Atlas / MCP servers / lokeswaran-aj / AWS

AWSSAFE

mcp/lokeswaran-aj/aws-4

An MCP(Model Context Protocol) Server for AWS services

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
54 21r · 20w · 13d
Transport
—
License
MIT
Stars
27
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

🎬 Demo

See it in action! Here's how easy it is to spin up a full-blown EC2 setup — VPC, subnets, security groups, this works — all through natural language prompts to an AI Model Context Protocol (MCP) server.

✨ Features

Currently supports

  1. RDS
  2. S3
  3. EC2
  4. VPC
  5. Subnet
  6. Internet Gateway
  7. Route Table
  8. Security Group
  9. Key Pair
  10. Instance Tag
  11. AMI

More AWS services (like Lambda, API Gateway, etc.) coming soon! Contributions welcome 🚀

📋 Prerequisites

For Development:

  • Node.js >= 18.0.0
  • pnpm >= 10.0.0

For Docker Deployment:

  • Docker and Docker Compose

For Both:

  • AWS Account with AWS credentials (Access Key ID and Secret Access Key)

⚙️ Developer Setup

1. Clone the repo

git clone https://github.com/lokeswaran-aj/aws-mcp.git
cd aws-mcp
❗️Currently, the server reads credentials from MCP configuration headers. In future versions, we'll support AWS Role ARN.

2. Install dependencies

pnpm install
💡 Make sure you have pnpm installed globally. If not: ``bash npm install -g pnpm ``

3. Run the dev server

pnpm dev

🐳 Docker Deployment

Quick Start with Docker

Option 1: Using Docker Compose (Recommended)

docker-compose up -d

Option 2: Using Docker directly

# Build the image
docker build -t aws-mcp .

# Run with port mapping
docker run -d --name aws-mcp-server -p 8080:8080 aws-mcp

The server will be available at:

  • MCP HTTP Stream: http://localhost:8080/mcp
  • MCP SSE: http://localhost:8080/sse

Managing Docker Containers

# View logs
docker-compose logs -f

# Stop container
docker-compose down

# Rebuild and restart
docker-compose build --no-cache 
Read from source at commit 252a9af0df03OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add aws-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "aws-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (54)

21 read · 20 write · 13 destructive. Blast radius: 13 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
associate-route-tablereadAssociate a route table with a subnet or internet gateway or virtual private gateway
attach-internet-gatewayreadAttach an internet gateway to a VPC
authorize-security-group-egressreadAuthorize a security group egress in the given region
authorize-security-group-ingressreadAuthorize a security group ingress in the given region
create-amiwriteCreate an AMI
create-bucketwriteCreate a new S3 bucket in the given region
create-db-instancewriteCreate a new RDS DB instance in the given region
create-instance-tagwriteCreate instance tag
create-internet-gatewaywriteCreate a new internet gateway in the given region
create-key-pairwriteCreate a key pair in the given region
create-route-tablewriteCreate a route table in the given region
create-security-groupwriteCreate a security group in the given region
create-subnetwriteCreate a subnet in the given region
create-vpcwriteCreate a new VPC in the given region
delete-amidestructiveDelete an AMI
delete-bucketdestructiveDelete an S3 bucket in the given region
delete-db-instancedestructiveDelete a given RDS DB instance in the given region
delete-instance-tagdestructiveDelete instance tag
delete-internet-gatewaydestructiveDelete an internet gateway by ID in the given region
delete-key-pairdestructiveDelete a key pair in the given region
delete-route-tabledestructiveDelete a route table in the given region
delete-security-groupdestructiveDelete a security group in the given region
delete-subnetdestructiveDelete a subnet by subnet ID in the given region
delete-vpcdestructiveDelete a VPC by VPC ID in the given region
detach-internet-gatewayreadDetach an internet gateway from a VPC
disassociate-route-tablereadDisassociate a route table from a subnet or internet gateway or virtual private gateway
import-key-pairwriteImport a key pair in the given region
launch-ec2-instancereadLaunch an EC2 instance in a given region
list-amisreadList AMIs
list-bucketsreadList all the S3 buckets in the given region
list-db-instancesreadList all the RDS DB instances in the given region
list-ec2-instancesreadList EC2 instances in a given region
list-instance-tagsreadList instance tags
list-internet-gatewaysreadList all internet gateways in the given region
list-key-pairsreadList key pairs in the given region
list-route-tablesreadList route tables in the given region
list-security-group-rulesreadList all security group rules in the given region
list-security-groupsreadList all security groups in the given region
list-subnetsreadList all the subnets in the given region
list-vpcsreadList all the VPCs in the given region
modify-security-group-ruleswriteModify a security group rule in the given region
reboot-ec2-instancereadReboot an EC2 instance in a given region
replace-route-table-associationreadReplace the route table association for a subnet or internet gateway or virtual private gateway
revoke-security-group-egressdestructiveRevoke a security group egress in the given region
revoke-security-group-ingressdestructiveRevoke a security group ingress in the given region
start-ec2-instancewriteStart an EC2 instance in a given region
stop-ec2-instancewriteStop an EC2 instance in a given region
terminate-ec2-instancedestructiveTerminate an EC2 instance in a given region
update-db-instancewriteUpdate a given RDS DB instance in the given region
update-security-group-rule-descriptions-egresswriteUpdate the description of a security group rule egress in the given region
update-security-group-rule-descriptions-ingresswriteUpdate the description of a security group rule ingress in the given region
update-subnet-attributewriteUpdate a subnet attributes by subnet ID in the given region
update-vpc-attributewriteUpdate a VPC attribute(EnableDnsHostnames, EnableDnsSupport, EnableNetworkAddressUsageMetrics) by VPC ID in the given region
update-vpc-endpointwriteUpdate a VPC endpoint(Gateway endpoint, Interface endpoint) by VPC endpoint ID in the given region
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete-ami, delete-bucket, delete-db-instance, delete-instance-tag, delete-internet-gateway, delete-key-pair, delete-route-table, delete-security-group, delete-subnet, delete-vpc, revoke-security-grou
Why it matters. 13 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/ec2/handler.ts:21
} from "../../schema/ec2";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@aws-sdk/client-ec2, @aws-sdk/client-rds, @aws-sdk/client-s3, @modelcontextprotocol/sdk, dotenv, fastmcp, zod, @eslint/js
Why it matters. 22 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
assets/demo.gif
assets/demo.gif
Why it matters. 41468586 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 252a9af0df03full audit observations/trust-audit/mcp-server/lokeswaran-aj__aws-4.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08252a9af0df03SAFEB89first audit
06

Questions

What is the AWS MCP server?

An MCP(Model Context Protocol) Server for AWS services

What tools does AWS expose?

54 in total: 21 read-only, 20 that write, and 13 that can delete or overwrite (delete-ami, delete-bucket, delete-db-instance, delete-instance-tag, delete-internet-gateway). Every one is listed on this page with its risk.

Is AWS safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 13 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does AWS need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (252a9af0df03), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement