Skip to main content
Glama
649,985 tools. Updated 2026-10-08 10:44

"Report on Internet Egress for EC2 Instances" matching MCP tools:

  • BATCH INSPECTION: run up to 32 AWS inspect probes in one call. ⚠️ **PREREQUISITE**: Same as awsinspect — deploy attempt required. Check convostatus for hasDeployAttempt=true before calling. Use this when you need to check more than ~3 resources. The backend fetches Oracle credentials ONCE per batch and fans out probes against a single AWS config — for a 12-resource health check this is ~5–8× faster and 12× fewer Oracle round-trips than calling awsinspect 12 times. BUDGETS: - Up to 32 sub-probes per call (subs array length). - 30s per-sub timeout; 60s total batch wall-clock. - Concurrency cap 8 — sub-probes run in parallel but never saturate AWS. - 512 KB response cap: subs past the cap keep their envelope (index/service/action/ok) but have result replaced with truncated=true. PARTIAL FAILURE IS EXPECTED. The response is an ordered results array; each entry has {index, service, action, ok, result, error}. Inspect each result — do NOT abort on the first error. A credential fetch failure leaves cred-less probes (list-actions, list-metrics) succeeding anyway. REQUIRES: session_id from convoopen response (format: sess_v2_...). Supported services: account, acm, alb, apigateway, apprunner, backup, bedrock, cloudfront, cloudwatchlogs, cognito, cost-explorer, dynamodb, ebs, ec2, ecs, eks, elasticache, kms, lambda, msk, opensearch, rds, route53, s3, sagemaker, secretsmanager, sqs, vpc, waf For a specific service's actions, use awsinspect (singular) with action="list-actions" — batch is not the place for discovery. Batch responses are always summarized (no detail/raw per-sub); use singular awsinspect when you need full metadata or raw API output for one resource. EXAMPLES: - awsinspect_batch(session_id=..., subs=[ {"service":"ec2","action":"describe-instances"}, {"service":"rds","action":"describe-db-instances"}, {"service":"vpc","action":"describe-vpcs"}, {"service":"s3","action":"list-buckets"}]) - awsinspect_batch(session_id=..., subs=[ {"service":"ec2","action":"get-metrics","filters":"{\"hours\":6}"}, {"service":"rds","action":"get-metrics","filters":"{\"hours\":6}"}])
    ConnectorNo auth
  • BATCH INSPECTION: run up to 32 AWS inspect probes in one call. ⚠️ **PREREQUISITE**: Same as awsinspect — deploy attempt required. Check convostatus for hasDeployAttempt=true before calling. Use this when you need to check more than ~3 resources. The backend fetches Oracle credentials ONCE per batch and fans out probes against a single AWS config — for a 12-resource health check this is ~5–8× faster and 12× fewer Oracle round-trips than calling awsinspect 12 times. BUDGETS: - Up to 32 sub-probes per call (subs array length). - 30s per-sub timeout; 60s total batch wall-clock. - Concurrency cap 8 — sub-probes run in parallel but never saturate AWS. - 512 KB response cap: subs past the cap keep their envelope (index/service/action/ok) but have result replaced with truncated=true. PARTIAL FAILURE IS EXPECTED. The response is an ordered results array; each entry has {index, service, action, ok, result, error}. Inspect each result — do NOT abort on the first error. A credential fetch failure leaves cred-less probes (list-actions, list-metrics) succeeding anyway. REQUIRES: session_id from convoopen response (format: sess_v2_...). Supported services: account, acm, alb, apigateway, apprunner, backup, bedrock, cloudfront, cloudwatchlogs, cognito, cost-explorer, dynamodb, ebs, ec2, ecs, eks, elasticache, kms, lambda, msk, opensearch, rds, route53, s3, sagemaker, secretsmanager, sqs, vpc, waf For a specific service's actions, use awsinspect (singular) with action="list-actions" — batch is not the place for discovery. Batch responses are always summarized (no detail/raw per-sub); use singular awsinspect when you need full metadata or raw API output for one resource. EXAMPLES: - awsinspect_batch(session_id=..., subs=[ {"service":"ec2","action":"describe-instances"}, {"service":"rds","action":"describe-db-instances"}, {"service":"vpc","action":"describe-vpcs"}, {"service":"s3","action":"list-buckets"}]) - awsinspect_batch(session_id=..., subs=[ {"service":"ec2","action":"get-metrics","filters":"{\"hours\":6}"}, {"service":"rds","action":"get-metrics","filters":"{\"hours\":6}"}])
    ConnectorNo auth
  • Start a cloud cost / FinOps scan of a linked account and return a job_id. Use this when the user wants to find idle, unused or underutilized cloud resources, review cloud spend, or estimate savings. The provider comes from the connection, and **AWS is the only provider supported today** (see `list_connections`). Other clouds will appear on this same tool as connections for them become linkable; nothing else about the call changes. READ-ONLY against your cloud: it reads resource metadata and monitoring metrics and reports; it never changes, stops or deletes anything. (It does create a scan job here and consume that account's scan quota, which is why this tool is not marked read-only.) On AWS it covers EC2 instances, EBS volumes and snapshots, RDS instances, Elastic IPs, NAT Gateways, load balancers, VPCs and VPC endpoints, site-to-site VPN and Transit Gateway attachments, Client VPN endpoints, Secrets Manager secrets, CloudFront distributions and WAF web ACLs. Resource kinds outside that list are not inspected, so a clean scan is not a claim that the whole bill is optimized. `connection_id` picks which linked AWS account to scan (see `list_connections`). Omit it to run against sample data — useful for showing the user what the output looks like before any account is linked. The scan runs asynchronously: poll `get_job(job_id)` roughly every 10 seconds until status is COMPLETED (typically 1-3 minutes), then call `list_cost_findings(job_id)`. Do NOT start another scan while one is running — each scan consumes the account's monthly quota. Pass `idempotency_key` (any unique string you choose) if you may retry on a network error: a retry with the same key returns the original job instead of starting a second scan.
    ConnectorNo auth
  • Report information about the caller's own public IP as seen by the server: IPv4/IPv6 address, ISP, ASN, approximate geolocation, and proxy/VPN heuristics. Takes no input — it reflects the egress IP of THIS MCP server's network, which is usually NOT the end user's IP. Use this to discover the server's outbound IP or test connectivity. To inspect a specific, known IP instead, use asn_lookup or reverse_dns. Read-only; requires no API key; rate-limited.
    ConnectorNo auth
  • Report information about the caller's own public IP as seen by the server: IPv4/IPv6 address, ISP, ASN, approximate geolocation, and proxy/VPN heuristics. Takes no input — it reflects the egress IP of THIS MCP server's network, which is usually NOT the end user's IP. Use this to discover the server's outbound IP or test connectivity. To inspect a specific, known IP instead, use asn_lookup or reverse_dns. Read-only; requires no API key; rate-limited.
    ConnectorNo auth
  • Suggest the best dimensions to group costs by, based on an optional filterCel (CEL). Call this when the user asks "what should I look at?" or when you need columns for query or find_cost_change_factors. Prefer datePreset over from/to. Omit compare for current-window ranking. Pass compare (`{}` auto-derives, or `{ from, to }`) when the user asks what changed — then pass 2–4 of the returned column names (max 8; { column, contains } for token columns, dropping metrics) into find_cost_change_factors. Returns { column } or { column, contains } plus metrics; do not invent columns. filterCel omitted or "" is unfiltered (not AWS-only). filterCel supports == null for unlabelled dimension values (e.g. cos_environment == null). EXAMPLES: • "What should I split last month's EC2 cost by?" → { datePreset: "LAST_MONTH", filterCel: "cos_service_name in [\"AmazonEC2\"]" } • "Costs of EC2 spiked last month, what should I investigate?" → { datePreset: "LAST_MONTH", compare: {}, filterCel: "cos_service_name in [\"AmazonEC2\"]" }
    ConnectorOAuth

Matching MCP Servers

  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables MCP clients to drive IDA Pro through a stability-hardened server that hosts multiple headless idalib instances, with per-session isolation, configurable HTTP/stdio transports, and API-key authentication.
    457
    MIT

Matching MCP Connectors

  • Internet Archive (archive.org) item search & metadata MCP.

  • Deterministic cleanup tools for decimals, whitespace, filenames, delimiters, and booleans.

  • Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc. Each row carries the upstream's SpeedtestLog shape — typically {id, timestamp, download_mbps, upload_mbps, latency_ms, jitter_ms, server, ...}, but any new columns added on the Laravel side flow through automatically. The tool doesn't reshape the row contents — just filters by time window and limits the return. Lower priority than ping/traceroute/netflow for general 'internet slow' investigations, but the right tool when the user specifically asks about WAN throughput trends or recent speedtest runs. Filters (client-side): hours (1-720, default 168 = 7d), limit (1-100, default 25). The upstream endpoint returns the full history with no server-side cap — narrow with hours rather than fetching unbounded. Permission: tools. Example: speedtest_history({hours: 24})
    ConnectorNo auth
  • Deploy a static website for an agent: creates a canister on the Internet Computer, installs the FirstKey static host, uploads every file, and returns the live https URL. The agent is added as a controller of its site canister. One free deploy per agent principal, funded from the FirstKey deploy pool; files must fit in one call (total under ~1.4 MB decoded) — use deploy_upload_chunk for larger files.
    ConnectorNo auth
  • PERMANENTLY delete a container on Cycle. This is IRREVERSIBLE: it destroys the container, every one of its instances, and any data on stateful local instances. This tool is two-step by design and NOTHING is deleted on the first call: 1. Call without confirm. The container is resolved and the response describes exactly what would be destroyed — name, ID, environment, when it was created, and how many instances exist, their state, and which servers they run on. Present ALL of those details to the user verbatim. 2. Only after the user explicitly approves deleting that specific container, call again with confirm:true and container set to the exact 24-char hex ID from step 1 (names are not accepted with confirm — the ID binds the deletion to what the user approved). Never set confirm:true unless the user has just approved this exact deletion; a general instruction like "clean up the environment" is not sufficient. Containers with deletion protection (lock) cannot be deleted until unlocked; reconfigure_container with lock:false lifts it, which is itself a change the user must approve.
    Connector
    Destructive
    API key
  • Migrate a container's or virtual machine's instances between servers on Cycle, or revert a recent migration. Pass exactly one of container or virtual_machine. Cycle backs every VM with a container, so a VM migrates through that container's single instance (select it with all_instances:true or name it in targets); the response reports both the VM and its backing container. Cycle migrates instances across any infrastructure it manages — between servers, data centers, cloud providers, and on-prem hardware. Not every server is a valid target: containers carry tag restrictions and other constraints, so this tool only accepts destinations Cycle reports as compatible for the container. A migration is reversible: the original instance is retained until Cycle's purge window elapses (roughly 3 hours for stateful instances), during which action:"revert" restores it on its source server. Only retained source instances are revertable; running destination copies are skipped. Load balancer instances cannot be migrated. Workflow: 1. Call with preview:true and your selection. It makes NO changes and returns the selected instances — each with its current server (id and name) and whether it is stateful — plus, for migrate, the compatible destination servers. The plan comes from read-only lookups; Cycle does not validate it. 2. If the destination is unclear, present the compatible servers and let the user choose. With NO compatible servers migration is impossible — tell the user why (tag or infrastructure constraints). 3. Confirm the specific move with the user, then call again without preview. Never migrate or revert without explicit confirmation. Select instances with exactly one of: targets (specific instances, each optionally with its own destination so they can spread across servers), source_server ("move this container off nuc-bear"), or all_instances. A top-level destination_server is the default for selected instances without their own and is required with source_server or all_instances. copy_volumes applies to stateful instances and defaults to true so data is never silently dropped. A VM's local volumes — including its boot disk — are what it moves, so copy_volumes:false lands the VM on empty local storage and is almost never wanted. External (SAN) volumes are attached, not copied, and are unaffected either way. Asynchronous: submits one job per instance and returns without waiting (wait_seconds gives a short bounded wait for quick moves). Track the job_ids with get_jobs, then call again with preview:true to confirm each instance reports its destination server.
    Connector
    Destructive
    API key
  • Search the full text of books scanned by the Internet Archive — the "which book contains this passage?" lookup that the metadata tools cannot answer. Quote a phrase for an exact-phrase match; bare terms match anywhere in the text. Each result is an Internet Archive item with the matching passages as snippets, plus a relevance score. The full-text index is far slower than the metadata endpoints, and a search usually takes 10–30 seconds. Use it when the passage is the question, and use openlibrary_search_books to search by title, author, or subject. Results key on Internet Archive items rather than Open Library works: chain the returned ia_identifier to archive.org, or match it against the ia_identifiers on openlibrary_search_books results to reach the catalogue record.
    ConnectorNo auth
  • Resolve one drafted marketing output in the founder's review queue: action 'ship' marks it done or posted WITHOUT publishing anywhere, action 'skip' dismisses it. WHEN: call 'ship' the moment the founder confirms the content is actually out, with their go and never on your own; call 'skip' when they decide against it. Posting is the human's decision; reporting the outcome is yours, and it is not optional, because an unreported result leaves the record blind to what the work earned. Report only what is true: a draft you have written is not a draft that went out. This never posts to a channel: real publishing is a separate, human-approved egress step. Free; requires the 'act' scope and Founder tier.
    Connector
    Destructive
    No auth
  • Resolve one drafted marketing output in the founder's review queue: action 'ship' marks it done or posted WITHOUT publishing anywhere, action 'skip' dismisses it. WHEN: call 'ship' the moment the founder confirms the content is actually out, with their go and never on your own; call 'skip' when they decide against it. Posting is the human's decision; reporting the outcome is yours, and it is not optional, because an unreported result leaves the record blind to what the work earned. Report only what is true: a draft you have written is not a draft that went out. This never posts to a channel: real publishing is a separate, human-approved egress step. Free; requires the 'act' scope and Founder tier.
    Connector
    Destructive
    No auth
  • Remote-safe upload for sandboxed MCP clients (Claude.ai, ChatGPT) whose egress allowlist blocks PUTs to the storage host: send the file bytes as base64 and they upload through the API itself — the same host the MCP session already uses. Returns a ready file_id for file_ids. Decode locally first: if a source image fails to decode or renders blank/transparent, the bytes are corrupt — tell the user instead of uploading. For logos/photos prefer this over asset_files on create_design/update_design when a presigned PUT is not possible. Not for files over ~20MB.
    ConnectorOAuth
  • Get upload URLs for a local image/video/audio file that has no public URL to hand to `popcraft_media_import_url`. THIS IS THE TOOL FOR VIDEO and for anything over 20 MB. Returns a `proxy_upload_url` on Popcraft's OWN host (PUT the bytes there — total file size up to the per-type cap: video 500 MB, image 30 MB, audio 50 MB; each individual REQUEST is capped at 28 MB by the transport, so files over 28 MB use the chunked recipe B — same URL, same total cap) and an `upload_url` for a direct PUT to storage.googleapis.com (fewer hops, but a different host that sandboxed clients often cannot reach). The result text contains ready-to-run shell recipes including the chunked one for large files — RUN one of them rather than reimplementing the upload. Running a shell command also keeps the file bytes out of your context, which is why this beats `popcraft_media_upload_inline` for video: that tool needs the whole file base64-encoded in its arguments, so it is only practical for small files. CAUTION on platform-mediated clients (e.g. claude.ai connectors): tool calls are made from the platform's servers, so this call succeeding does NOT prove your shell can reach Popcraft — run the 5-second egress probe in recipe 0 first. If your shell's egress is blocked: prefer asking the user for any shareable link to the file (Drive/Dropbox/etc) and `popcraft_media_import_url` (server-side fetch, immune to client egress blocks); if no link exists, open `popcraft_media_upload_widget` when the client renders widgets. After the upload, call `popcraft_media_confirm` with the returned `media_id` to verify it landed, then pass that `media_id` as a `medias[].value` for `popcraft_generate_image` / `popcraft_generate_video` / `popcraft_generate_audio`. If you have no shell and no network at all, fall back to `popcraft_media_upload_inline` — but never tell the user to upload the file on the website instead.
    ConnectorOAuth
  • Get upload URLs for a local image/video/audio file that has no public URL to hand to `popcraft_media_import_url`. THIS IS THE TOOL FOR VIDEO and for anything over 20 MB. Returns a `proxy_upload_url` on Popcraft's OWN host (PUT the bytes there — total file size up to the per-type cap: video 500 MB, image 30 MB, audio 50 MB; each individual REQUEST is capped at 28 MB by the transport, so files over 28 MB use the chunked recipe B — same URL, same total cap) and an `upload_url` for a direct PUT to storage.googleapis.com (fewer hops, but a different host that sandboxed clients often cannot reach). The result text contains ready-to-run shell recipes including the chunked one for large files — RUN one of them rather than reimplementing the upload. Running a shell command also keeps the file bytes out of your context, which is why this beats `popcraft_media_upload_inline` for video: that tool needs the whole file base64-encoded in its arguments, so it is only practical for small files. CAUTION on platform-mediated clients (e.g. claude.ai connectors): tool calls are made from the platform's servers, so this call succeeding does NOT prove your shell can reach Popcraft — run the 5-second egress probe in recipe 0 first. If your shell's egress is blocked: prefer asking the user for any shareable link to the file (Drive/Dropbox/etc) and `popcraft_media_import_url` (server-side fetch, immune to client egress blocks); if no link exists, open `popcraft_media_upload_widget` when the client renders widgets. After the upload, call `popcraft_media_confirm` with the returned `media_id` to verify it landed, then pass that `media_id` as a `medias[].value` for `popcraft_generate_image` / `popcraft_generate_video` / `popcraft_generate_audio`. If you have no shell and no network at all, fall back to `popcraft_media_upload_inline` — but never tell the user to upload the file on the website instead.
    ConnectorOAuth
  • A page of the merged records of a dataset version (requires auth). Latest version and 50 records by default; a version never changes, so pages are stable. The response size counts toward your operator's free monthly egress (50 GB). A paid dataset answers with its price instead — see buy_dataset. For aggregates use query_dataset; for a whole version use dataset_manifest.
    ConnectorOAuth
  • Get Open Network Outages (No Authentication Required). Returns a list of publicly available network and/or application outages from ThousandEyes Internet Insights. This endpoint does not require authentication and provides visibility into global Internet infrastructure outages. Use this to: - Monitor current Internet outages affecting ISPs, DNS providers, CDNs, and SaaS providers - Track macro-level impact of Internet events - Get real-time visibility into infrastructure issues Args: ---- latest_seconds: Time window in seconds to look back (default: 86400 = 24 hours) minimum_outage_duration_seconds: Minimum duration filter (default: 200 seconds) Returns: ------- List of outage events with details about affected infrastructure
    ConnectorNo auth
  • Classifies an IPv4 or IPv6 address by network type — the high-value ad-fraud signal being datacenter traffic posing as residential or living-room (CTV) devices. IP→ASN resolution uses Team Cymru's public service; the ASN is then classified by its registered organization name. It also cross-references the Scry attacker-observation corpus to detect anonymizing EGRESS — the thing a rotating-residential proxy provider is built to hide. A residential- or mobile-looking IP that Scry has observed acting as a hostile actor is a residential-proxy exit node (home devices don't scan honeypots); tor and vpn egress are named outright. It also identifies the proxy COMPANY by network: if the IP's ASN belongs to a known VPN/anonymizing-egress provider (X4BNet's curated list), the verdict is `vpn` and `scry_signals` carries `vpn_provider_asn` — even when Scry has never observed the IP acting. Datacenter and residential proxy verdicts still require observed conduct. PRIVACY: the IP is used for lookup only — never logged, never stored. The Scry cross-reference is likewise a read-only corpus lookup. Inputs: - `ip` (query, required): IPv4 or IPv6 address. Returns: - `ip_type`: datacenter | residential | mobile | unknown. - `confidence`: high | medium | low. - `asn`, `asn_name`: the resolved autonomous system. - `proxy_suspected`: boolean — the IP is an anonymizing egress. - `proxy_type`: tor | vpn | residential_proxy | datacenter_proxy | null. - `scry_signals`: evidence strings from the corpus (actor_class, threat feeds, observation counts); empty when the IP is unknown to Scry. Latency: - Typical: 100-250ms (DNS + a parallel corpus lookup).
    ConnectorNo auth
  • Delete an instance from a project. The request requires the 'name' field to be set in the format 'projects/{project}/instances/{instance}'. Example: { "name": "projects/my-project/instances/my-instance" } Before executing the deletion, you MUST confirm the action with the user by stating the full instance name and asking for "yes/no" confirmation.
    Connector
    Destructive
    No auth
  • Delete a table. The request requires the 'name' field to be set in the format 'projects/{project}/instances/{instance}/tables/{table}'. Example: { "name": "projects/my-project/instances/my-instance/tables/my-table" } The table must exist. You can use `list_tables` to verify. Before executing the deletion, you MUST confirm the action with the user by stating the full table name and asking for "yes/no" confirmation.
    Connector
    Destructive
    No auth