), and Security (encryption) pillars. |
rds_report | read | Generate detailed RDS optimization report with recommendations |
run_cloudtrail_trails_analysis | write | Run CloudTrail trails analysis for optimization. Provide Well-Architected recommendations for Security, Cost Optimization, and Operational Excellence. |
s3_api_cost_minimization | read | Minimize S3 API request charges through access pattern optimization. Provide Well-Architected recommendations for Cost Optimization and Performance Efficiency. |
s3_archive_optimization | read | Identify and optimize long-term archive data storage for cost reduction. Provide Well-Architected recommendations for Cost Optimization. |
s3_bucket_analysis | read | Analyze specific S3 buckets for optimization opportunities. Provide Well-Architected recommendations for Cost Optimization and Security. |
s3_comprehensive_analysis | write | Run comprehensive S3 cost optimization analysis. Analyze results to provide AWS Well-Architected Framework recommendations for Cost Optimization (storage classes, lifecycle policies), Security (encryption, access controls), and Operational Excellence (monitoring, automation) pillars. |
s3_comprehensive_optimization_tool | write | Run comprehensive S3 optimization with unified tool - executes all 8 functionalities in parallel with intelligent orchestration. Provide holistic Well-Architected recommendations. |
s3_general_spend_analysis | read | Analyze overall S3 spending patterns and usage to identify optimization opportunities. Provide Well-Architected recommendations for Cost Optimization. |
s3_governance_check | read | Implement S3 cost controls and governance policy compliance checking. Provide Well-Architected recommendations for Security and Operational Excellence. |
s3_multipart_cleanup | read | Identify and clean up incomplete multipart uploads to eliminate storage waste. Provide Well-Architected recommendations for Cost Optimization and Operational Excellence. |
s3_storage_class_selection | read | Provide guidance on choosing the most cost-effective storage class for new data. Provide Well-Architected recommendations for Cost Optimization. |
s3_storage_class_validation | read | Validate that existing data is stored in the most appropriate storage class. Provide Well-Architected recommendations for Cost Optimization. |
validate_cloudwatch_cost_preferences | read | Validate CloudWatch cost preferences and get functionality coverage estimates. Provide Well-Architected recommendations for Cost Optimization. |
Trust audit
SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
module = importlib.import_module(module_path)
key_hash = hashlib.md5(key_string.encode()).hexdigest()
return hashlib.md5(key_str.encode()).hexdigest()
sys.path.insert(0, os.path.join(os.path.dirname(__file__), '../../..'))
sys.path.insert(0, os.path.join(os.path.dirname(__file__), '../../..'))
sys.path.insert(0, os.path.join(os.path.dirname(__file__), '../../..'))
sys.path.insert(0, os.path.join(os.path.dirname(__file__), '../../..'))
sys.path.insert(0, os.path.join(os.path.dirname(__file__), '../../..'))
awslabs.mcp-lambda-handler, mcp, boto3, botocore, psutil
boto3, botocore, psutil
Gates applied: no_behavioural_pass.
7dff05b2981bfull audit observations/trust-audit/mcp-server/aws-samples__cfm-tips.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 7dff05b2981b | SAFE | B | 88 | first audit |
Questions
What is the CFM Tips MCP server?
A MCP Server that's built on top of AWS Cloud Financial Management (CFM) Technical Implementation Playbooks (TIPs) - our proven collection of cost optimization best practices
What tools does CFM Tips expose?
54 in total: 40 read-only, 14 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is CFM Tips safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does CFM Tips need?
No credential environment variables were found in its source, so it appears to need none.
How does CFM Tips run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (7dff05b2981b), read on 2026-10-08. The repository is watched and re-audited when it changes.