aws-mcp-audit (MVP)
A contractor-friendly read-only AWS assessment tool (MCP server) that inventories an AWS environment, runs deterministic security/ops checks, and generates actionable reports plus a cost/usage snapshot.
Quick start (uv)
Claude Desktop (Windows) example config
Put this in %APPDATA%\Claude\claude_desktop_config.json and adjust the directory path:
Tool usage (conceptual)
aws_whoami(auth?)collect_snapshot(scope, auth?) -> snapshot_idrun_checks(snapshot_id) -> finding_set_idcost_signals(snapshot_id)cost_explorer_summary(days=30, auth?)(optional permissions)generate_report(snapshot_id, finding_set_id, format="md|pdf")
Auth
All tools accept an optional auth object:
or (contractor-run):
Outputs
Artifacts are stored locally under ./data/snapshots/<snapshot_id>/:
snapshot.jsonfindings.jsoncost.json(tier-1 signals)cost_explorer.json(if enabled)report.md/report.pdf
Terraform module (client-side)
See terraform/ContractorAuditReadOnly/ for a simple module that creates a read-only role with ExternalId.