AWS Security Posture Advisor MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| AWS_REGION | Yes | AWS region to operate in (e.g., us-east-1) | |
| AWS_ACCESS_KEY_ID | No | AWS access key ID for authentication | |
| AWS_SESSION_TOKEN | No | AWS session token for temporary credentials | |
| FASTMCP_LOG_LEVEL | No | Log level (DEBUG, INFO, WARNING, ERROR) | |
| AWS_SECRET_ACCESS_KEY | No | AWS secret access key for authentication | |
| AWS_SECURITY_ADVISOR_LOG_DIR | No | Log directory | |
| AWS_SECURITY_ADVISOR_TIMEOUT | No | Request timeout in seconds | 300 |
| AWS_SECURITY_ADVISOR_CACHE_TTL | No | Cache TTL in seconds | 300 |
| AWS_SECURITY_ADVISOR_READ_ONLY | No | Enable read-only mode | true |
| AWS_SECURITY_ADVISOR_CACHE_SIZE | No | Max cache entries | 1000 |
| AWS_SECURITY_ADVISOR_CONFIG_FILE | No | Path to a configuration YAML file | |
| AWS_SECURITY_ADVISOR_LOG_TO_FILE | No | Enable file logging | |
| AWS_SECURITY_ADVISOR_MAX_RETRIES | No | Max retry attempts | 3 |
| AWS_SECURITY_ADVISOR_REQUIRE_TLS | No | Require TLS for all connections | |
| AWS_SECURITY_ADVISOR_ENABLE_CACHE | No | Enable response caching | true |
| AWS_SECURITY_ADVISOR_ENCRYPT_LOGS | No | Encrypt log files | |
| AWS_SECURITY_ADVISOR_LOG_MAX_SIZE | No | Max log file size (e.g., 100MB) | |
| AWS_SECURITY_ADVISOR_LOG_ROTATION | No | Enable log rotation | |
| AWS_SECURITY_ADVISOR_PROFILE_NAME | No | AWS profile name to use for credentials | |
| AWS_SECURITY_ADVISOR_AUDIT_LOGGING | No | Enable audit logging | true |
| AWS_SECURITY_ADVISOR_SANITIZE_LOGS | No | Sanitize sensitive data in logs | |
| AWS_SECURITY_ADVISOR_BACKOFF_FACTOR | No | Exponential backoff factor | 2 |
| AWS_SECURITY_ADVISOR_MAX_CONCURRENT | No | Max concurrent AWS API calls | 10 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| health_checkA | Check the health and configuration of the AWS Security Posture Advisor MCP server. |
| get_server_infoA | Get detailed information about the AWS Security Posture Advisor MCP server. |
| assess_security_postureA | Perform comprehensive security assessment across AWS infrastructure. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 3 tools
Each tool has a clearly distinct purpose with no overlap: assess_security_posture performs security assessments, get_server_info provides server metadata, and health_check monitors server health. The descriptions reinforce these distinct roles, making misselection unlikely.
All tools follow a consistent verb_noun naming pattern (assess_security_posture, get_server_info, health_check). The naming is uniform and predictable across the set, enhancing readability and usability.
With only 3 tools, the set feels thin for a server focused on AWS security posture management. While the core assessment tool is comprehensive, the lack of tools for specific actions like remediation, reporting, or detailed compliance checks limits the scope and may require agents to work around gaps.
The tool surface is severely incomplete for the domain of AWS security posture management. There are significant gaps: no tools for remediation (e.g., fix_finding), reporting (e.g., generate_report), or detailed compliance operations (e.g., check_compliance). This will likely cause agent failures when trying to perform full security workflows.