Claude security directory

AWS MCP

Published by Amazon Web Services

High risk

The AWS MCP Server is a managed server that gives agents access to AWS through MCP. Agents can search AWS documentation and retrieve service information without authentication. To execute AWS API calls, run Python scripts in a sandboxed environment, or follow curated skills, agents authenticate through your existing IAM credentials. All capabilities are available through a single endpoint with CloudWatch metrics and IAM-based access controls. CloudTrail logs all API calls for audit visibility.

Security assessment

Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.

  • Can run commands or queries on your behalf: This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.
  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.

Available capabilities

This add-on exposes 9 tools or capabilities.

  • aws___call_aws
  • aws___get_presigned_url
  • aws___get_regional_availability
  • aws___get_tasks
  • aws___list_regions
  • aws___read_documentation
  • aws___retrieve_skill
  • aws___run_script
  • aws___search_documentation

The interactive security report will load automatically.