Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI โ†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE โ†— (opens in a new tab)
  • llms.txt โ†— (opens in a new tab)
  • Catalog JSON โ†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub โ†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
ยฉ 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. ๐Ÿ”’ Security
  3. Cloud Audit
Cloud Audit logo
Health: ActiveRecent health check succeeded.Last checked 9/9/2026, 6:02:44 PM

Cloud Audit

User RatingsBe the first to rate and review this MCP server!
View Repository72 GitHub StarsTotal stargazers on GitHub for the source repository (72 stars).Visit Website

Open-source read-only AWS security scanner detecting attack chains with remediation via CLI and Terraform.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent โ€” or use 1-click editor setup below.

Add to CursorAdd to VS Code
Not yet automatically verified

We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag โ€” we're steadily working through the catalog.

Manual Client & Custom JSON ConfigExpand JSON โ–พ

Client Config & Setup

Choose your client or environment
Target File:~/Library/Application Support/Claude/claude_desktop_config.json
claude_desktop_config.json
{
  "mcpServers": {
    "gebalamariusz-cloud-audit": {
      "command": "uvx",
      "args": [
        "--from"
      ]
    }
  }
}

๐Ÿ’ก Paste the JSON block into your client's configuration file under mcpServers, then restart the application.

Install Directory Badge Claim listing Alternatives๐Ÿ”’ More in Security

Overview

This tool scans AWS environments to identify security issues and correlates them into attack chains, highlighting privilege escalation paths and exposure risks. It ranks root-cause fixes by impact and provides copy-paste AWS CLI commands and Terraform code for remediation. The scanner operates without agents or infrastructure changes, requiring only read-only AWS permissions.

Use cases

โ€ขDetect AWS attack paths and privilege escalation routes
โ€ขEstimate breach costs and prioritize fixes
โ€ขGenerate remediation plans with CLI and Terraform code
โ€ขVisualize blast radius of compromised resources
โ€ขTrack security posture trends and configuration drift

Key features

โ€ข47 security checks and 16 attack chain detection rules
โ€ขIAM privilege escalation analysis across 64 methods
โ€ขProof mode verifying escalation paths with IAM policy simulator
โ€ขData perimeter checks for resource-policy exposures
โ€ขThreat feed with active-abuse pattern detectors
โ€ขExportable reports in HTML, SARIF, and JSON formats

Capabilities & Tool Schemas

Inspect callable tools, capabilities, and parameters exposed to AI agents by Cloud Audit.

Extracted Tool Capabilities
47 security checks and 16 attack chain detection rules
IAM privilege escalation analysis across 64 methods
Proof mode verifying escalation paths with IAM policy simulator
Data perimeter checks for resource-policy exposures
Threat feed with active-abuse pattern detectors
Exportable reports in HTML, SARIF, and JSON formats

Documentation Overview

cloud-audit logo

cloud-audit

English | ็ฎ€ไฝ“ไธญๆ–‡

What can a hijacked AI agent reach in your AWS account, and can you prove it?

Open-source, read-only AWS security scanner. 110 checks, 64 IAM privilege-escalation methods, 31 attack-chain rules, blast radius for any resource, and agent-blast for Bedrock Agents and AgentCore: what a prompt-injected or credential-stolen agent can reach, with the IAM policy simulator as the witness. Every finding ships an AWS CLI + Terraform fix. Nothing is written to your account.

PyPI version Python versions CI License: MIT Docker Documentation

30-second demo - agent-blast - Full scan - What's inside - Proof Mode - Installation - Documentation

Thirty seconds, no AWS account needed

Terminal
pip install cloud-audit

cloud-audit agent-blast --demo          # a hijacked Bedrock Agent, two threat models, one screen
cloud-audit demo --save demo.json       # a full sample scan, then explore it offline:
cloud-audit blast-radius --report demo.json --resource arn:aws:iam::123456789012:role/support-bot-ticket-role
cloud-audit simulate     --report demo.json --fix aws-iam-018
cloud-audit exposure     --report demo.json

The sample account is invented. Everything derived from it (attack chains, root causes, breach cost, security graph, agent reach) is produced by the same engines a real scan uses.

With credentials, the real thing is one command and read-only. The AWS-managed SecurityAudit policy covers every check (permissions):

bash
cloud-audit scan                         # default profile and region
cloud-audit scan --verify                # plus IAM policy-simulator proof for escalation paths
cloud-audit agent-blast --verify         # then: what your agents can reach, simulator-confirmed

agent-blast: what a hijacked AI agent can reach

An AI agent in AWS is a bundle of IAM identities: the role the agent runs as, the execution roles of the Lambda functions behind its tools, the roles of its knowledge bases, gateways and sandboxes. When the agent is hijacked, the attacker acts with those identities. agent-blast answers what that means, per agent, under two threat models:

Threat modelWhat the attacker hasWhat is in reach
Identity takeoverthe credentials of a role the agent runs as (sandbox escape, metadata-service read, leaked session)the full role: privilege-escalation methods, AssumeRole hops, data
Behaviour takeovernothing but a prompt (indirect prompt injection through a document, a ticket, a web page)what the agent's tools can do, bounded by the tools' own execution roles

Real output for the sample agent (cloud-audit agent-blast --demo -a support-bot):

Code
support-bot (bedrock_agent, eu-central-1)
โ”œโ”€โ”€ A hijacked tool (tool: create-ticket) can escalate to account admin via PassRole+Lambda
โ”œโ”€โ”€ status: PREPARED
โ”œโ”€โ”€ Identity takeover (attacker holds the role's credentials)
โ”‚   โ””โ”€โ”€ support-bot-agent-role arn:aws:iam::123456789012:role/support-bot-agent-role
โ”‚       โ””โ”€โ”€ no escalation path; 3 reach(es) from policy grants, 1 on named resources (see Reach)
โ”‚           (risk 0/100, 1 nodes)
โ”œโ”€โ”€ Behaviour takeover (prompt injection: the agent's tools, their roles)
โ”‚   โ”œโ”€โ”€ search-docs action_group_lambda -> support-bot-search-role
โ”‚   โ”‚   โ”œโ”€โ”€ 3 OpenAPI path(s) in apiSchema; state ENABLED
โ”‚   โ”‚   โ””โ”€โ”€ no escalation path; 4 reach(es) from policy grants, 4 on named resources (see Reach)
โ”‚   โ”œโ”€โ”€ create-ticket action_group_lambda -> support-bot-ticket-role
โ”‚   โ”‚   โ”œโ”€โ”€ 2 function(s) in functionSchema; state ENABLED
โ”‚   โ”‚   โ”œโ”€โ”€ reaches Account Takeover in 1 hop(s) via PassRole+Lambda (risk 72/100)
โ”‚   โ”‚   โ””โ”€โ”€ escalation: PassRole+Lambda
โ”‚   โ””โ”€โ”€ product-docs knowledge_base -> support-bot-kb-role
โ”‚       โ”œโ”€โ”€ 1 S3 data source(s)
โ”‚       โ””โ”€โ”€ no escalation path; 2 reach(es) from policy grants, 2 on named resources (see Reach)
โ”œโ”€โ”€ Reach (13 action/resource pairs)
โ”‚   โ”œโ”€โ”€ tool: search-docs secretsmanager:GetSecretValue on
โ”‚   โ”‚   arn:aws:secretsmanager:eu-central-1:123456789012:secret:prod/db-credentials-Ab12Cd
โ”‚   โ”‚   unverified read secret values
โ”‚   โ”œโ”€โ”€ tool: create-ticket sts:AssumeRole on arn:aws:iam::123456789012:role/ops-admin unverified
โ”‚   โ”‚   assume IAM roles
โ”‚   โ”œโ”€โ”€ tool: create-ticket lambda:InvokeFunction on * unverified invoke Lambda functions
โ”‚   โ”œโ”€โ”€ tool: search-docs s3:PutObject on arn:aws:s3:::company-backups-2024/* unverified write S3
โ”‚   โ”‚   objects
โ”‚   โ”œโ”€โ”€ support-bot-agent-role s3:GetObject on arn:aws:s3:::kb-product-docs/* unverified read the
โ”‚   โ”‚   agent's knowledge base
โ”‚   โ”œโ”€โ”€ tool: search-docs s3:GetObject on arn:aws:s3:::company-backups-2024/* unverified read S3
โ”‚   โ”‚   objects
โ”‚   ...
โ”œโ”€โ”€ Tags
โ”‚   โ”œโ”€โ”€ OWASP Agentic: ASI02 Tool Misuse and Exploitation, ASI03 Identity and Privilege Abuse,
โ”‚   โ”‚   ASI05 Unexpected Code Execution
โ”‚   โ””โ”€โ”€ MITRE ATLAS: AML.T0034 Cost Harvesting, AML.T0040 AI Model Inference API Access, AML.T0053
โ”‚       AI Agent Tool Invocation, AML.T0086 Exfiltration via AI Agent Tool Invocation
โ””โ”€โ”€ Simulated, not executed: identity policies, the attached permissions boundary and SCPs are
    evaluated by the IAM policy simulator; resource-based policies of the targets, RCPs and VPC
    endpoint policies are not. Tool reach is an upper bound set by the tool's role; what the tool
    code does with its inputs is narrower.

The story the output tells: the support bot itself is harmless, but a document that tricks it into calling create-ticket runs code under a role that can pass an admin role to a new Lambda. The search-docs tool, meant to read product docs, can also read the production database secret and write into the backups bucket. Every line names the identity, the action and the resource, so the fix is a policy statement, not a debate.

The same engine covers AgentCore. For the sample gateway (--demo -a tools-gw) the headline is a cross-agent one:

Code
tools-gw (agentcore_gateway, eu-central-1)
โ”œโ”€โ”€ tool: crm-sync can write into agent 'support-bot' knowledge base (RAG poisoning): arn:aws:s3:::kb-product-docs/*
โ”œโ”€โ”€ inbound authorizer: NONE; policy engine: none
...
โ”‚   โ”œโ”€โ”€ tool: crm-sync s3:PutObject on arn:aws:s3:::kb-product-docs/* unverified write into agent
โ”‚   โ”‚   'support-bot' knowledge base (RAG poisoning)
...
โ”œโ”€โ”€ Coverage notes
โ”‚   โ””โ”€โ”€ tool 'erp-mcp' (gateway_target_mcp_server): backend identity unknown, not assessed - remote
โ”‚       MCP server; credential provider: OAUTH

What agent-blast reads (all list/get, no charge):

  • Bedrock Agents: the agent resource role, every action group at the DRAFT version resolved to its Lambda and the Lambda's execution role, knowledge bases resolved to their S3 data-source buckets.
  • AgentCore: runtime role and network mode, gateway role with authorizer, policy engine and every target (Lambda, remote MCP server, API Gateway, OpenAPI, Smithy) with its credential provider, code interpreter and browser execution roles.
  • IAM policies of exactly those identities (inline, attached, group), kept raw: action, resource, effect, whether a Condition is present. Conditions are flagged, never guessed. The simulator decides.

Then, per identity: the 64 privilege-escalation methods, AssumeRole hops through the trust graph, and every data, secret, lateral, code-execution and model-invocation grant matched against concrete resources. A knowledge-base bucket is always a concrete target, even behind s3:* on *, and write access to it is reported as RAG poisoning. Anything the scanner could not read (a denied region, a tool without an IAM identity) is a coverage note, never a silent pass.

--verify asks iam:SimulatePrincipalPolicy about every concrete pair, with the context an attacker really has (no MFA on the session, TLS transport), and marks each reach PROVEN, DENIED (with the policy layer that denied: SCP, permissions boundary) or not asserted. Output formats: tree, json, markdown. The MCP server exposes the same report as get_agent_blast.

A full scan

cloud-audit scan runs 110 read-only checks across 25 AWS services, correlates the findings into attack chains, ranks the fixes by how many chains they break and prices the exposure. This is the sample account (cloud-audit demo), rendered by the same code as a real scan and trimmed for length:

Read the full README โ†’View source on GitHub โ†’

Related MCP Servers

View all in Security View all alternatives
  • Jadx AI MCP logoJadx AI MCP

    JADX-AI-MCP is a plugin and MCP Server for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.

    ๐Ÿ”’ Security3 views
    Compare vs Jadx AI MCP โ†’
  • Apktool MCP Server logoApktool MCP Server

    APKTool MCP Server is a MCP server for the Apk Tool to provide automation in reverse engineering of Android APKs.

    ๐Ÿ”’ Security3 views
    Compare vs Apktool MCP Server โ†’
  • Mobb Vibe Shield MCP logoMobb Vibe Shield MCP

    Mobb Vibe Shield identifies and remediates vulnerabilities in both human and AI-written code, ensuring your applications remain secure without slowing development.

    ๐Ÿ”’ Security2 views
    Compare vs Mobb Vibe Shield MCP โ†’
  • MCP Maigret logoMCP Maigret

    MCP server for maigret, a powerful OSINT tool that collects user account information from various public sources. This server provides tools for searching usernames across social networks and analyzing URLs.

    ๐Ÿ”’ Security4 views
    Compare vs MCP Maigret โ†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks โ€” not a rating.

GitHub stars
72
Stargazers on the source repository.
Last commit
4d ago
Most recent push to the default branch.
Directory activity
1 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet โ€” be the first to share how this listing worked for you.

Frequently Asked Questions about Cloud Audit

No, cloud-audit is read-only and does not write to your AWS account.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewCloud Audit AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/gebalamariusz-cloud-audit?style=directory)](https://allmcps.com/mcp/gebalamariusz-cloud-audit)
HTML Embed
<a href="https://allmcps.com/mcp/gebalamariusz-cloud-audit"><img src="https://allmcps.com/api/badge/gebalamariusz-cloud-audit?style=directory" alt="Cloud Audit on AllMCPs" /></a>

Technical Specs & Signals

Category๐Ÿ”’Security
More technical detailsExpand โ–พ
TransportSTDIO
RuntimePython
Last updatedSep 8, 2026
11/11 checks healthy over the last 34d
Views1
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars72
GitHub Star CountTotal stargazers on GitHub representing community popularity (72 stars).
Last commit4d ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Sep 8, 2026
52Quality signal: Good ยท 52/100How this signal is calculated โ–พ
Server availabilityNot measured

Not scored for repo-hosted servers โ€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools22/30
Adoption & activity7/15
Community engagement0/10

A guidance signal from public completeness & health data โ€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

Supply-chain signal

No high-severity advisories surfaced by our automated scan.

Critical 0High 0Medium 0Low 0

Scanned 28d ago via OSV.dev ยท --from (PyPI)

โ˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server โ†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge โ€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it โ€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in ๐Ÿ”’ Security โ†’Best MCP servers for Security โ†’Alternatives to Cloud Audit โ†’Install in Claude DesktopInstall in CursorInstall in VS Code