Skip to main content
Glama

Server Details

IaC attack-path auditor: finds internet-to-crown-jewel chains in Terraform/CFN/K8s.

Glama couldn't complete the latest health check. If this server requires authentication, missing or expired test credentials may be the cause. A test profile lets Glama authenticate for health checks and discover tools; it is separate from your personal connections.

If you are the author, claim ownership, then add or update a test profile under Admin → Test Profile.

Status
Unhealthy
Uptime
0.0% over 48 days
Last Tested
Transport
Streamable HTTP
URL
Repository
Baneado98/cloud-pathfinder
GitHub Stars
0
Server Listing
cloud-pathfinder

TDQS

A4.6/5.0

Scored across 2 tools

Disambiguation5/5

The two tools have clearly distinct purposes: one analyzes a single IaC state for attack paths, while the other compares two states to detect changes in attack surface. There is no overlap.

Naming Consistency5/5

Both tools follow a consistent verb_noun pattern (audit_attack_paths, diff_attack_paths) using snake_case, making the naming predictable and clear.

Tool Count4/5

With only 2 tools, the server is slightly minimal but each tool provides essential functionality for the domain. It falls at the low end of the typical range but still earns its place.

Completeness4/5

The server covers the core workflows of static IaC attack-path analysis (single-state audit and differential comparison). Minor gaps exist, such as lack of support for other IaC providers or more granular query tools, but the main use cases are addressed.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections.

  1. 2 tool updates
    • First observedaudit_iac_attack_paths
    • First observeddiff_attack_paths

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    C
    maintenance
    A local-first AWS security tool that uses graph theory to discover attack paths (e.g., Internet → Role → DB) and prioritize remediations. It allows agents to perform read-only security audits and generate Terraform fixes without data exfiltration.
    15
    62 PyPI
    4
    Apache 2.0
  • A
    license
    A
    quality
    A
    maintenance
    Read-only attack-path tools for cloud and Kubernetes: list the reachable routes from internet exposure to sensitive assets, explain each hop and the evidence behind it, and simulate a fix before recommending it. Connects to a running PerspectiveGraph engine.
    50
    8
    8
    Apache 2.0
Try in Browser

Glama MCP Gateway

Add one secure layer between your agents and this server.