Atlas / MCP servers / kuudoai / Amazon Ads

Amazon AdsCAUTION

mcp/kuudoai/amazon-ads-1

Amazon Ads MCP - Model Context Protocol server for Amazon Advertising API

Verdict
CAUTION
Grade
D
Trust score
60 /100
Exposed tools
16 14r · 1w · 1d
Transport
streamable-http
License
MIT
Stars
72
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Build AI-powered advertising applications with the Model Context Protocol (MCP) SDK for Amazon Advertising API

Made with ❤️ + ☕ by [Openbridge](https://www.openbridge.com/)

[](https://www.python.org/downloads/) [](https://opensource.org/licenses/MIT) [](https://github.com/KuudoAI/amazonadsmcp/actions/workflows/ci.yml)

MCP registry id (for clients and catalogs that display a stable package name): io.github.KuudoAI/amazon_ads_mcp

Table of contents

  • Where this fits in Kuudo
  • What are MCP tools?
  • What is Amazon Ads API MCP SDK?
  • Quick start
  • Installation
  • Configuration (auth, packages, profiles, regions)
  • Downloading reports and exports
  • Example MCP client (Claude Desktop)
  • Context limits
  • Code mode
  • Tool audit
  • Background tasks
  • Frequently asked
  • Troubleshooting
  • Documentation map

Where this fits in Kuudo

This repository is the tool layer of a broader Amazon agent platform. Kuudo gives Amazon agents tools, knowledge, workflows, and a place to work. This repository is the tools.

Read from source at commit b8317dc3160cOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add amazon-ads-mcp --env AMAZON_ADS_AUTH_METHOD=${AMAZON_ADS_AUTH_METHOD} --env AMAZON_ADS_DOWNLOAD_AUTH_TOKEN=${AMAZON_ADS_DOWNLOAD_AUTH_TOKEN} --env AMAZON_ADS_ENCRYPTION_KEY=${AMAZON_ADS_ENCRYPTION_KEY} --env AMAZON_ADS_TOKEN_PERSIST=${AMAZON_ADS_TOKEN_PERSIST} -- uvx amazon-ads-mcp
claude-desktop
{
  "mcpServers": {
    "amazon-ads-mcp": {
      "command": "uvx",
      "args": [
        "amazon-ads-mcp"
      ],
      "env": {
        "AMAZON_ADS_AUTH_METHOD": "${AMAZON_ADS_AUTH_METHOD}",
        "AMAZON_ADS_DOWNLOAD_AUTH_TOKEN": "${AMAZON_ADS_DOWNLOAD_AUTH_TOKEN}",
        "AMAZON_ADS_ENCRYPTION_KEY": "${AMAZON_ADS_ENCRYPTION_KEY}",
        "AMAZON_ADS_TOKEN_PERSIST": "${AMAZON_ADS_TOKEN_PERSIST}"
      }
    }
  }
}
03

Exposed tools (16)

14 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
check_oauth_statusreadCheck OAuth authentication status.
clear_oauth_tokensdestructiveClear OAuth tokens.
constrained_toolreadreturn {
dummy_toolreadreturn {
echoreadset_last_http_meta(
enum_toolreadreturn {
get_regionreadGet the current region.
list_downloadsreadList downloaded files for the active profile.
list_identitiesreadList all available identities.
list_regionsreadList available regions.
page_profilesread# Echo the values the function actually received so the test can
refresh_oauth_tokenreadRefresh OAuth access token.
select_profilereadInteractively select an Amazon Ads profile.
start_oauth_flowwriteStart the OAuth authorization flow.
test_QueryCampaignreadreturn {
test_samplingreadTest the native MCP sampling functionality.
04

Trust audit

CAUTIONgrade D · trust 60/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (8 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (25)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/amazon_ads_mcp/middleware/authentication.py:309
>>> print(f"Retrieved token: {token is not None}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/amazon_ads_mcp/middleware/authentication.py:929
self.logger.debug(f"Extracted token (length: {len(token)}, type: JWT)")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/amazon_ads_mcp/middleware/authentication.py:1082
self.logger.debug(f"Validating JWT token (length: {len(token)})")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/amazon_ads_mcp/middleware/authentication.py:1157
self.logger.error(f"Original token: {sanitize_string(token)}")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
Dockerfile:144
sys.exit(0 if urllib.request.urlopen(f'http://127.0.0.1:{port}/health', timeout=4).status == 200 else 1)" \
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/amazon_ads_mcp/tool_audit/audit.py:274
default="http://127.0.0.1:9080/mcp",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/test_inbound_auth.py:105
token = "sk_test_client_supplied"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/test_inbound_auth.py:281
token = "sk_test_client_supplied"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/test_kuudo_provider.py:265
api_key="client-supplied-token",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/test_kuudo_provider.py:288
api_key="client-supplied-token",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/unit/test_kuudo_provider.py:308
api_key = "client-supplied-token"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_oauth_tokens
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/unit/test_session_state_probe.py:374
module = importlib.import_module(module_path)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_download_paths.py:62
for bad in ("../escape.csv", "a/../../escape.csv", "..\\escape"):
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_download_paths.py:120
"../../outside.csv", profile_id=profile_id
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_download_tools.py:149
for bad in ("../escape.csv", "/etc/passwd", "a/../../escape.csv"):
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_security_helpers.py:240
out = sanitize_filename("../../etc/passwd")
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/unit/test_download_url_security.py:31
(socket.AF_INET, socket.SOCK_STREAM, 6, "", ("169.254.169.254", 443))
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/unit/test_ssrf_guard.py:25
return [(socket.AF_INET, socket.SOCK_STREAM, 0, "", ("169.254.169.254", 0))]
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/unit/test_ssrf_guard.py:64
"https://169.254.169.254/latest/meta-data/",
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:898
--url http://127.0.0.1:9080/mcp \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:906
--url http://127.0.0.1:9080/mcp \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:918
--url http://127.0.0.1:9080/mcp \
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/amazon_ads_mcp/auth/token_store.py:718
encrypted_bytes = base64.b64decode(encrypted_b64)

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha b8317dc3160cfull audit observations/trust-audit/mcp-server/kuudoai__amazon-ads-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b8317dc3160cCAUTIOND60first audit
06

Questions

What is the Amazon Ads MCP server?

Amazon Ads MCP - Model Context Protocol server for Amazon Advertising API

What tools does Amazon Ads expose?

16 in total: 14 read-only, 1 that write, and 1 that can delete or overwrite (clear_oauth_tokens). Every one is listed on this page with its risk.

Is Amazon Ads safe to connect to an agent?

With care. The audit graded it D (60/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Amazon Ads need?

It reads AMAZON_ADS_AUTH_METHOD, AMAZON_ADS_DOWNLOAD_AUTH_TOKEN, AMAZON_ADS_ENCRYPTION_KEY, AMAZON_ADS_TOKEN_PERSIST, AMAZON_AD_API_CLIENT_SECRET, AMAZON_AD_API_REFRESH_TOKEN, AUTH0_CLIENT_ID, AUTH0_DOMAIN, AUTH_ENABLED, AUTH_METHOD, DOWNLOAD_AUTH_TOKEN and JSON_API_TOKEN_TYPE_NAME from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Amazon Ads run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as amazon-ads-mcp.

How current is this page?

The grade is for one exact copy of the source (b8317dc3160c), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement