cloud-pathfinder
Server Details
IaC attack-path auditor: finds internet-to-crown-jewel chains in Terraform/CFN/K8s.
Glama couldn't complete the latest health check. If this server requires authentication, missing or expired test credentials may be the cause. A test profile lets Glama authenticate for health checks and discover tools; it is separate from your personal connections.
If you are the author, claim ownership, then add or update a test profile under Admin → Test Profile.
- Status
- Unhealthy
- Uptime
- 0.0% over 48 days
- Last Tested
- Transport
- Streamable HTTP
- URL
- Repository
- Baneado98/cloud-pathfinder
- GitHub Stars
- 0
- Server Listing
- cloud-pathfinder
TDQS
Scored across 2 tools
The two tools have clearly distinct purposes: one analyzes a single IaC state for attack paths, while the other compares two states to detect changes in attack surface. There is no overlap.
Both tools follow a consistent verb_noun pattern (audit_attack_paths, diff_attack_paths) using snake_case, making the naming predictable and clear.
With only 2 tools, the server is slightly minimal but each tool provides essential functionality for the domain. It falls at the low end of the typical range but still earns its place.
The server covers the core workflows of static IaC attack-path analysis (single-state audit and differential comparison). Minor gaps exist, such as lack of support for other IaC providers or more granular query tools, but the main use cases are addressed.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
2 tool updates
- First observed
audit_iac_attack_paths - First observed
diff_attack_paths
Related MCP Connectors
- ZopDev MCPOAuthdev.zop
Cloud cost, inventory and governance on AWS/Azure/GCP. Read-only by default, optional scoped writes
Discover exposed assets, leaked secrets, APIs & client-side vulns across your attack surface
Unified API to query AWS, GCP, Azure and generate Terraform/CLI execution kits for AI agents.
Audit GitHub repos for malicious and supply-chain code before you depend on them.
Related MCP Servers
- AlicenseAqualityCmaintenanceA local-first AWS security tool that uses graph theory to discover attack paths (e.g., Internet → Role → DB) and prioritize remediations. It allows agents to perform read-only security audits and generate Terraform fixes without data exfiltration.1562 PyPI4Apache 2.0
- AlicenseAqualityAmaintenanceRead-only attack-path tools for cloud and Kubernetes: list the reachable routes from internet exposure to sensitive assets, explain each hop and the evidence behind it, and simulate a fix before recommending it. Connects to a running PerspectiveGraph engine.5088Apache 2.0
- FlicenseNot gradedqualityAmaintenanceEnables auditors to scan cloud IAM policies for privilege-escalation paths, wildcards, and risky grants directly within Cursor or Claude Code, using a deterministic rule engine that runs entirely on local infrastructure.1-
- FlicenseNot gradedqualityBmaintenanceEnables AI to scan AWS accounts, analyze attack paths, and verify security fixes on a read-only graph of cloud resources.4-
Glama MCP Gateway
Add one secure layer between your agents and this server.