Skip to main content
Glama
YawLabs

@yawlabs/aws-mcp

Official
by YawLabs

aws_call

Destructive

Execute any AWS API operation via the AWS CLI by specifying kebab-case service and operation names and passing parameters as JSON.

Instructions

Run an arbitrary AWS API operation via the aws CLI. Use kebab-case service and operation names as in aws help (service='s3api', operation='list-buckets'). Pass params as a JSON object using the AWS API's PascalCase keys (e.g. {Bucket: 'foo'}); they go through --cli-input-json. Session profile/region (from aws_session_set) are used by default; override per-call when needed. Hand-written CLI commands (aws s3 cp/ls/sync, aws logs tail) and operations that stream their response to an output file (s3api get-object, bedrock-runtime invoke-model, bedrock-agentcore invoke-agent-runtime, lambda invoke) do not accept --cli-input-json and cannot run here -- use aws_lambda_invoke or aws_logs_tail where they exist, bedrock-runtime converse for text inference, otherwise your shell. Waiters work: operation 'wait instance-running'. Blob-typed members of params (KMS Plaintext, Kinesis Data, DynamoDB B) take base64 -- the server runs the CLI with --cli-binary-format base64 whatever your AWS config says. Returns parsed JSON output by default, plus the literal command that was run.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
queryNoJMESPath expression to extract a subset of the response (passed as --query). E.g. 'Buckets[].Name', 'Reservations[].Instances[].{Id:InstanceId,State:State.Name}'. Dramatically reduces output size; reach for this whenever you only need a few fields.
paramsNoOperation parameters as a JSON object (AWS API schema, PascalCase keys). E.g. {Bucket: 'foo', Key: 'bar'}.
regionNoOverride session region for this call.
profileNoOverride session profile for this call.
serviceYesAWS service name in kebab-case: 's3api', 'ec2', 'iam', 'lambda', 'dynamodb', 'logs', 'sts', 'cloudformation', etc.
operationYesOperation name in kebab-case: 'list-buckets', 'describe-instances', 'get-caller-identity', 'put-object'.
timeoutMsNoTimeout in milliseconds. Default 60000 (60s). Raise for slow ops; lower to fail fast.
outputFormatNoOutput format. Default 'json' (parsed into structured data when possible).

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv1.3.2

TDQS

A5/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

The description reveals important behavioral traits not visible in annotations: blob-typed params are base64-encoded, the CLI runs with --cli-binary-format base64 regardless of config, session profile/region defaults apply, and the return value includes both parsed JSON and the literal CLI command. It also discloses which operations stream output and therefore cannot run here. This is substantive context beyond the readOnly/destructive hints.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is long but every sentence adds necessary information for a tool this broad. It front-loads the core invocation pattern, then covers exclusions, waiters, binary handling, and output behavior without repetition or filler. The density is justified by the tool's complexity.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For an arbitrary AWS API caller with no output schema, the description covers invocation syntax, parameter casing, binary handling, streaming limitations, alternatives, default session behavior, waiters, timeouts, and return format. An agent has everything needed to call this tool correctly and to decide when to route to a sibling tool instead.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters5/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Although the schema already describes all 8 parameters, the description adds critical semantic nuance: kebab-case for service/operation names, PascalCase for API params, JMESPath usage for query, and base64 handling for blob-typed members. This goes far beyond the schema's one-line descriptions and materially helps the agent construct correct calls.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description opens with a specific verb+resource statement: 'Run an arbitrary AWS API operation via the aws CLI.' It immediately clarifies the tool's role as a general-purpose API caller and further distinguishes it from sibling tools by explicitly listing operations it cannot handle (e.g., s3api get-object, lambda invoke) and the alternatives to use instead.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Usage guidance is explicit: it names operations that do not accept --cli-input-json, points to aws_lambda_invoke, aws_logs_tail, bedrock-runtime converse, or the shell as alternatives, and confirms that waiters work via 'wait instance-running'. This gives an agent clear when-to-use and when-not-to-use rules that go well beyond generic advice.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.