{"generated_at":"2026-09-18T12:54:00+00:00","item":{"added_at":"2026-08-05","analysis_method":"capability_triage","category":"Web Connector","description":"Give agents secure access to AWS via MCP","did":"0a14ad3c-54c3-4adf-8a43-90539a225509","homepage_url":"https://aws.amazon.com/products/developer-tools/agent-toolkit-for-aws","icon":"https://a0.awsstatic.com/libra-css/images/logos/aws_logo_smile_179x109.png","id":"0a14ad3c-54c3-4adf-8a43-90539a225509","installs":0,"last_scanned":"","license":"","long_description":"The AWS MCP Server is a managed server that gives agents access to AWS through MCP. Agents can search AWS documentation and retrieve service information without authentication. To execute AWS API calls, run Python scripts in a sandboxed environment, or follow curated skills, agents authenticate through your existing IAM credentials.\n\nAll capabilities are available through a single endpoint with CloudWatch metrics and IAM-based access controls. CloudTrail logs all API calls for audit visibility.","name":"AWS MCP","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=0a14ad3c-54c3-4adf-8a43-90539a225509&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"Amazon Web Services","publisher_url":"https://aws.amazon.com/products/developer-tools/agent-toolkit-for-aws","repository_url":"","risk":"high","risk_severity":"high","security_risks":[{"description":"This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.","evidence":"2 observed tool(s): aws___run_script, [declared description].","remediation":{"block_tool_categories":["code_execution"],"steps":["In the tools list below, turn off any tool tagged Block before connecting this to real data or production systems.","If you need code execution, run it on a separate test machine that has no access to your work files, customer data, or saved passwords.","Limit which websites and services that test machine can talk to."]},"risk_type":"runs_code","severity":"high","title":"Can run commands or queries on your behalf"},{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"Kept High and added private-data access: authenticated aws___call_aws and script execution operate under the user's IAM credentials and can read connected AWS account/resource data; arbitrary script/API execution already requires High.","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"low","title":"Reads your private information"},{"description":"Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.","evidence":"1 observed tool(s): [remote publisher endpoint].","remediation":{"block_tool_categories":[],"steps":["Treat anything you tell this connector as if you sent it directly to the third-party company - because you did.","Check how long that company keeps your data and how to delete it.","Avoid putting health info, customer names, or payment details into this connector unless you have a written agreement with that company."]},"risk_type":"forwards_data_to_third_party","severity":"low","title":"Sends your data to outside companies"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["forwards_data_to_third_party","network_access","reads_private_data","runs_code","web_connector"],"tools":[{"description":"","name":"aws___call_aws"},{"description":"","name":"aws___get_presigned_url"},{"description":"","name":"aws___get_regional_availability"},{"description":"","name":"aws___get_tasks"},{"description":"","name":"aws___list_regions"},{"description":"","name":"aws___read_documentation"},{"description":"","name":"aws___retrieve_skill"},{"description":"","name":"aws___run_script","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and require explicit approval.","why":"Runs arbitrary code, queries, shell commands, or deployment actions with the privileges granted to the connector."}},{"description":"","name":"aws___search_documentation"}],"tools_count":9,"type":"web_connector","url":"https://claude.ai/directory/0a14ad3c-54c3-4adf-8a43-90539a225509","uuid":"b0fe3990-1f5e-5bb3-b6a3-78381def83ed","version":""},"query_key":"amazon web services aws mcp","schema_version":1,"status":"match"}
