Atlas / MCP servers / aws-samples / CFM Tips

CFM TipsSAFE

mcp/aws-samples/cfm-tips

A MCP Server that's built on top of AWS Cloud Financial Management (CFM) Technical Implementation Playbooks (TIPs) - our proven collection of cost optimization best practices

Verdict
SAFE
Grade
B
Trust score
88 /100
Exposed tools
54 40r · 14w · 0d
Transport
stdio
License
NOASSERTION
Stars
34
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A comprehensive Model Context Protocol (MCP) server for AWS cost analysis and optimization recommendations, designed to work seamlessly with Kiro CLI and other MCP-compatible clients.

✅ Features

Core AWS Services Integration

  • Cost Explorer - Retrieve cost data and usage metrics
  • Cost Optimization Hub - Get AWS cost optimization recommendations
  • Compute Optimizer - Right-sizing recommendations for compute resources
  • Trusted Advisor - Cost optimization checks and recommendations
  • Performance Insights - RDS performance metrics and analysis

Cost Optimization Playbooks

  • 🔧 EC2 Right Sizing - Identify underutilized EC2 instances with 12 specialized analysis tools
  • 💾 EBS Optimization - Find unused and underutilized volumes
  • 🗄️ RDS Optimization - Identify idle and underutilized databases
  • ⚡ Lambda Optimization - Find overprovisioned and unused functions
  • 🪣 S3 Optimization - Comprehensive S3 cost analysis and storage class optimization with 11 specialized tools
  • 📋 CloudTrail Optimization - Analyze and optimize CloudTrail configurations
  • 📊 CloudWatch Optimization - Optimize monitoring costs across logs, metrics, alarms, and dashboards
  • 💰 Database Savings Plans - Analyze and optimize database commitment plans for Aurora, RDS, DynamoDB, and more
  • 🌐 NAT Gateway Optimization - Identify underutilized, redundant, and unused NAT Gateways
  • 📈 Comprehensive Analysis - Multi-service cost analysis

Advanced Features

  • Real CloudWatch Metrics - Uses actual AWS metrics for analysis
  • Multiple Output Formats - JSON and Markdown report generation
  • Cost Calculations - Estimated savings and cost breakdowns
  • Actionable Recommendations - Priority-based optimization suggestions

📁 Project Structure

sample-cfm-tips-mcp/
├── playbooks/                            # CFM Tips optimization playbooks engine
│   ├── ec2/                          
Read from source at commit 7dff05b2981bOBSERVED · 2026-10-08
02

Exposed tools (54)

40 read · 14 write · 0 destructive.

ToolRiskDescription
cloudwatch_alarms_and_dashboards_optimizationwriteRun CloudWatch alarms and dashboards optimization analysis to identify monitoring efficiency improvements. Provide Well-Architected recommendations for Operational Excellence and Cost Optimization.
cloudwatch_comprehensive_optimization_toolwriteRun comprehensive CloudWatch optimization using the unified optimization tool with intelligent orchestration. Returns aggregate summary by default to avoid token overflow. Use detail_level=
cloudwatch_general_spend_analysiswriteRun CloudWatch general spend analysis to understand cost breakdown across logs, metrics, alarms, and dashboards. Provide Well-Architected recommendations for Cost Optimization and Operational Excellence.
cloudwatch_logs_optimizationwriteRun CloudWatch logs optimization analysis to identify log retention and ingestion cost optimization opportunities. Provide Well-Architected recommendations for Cost Optimization and Operational Excellence.
cloudwatch_metrics_optimizationwriteRun CloudWatch metrics optimization analysis to identify custom metrics cost optimization opportunities. Provide Well-Architected recommendations for Cost Optimization and Performance Efficiency.
ebs_optimizationwriteRun comprehensive EBS optimization analysis to identify unused and underutilized volumes. Use results to suggest AWS Well-Architected Framework improvements for Cost Optimization (unused resources), Performance Efficiency (volume types), and Reliability (backup strategies) pillars.
ebs_reportreadGenerate detailed EBS optimization report with cost savings
ebs_unusedreadIdentify unused EBS volumes that can be deleted. Provide Well-Architected recommendations for Cost Optimization.
ec2_burstable_analysisreadAnalyze burstable instances for credit usage optimization. Provide Well-Architected recommendations for Performance Efficiency and Cost Optimization.
ec2_commitment_plansreadAnalyze instances for Reserved Instance and Savings Plans opportunities. Provide Well-Architected recommendations for Cost Optimization.
ec2_comprehensive_reportreadGenerate comprehensive EC2 optimization report covering all playbooks. Provide holistic Well-Architected recommendations across all pillars.
ec2_detailed_monitoringreadIdentify instances without detailed monitoring enabled. Provide Well-Architected recommendations for Operational Excellence.
ec2_governance_violationsreadDetect EC2 governance violations and policy non-compliance. Provide Well-Architected recommendations for Security and Operational Excellence.
ec2_graviton_compatiblereadIdentify instances compatible with Graviton processors. Provide Well-Architected recommendations for Cost Optimization and Performance Efficiency.
ec2_old_generationreadIdentify old generation EC2 instances that should be upgraded. Provide Well-Architected recommendations for Performance Efficiency and Cost Optimization.
ec2_reportreadGenerate detailed EC2 right-sizing report with recommendations
ec2_rightsizingwriteRun comprehensive EC2 right-sizing analysis to identify underutilized instances. Based on findings, provide AWS Well-Architected Framework recommendations for Cost Optimization (right-sizing), Performance Efficiency (instance types), and Reliability (availability zones) pillars.
ec2_scheduling_opportunitiesreadIdentify instances suitable for scheduling optimization. Provide Well-Architected recommendations for Cost Optimization and Operational Excellence.
ec2_spot_opportunitiesreadIdentify instances suitable for Spot pricing. Provide Well-Architected recommendations for Cost Optimization and Reliability.
ec2_stopped_instancesreadIdentify stopped EC2 instances that could be terminated. Provide Well-Architected recommendations for Cost Optimization and Operational Excellence.
ec2_unattached_eipsreadIdentify unattached Elastic IP addresses. Provide Well-Architected recommendations for Cost Optimization.
ec2_unused_reservationsreadIdentify unused On-Demand Capacity Reservations. Provide Well-Architected recommendations for Cost Optimization.
generate_cloudtrail_reportreadGenerate CloudTrail optimization report. Use findings to suggest AWS Well-Architected Framework improvements for Security (logging, monitoring), Operational Excellence (observability), and Cost Optimization (log retention) pillars.
get_cloudwatch_cost_estimatereadGet detailed cost estimate for CloudWatch optimization analysis based on enabled features. Provide Well-Architected recommendations for Cost Optimization.
get_coh_recommendationsreadGet cost optimization recommendations from AWS Cost Optimization Hub. Analyze these recommendations and provide additional AWS Well-Architected Framework insights for Cost Optimization, Performance Efficiency, and Operational Excellence pillars.
get_compute_optimizer_recommendationsreadGet recommendations from AWS Compute Optimizer. Use these findings to suggest AWS Well-Architected Framework improvements for Performance Efficiency, Cost Optimization, and Reliability pillars.
get_cost_explorer_datareadRetrieve cost data from AWS Cost Explorer. Use this data to analyze spending patterns and provide AWS Well-Architected Framework Cost Optimization pillar recommendations.
get_management_trailsreadGet CloudTrail management trails. Provide Well-Architected recommendations for Security and Operational Excellence.
get_performance_insights_metricsreadGet Performance Insights metrics for an RDS instance. Provide Well-Architected recommendations for Performance Efficiency and Cost Optimization.
get_trusted_advisor_checksreadGet AWS Trusted Advisor check results. Provide Well-Architected recommendations across all pillars based on findings.
lambda_optimizationwriteRun comprehensive Lambda optimization analysis to identify overprovisioned functions. Use findings to suggest AWS Well-Architected Framework improvements for Cost Optimization (memory sizing), Performance Efficiency (execution time), and Operational Excellence (monitoring) pillars.
lambda_reportreadGenerate detailed Lambda optimization report with cost savings
lambda_unusedreadIdentify unused Lambda functions with minimal invocations. Provide Well-Architected recommendations for Cost Optimization.
list_coh_enrollmentreadList Cost Optimization Hub enrollment statuses
nat_gateway_optimizationwriteRun comprehensive NAT Gateway optimization analysis to identify underutilized, redundant, and unused NAT Gateways. Provide Well-Architected recommendations for Cost Optimization and Network Architecture.
nat_gateway_redundantreadIdentify potentially redundant NAT Gateways in the same availability zone. Provide Well-Architected recommendations for Cost Optimization and Reliability.
nat_gateway_underutilizedwriteIdentify underutilized NAT Gateways based on data transfer metrics with cost optimization. Provide Well-Architected recommendations for Cost Optimization.
nat_gateway_unusedreadIdentify NAT Gateways that are not referenced by any route tables. Provide Well-Architected recommendations for Cost Optimization.
query_cloudwatch_analysis_resultsreadQuery stored CloudWatch analysis results using SQL queries. Provide Well-Architected recommendations based on historical analysis data.
rds_idlereadIdentify idle RDS instances with minimal activity. Provide Well-Architected recommendations for Cost Optimization.
rds_optimizationwriteRun comprehensive RDS optimization analysis to identify underutilized databases. Analyze findings to provide AWS Well-Architected Framework recommendations for Cost Optimization (right-sizing), Performance Efficiency (instance classes), Reliability (Multi-AZ), and Security (encryption) pillars.
rds_reportreadGenerate detailed RDS optimization report with recommendations
run_cloudtrail_trails_analysiswriteRun CloudTrail trails analysis for optimization. Provide Well-Architected recommendations for Security, Cost Optimization, and Operational Excellence.
s3_api_cost_minimizationreadMinimize S3 API request charges through access pattern optimization. Provide Well-Architected recommendations for Cost Optimization and Performance Efficiency.
s3_archive_optimizationreadIdentify and optimize long-term archive data storage for cost reduction. Provide Well-Architected recommendations for Cost Optimization.
s3_bucket_analysisreadAnalyze specific S3 buckets for optimization opportunities. Provide Well-Architected recommendations for Cost Optimization and Security.
s3_comprehensive_analysiswriteRun comprehensive S3 cost optimization analysis. Analyze results to provide AWS Well-Architected Framework recommendations for Cost Optimization (storage classes, lifecycle policies), Security (encryption, access controls), and Operational Excellence (monitoring, automation) pillars.
s3_comprehensive_optimization_toolwriteRun comprehensive S3 optimization with unified tool - executes all 8 functionalities in parallel with intelligent orchestration. Provide holistic Well-Architected recommendations.
s3_general_spend_analysisreadAnalyze overall S3 spending patterns and usage to identify optimization opportunities. Provide Well-Architected recommendations for Cost Optimization.
s3_governance_checkreadImplement S3 cost controls and governance policy compliance checking. Provide Well-Architected recommendations for Security and Operational Excellence.
s3_multipart_cleanupreadIdentify and clean up incomplete multipart uploads to eliminate storage waste. Provide Well-Architected recommendations for Cost Optimization and Operational Excellence.
s3_storage_class_selectionreadProvide guidance on choosing the most cost-effective storage class for new data. Provide Well-Architected recommendations for Cost Optimization.
s3_storage_class_validationreadValidate that existing data is stored in the most appropriate storage class. Provide Well-Architected recommendations for Cost Optimization.
validate_cloudwatch_cost_preferencesreadValidate CloudWatch cost preferences and get functionality coverage estimates. Provide Well-Architected recommendations for Cost Optimization.
03

Trust audit

SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
playbooks/cloudwatch/analysis_engine.py:287
module = importlib.import_module(module_path)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
utils/cache_decorator.py:153
key_hash = hashlib.md5(key_string.encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
utils/intelligent_cache.py:156
return hashlib.md5(key_str.encode()).hexdigest()
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/cloudwatch/test_cloudwatch_integration.py:13
sys.path.insert(0, os.path.join(os.path.dirname(__file__), '../../..'))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/performance/cloudwatch/test_cloudwatch_performance.py:10
sys.path.insert(0, os.path.join(os.path.dirname(__file__), '../../..'))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/cloudwatch/test_cloudwatch_api_mocking.py:15
sys.path.insert(0, os.path.join(os.path.dirname(__file__), '../../..'))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/cloudwatch/test_cloudwatch_metrics_pagination.py:12
sys.path.insert(0, os.path.join(os.path.dirname(__file__), '../../..'))
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/cloudwatch/test_cloudwatch_pagination_comprehensive.py:22
sys.path.insert(0, os.path.join(os.path.dirname(__file__), '../../..'))
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
remote-deployment/requirements.txt
awslabs.mcp-lambda-handler, mcp, boto3, botocore, psutil
Why it matters. 5 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
boto3, botocore, psutil
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 7dff05b2981bfull audit observations/trust-audit/mcp-server/aws-samples__cfm-tips.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-087dff05b2981bSAFEB88first audit
05

Questions

What is the CFM Tips MCP server?

A MCP Server that's built on top of AWS Cloud Financial Management (CFM) Technical Implementation Playbooks (TIPs) - our proven collection of cost optimization best practices

What tools does CFM Tips expose?

54 in total: 40 read-only, 14 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is CFM Tips safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does CFM Tips need?

No credential environment variables were found in its source, so it appears to need none.

How does CFM Tips run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (7dff05b2981b), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement