@atengk/mcp-server-s3
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| AWS_REGION | No | 目标区域(MCP_S3_REGION 的兼容备用变量) | us-east-1 |
| MCP_S3_REGION | No | 目标区域(MinIO/R2 通常为 us-east-1 或 auto) | us-east-1 |
| MCP_S3_ENDPOINT | No | S3 兼容接入点(如 http://127.0.0.1:9000) | |
| AWS_ENDPOINT_URL | No | S3 兼容接入点(MCP_S3_ENDPOINT 的兼容备用变量) | |
| MCP_S3_READ_ONLY | No | 只读门禁模式:为 true 时在 MCP 协议层完全隐藏写/删类工具 | false |
| MCP_S3_TRANSPORT | No | 通信传输模式:stdio(标准管道)或 sse(HTTP长轮询) | stdio |
| AWS_ACCESS_KEY_ID | No | S3 访问密钥 ID(MCP_S3_ACCESS_KEY_ID 的兼容备用变量) | |
| AWS_SESSION_TOKEN | No | STS 临时会话令牌(MCP_S3_SESSION_TOKEN 的兼容备用变量) | |
| AWS_DEFAULT_REGION | No | 目标区域(MCP_S3_REGION 的兼容备用变量) | us-east-1 |
| MCP_S3_SERVER_HOST | No | sse 模式下 HTTP 服务监听地址 | 0.0.0.0 |
| MCP_S3_SERVER_PORT | No | sse 模式下 HTTP 服务监听端口 | 8000 |
| AWS_ENDPOINT_URL_S3 | No | S3 兼容接入点(MCP_S3_ENDPOINT 的兼容备用变量) | |
| MCP_S3_ACCESS_KEY_ID | No | S3 访问密钥 ID | |
| MCP_S3_SESSION_TOKEN | No | STS 临时会话令牌(可选) | |
| AWS_SECRET_ACCESS_KEY | No | S3 访问密钥 Secret(MCP_S3_SECRET_ACCESS_KEY 的兼容备用变量) | |
| MCP_S3_DEFAULT_BUCKET | No | 默认绑定存储桶(配置后所有 Tool 的 bucket 参数变为可选) | |
| MCP_S3_MAX_READ_BYTES | No | 文本读取最大安全阈值:超出部分强制截断防爆 | 262144 |
| AWS_S3_FORCE_PATH_STYLE | No | 是否强制使用路径寻址(MCP_S3_FORCE_PATH_STYLE 的兼容备用变量) | false |
| MCP_S3_FORCE_PATH_STYLE | No | 是否强制使用路径寻址(MinIO 设为 true,云上设为 false) | false |
| MCP_S3_ALLOWED_LOCAL_DIR | No | 本地文件沙箱基准目录:严格阻断沙箱外路径读写 | ./ |
| MCP_S3_PRESIGNED_EXPIRES | No | 预签名 URL 默认有效生命周期(秒) | 3600 |
| MCP_S3_SECRET_ACCESS_KEY | No | S3 访问密钥 Secret |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| s3_pingA | 毫秒级自检端点连通性、网络 RTT、生效 Region 与脱敏鉴权身份 |
| list_bucketsB | 列出所有存储桶名称及创建时间列表 |
| create_bucketC | 创建新存储桶(支持指定部署区域) |
| delete_bucketB | 删除存储桶(支持 force 参数强制清理桶内对象后删除) |
| get_bucket_locationC | 查询存储桶的物理实际部署地域 |
| list_objectsC | 模拟分层虚拟目录树(Delimiter 默认为 /),支持游标分页 |
| search_objectsC | 在前缀路径树中执行关键字匹配与正则搜索 |
| stat_objectC | 提取对象大小、Content-Type、最后修改时间、ETag 及元数据 |
| read_object_textC | 文本直读,受 256KB 阈值截断保护,二进制文件智能拦截引导 |
| read_object_rangeB | HTTP Range 字节范围读取(适用于大对象末尾排障与对象头检视) |
| put_object_textC | 文本直接写入或覆盖对象 |
| upload_fileC | 本地文件流式上传至 S3(受本地工作区沙箱严格约束保护) |
| download_fileC | S3 对象流式保存为本地文件(受本地工作区沙箱保护) |
| get_presigned_urlB | 生成带有时效的预签名 HTTP(S) 直链(支持 GET 下载与 PUT 上传) |
| copy_objectC | 同桶或跨桶对象复制 |
| move_objectC | 原子化移动与重命名对象(复制成功后自动删除源对象) |
| delete_objectC | 删除指定的单个对象 |
| delete_objects_batchC | 批量删除指定的多个对象键列表(单批上限 1000 个对象) |
| delete_objects_by_prefixC | 递归清理虚拟子目录树,内置三重防灾熔断守卫 |
| get_object_tagsC | 查询对象关联的 Key-Value 标签字典 |
| set_object_tagsC | 写入或全量覆盖对象业务标签 |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 21 tools
Most tools have clearly distinct purposes: copy vs move, single/batch/prefix delete, text vs range read, file vs text upload. Minor overlap exists between list_objects and search_objects (both can return object keys by prefix) and between read_object_text and read_object_range, but the descriptions clarify their intended scopes.
Nearly all tools follow a predictable snake_case verb_noun pattern (list_buckets, create_bucket, delete_object, get_object_tags). Minor deviations include s3_ping (service prefix instead of a verb) and delete_objects_batch/by_prefix (extra qualifiers), but the overall convention is consistent.
21 tools is on the heavy side for the rubric's 16-25 range. While S3 is a broad domain and most tools serve distinct needs, there are three deletion tools, two read tools, and two write tools that could arguably be consolidated, making the surface feel somewhat fragmented.
Core lifecycle coverage is strong: bucket create/list/delete/location, object CRUD, copy/move, tags get/set, presigned URLs, and diagnostics. Gaps remain for advanced S3 features such as multipart upload, versioning, ACLs/policies, and metadata updates beyond tags, but agents can work around these for common workflows.