Mmcp.market

cloud-audit MCP server

by gebalamariusz·io.github.gebalamariusz/cloud-audit·v2.0.1·72 stars

AWS security scanner with attack chain detection, IAM privilege escalation, and fixes

A92/100grade A
What users say
No reviews yet
Be the first
Safety scan
A92/100

full report

Adoption
Established

72 stars147 downloads/wk

Reviews

Write one

Nobody has reviewed cloud-audit yet.

If you have run it, two minutes of your experience saves the next person an afternoon.

cloud-audit tools (6, 1 write)

write = sends, deletes, buys or posts

Read from the package source without running it. The installed server may list more.

  • get_attack_chains

    Get all detected attack chains from the last scan.

  • get_findings

    Get findings from the last scan, optionally filtered.

  • get_health_score

    Get the current health score and risk exposure summary.

  • get_remediation

    Get remediation details (CLI command + Terraform code) for a specific check.

  • list_checks

    List all available security checks (no AWS credentials needed).

  • scan_awswrite action

    Run an AWS security scan and return a summary.

Public scan report

scanner v0.1.9 · 2026-09-27 · same rubric, same numbers if you re-run it

no findings
  • Code scan63 source files scanned25/25
  • –Live reliabilityno gateway calls yet and no remote to proben/a
  • –Tool poisoningtools not inspected (local package is not executed); not countedn/a
  • Auth qualitylocal package, no credentials required12/15
  • Maintenancelast push 6 days ago15/15
  • Maintainer identityregistry namespace matches repository owner; GitHub account older than a year8/10
Overall 92/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON

Install cloud-audit in Claude Code, Cursor or VS Code

claude mcp add cloud-audit -- uvx cloud-audit
Add to Cursor

What the publisher says

From the cloud-audit repository's README, as published. We do not edit it. Read it on GitHub

<!-- mcp-name: io.github.gebalamariusz/cloud-audit --> cloud-audit

English | 简体中文

What can a hijacked AI agent reach in your AWS account, and can you prove it?

Open-source, read-only AWS security scanner. 110 checks, 64 IAM privilege-escalation methods, 31 attack-chain rules, blast radius for any resource, and agent-blast for Bedrock Agents and AgentCore: what a prompt-injected or credential-stolen agent can reach, with the IAM policy simulator as the witness. Every finding ships an AWS CLI + Terraform fix. Nothing is written to your account.

30-second demo - agent-blast - Full scan - What's inside - Proof Mode - Installation - Documentation

Thirty seconds, no AWS account needed

pip install cloud-audit

cloud-audit agent-blast --demo          # a hijacked Bedrock Agent, two threat models, one screen
cloud-audit demo --save demo.json       # a full sample scan, then explore it offline:
cloud-audit blast-radius --report demo.json --resource arn:aws:iam::123456789012:role/support-bot-ticket-role
cloud-audit simulate     --report demo.json --fix aws-iam-018
cloud-audit exposure     --report demo.json

The sample account is invented. Everything derived from it (attack chains, root causes, breach cost, security graph, agent reach) is produced by the same engines a real scan uses.

With credentials, the real thing is one command and read-only. The AWS-managed SecurityAudit policy covers every check (permissions):

cloud-audit scan                         # default profile and region
cloud-audit scan --verify                # plus IAM policy-simulator proof for escalation paths
cloud-audit agent-blast --verify         # then: what your agents can reach, simulator-confirmed

agent-blast: what a hijacked AI agent can reach

An AI agent in AWS is a bundle of IAM identities: the role the agent runs as, the execution roles of the Lambda functions behind its tools, the roles of its knowledge bases, gateways and sandboxes. When the agent is hijacked, the attacker acts with those identities. agent-blast answers what that means, per agent, under two threat models:

Shortened. The full README is on GitHub.

Nothing above is checked by us. What we check is on the safety report.

cloud-audit: common questions

Is cloud-audit MCP server safe?
Yes, by our scan: it is graded A (92/100). Read the cloud-audit safety report
How do I install cloud-audit?
It runs on your machine. Copy the Claude Code, Cursor, VS Code or Claude Desktop config from the install section.
Does cloud-audit need an API key?
Not as far as the registry entry and our scan can tell: no credentials are declared or required.
Is cloud-audit maintained?
The last commit was 6 days ago (2026-09-22). The latest release is v2.0.1.
What can I use instead of cloud-audit?
Servers from other publishers that do the same job: Observatory MCP server, Emfirge MCP server and TerraVision MCP server. Compare all cloud-audit alternatives.

Alternatives to cloud-audit

Same job from other publishers: the closest match first, then the best rated.

All cloud-audit alternatives →
  • Observatory
    MCP security scanner. CI-native testing, attack simulation, health scoring, and SARIF.
    B
  • Emfirge
    Git branch for your cloud. Understand AWS risk, prove fixes, and ship safer changes.
    A
  • TerraVision
    Cloud architecture diagrams with official AWS, Azure and GCP icons, from Terraform or a JSON graph.
    A
  • Cloud FinOps Skill & MCP
    Cloud cost + FinOps knowledge for AI agents: AWS/Azure/GCP optimisation, AI spend, waste playbooks.
    B
  • nable
    Local-first FinOps copilot: ask AWS, Azure, GCP, Kubernetes and SaaS cost questions in your editor.
    A

More from gebalamariusz →