Cloud Audit

general MCP Server

Fast, opinionated AWS security scanner. Curated checks. Zero noise. Copy-paste fixes.

generalgeneralaws
7 views61 stars13 forksMIT

Why This Matters

Discovered via unknown and last synced 3mo ago.

Source
unknown
Stars
61
Last synced
3mo ago
Install
Check source

Install

Install instructions not detected yet

Check the source repository for the latest setup steps.

View source instructions
34
Tools
0
Resources
0
Prompts
Standard I/O
Transport

Available Tools (34)

Auto-remediation

55 fixers across 17 AWS services (direct API calls)

Variable

Example

Chain

What it catches

0

No findings

LLMjacking

Bedrock no logging + no guardrails = undetected model abuse

1

Findings detected

2

Scan error

Free

Free

CLOUD_AUDIT_EXCLUDE_CHECKS

`aws-eip-001,aws-iam-001`

No

Per-finding + per-chain

CLOUD_AUDIT_REGIONS

`eu-central-1,eu-west-1`

Multi-cloud

AWS + 13 others

CLOUD_AUDIT_ROLE_ARN

`arn:aws:iam::...:role/auditor`

CLOUD_AUDIT_MIN_SEVERITY

`high`

Feature

Prowler

License

Apache 2.0

Version

Highlight

Trivy

no

Scenario

Year

PMapper

IAM-only, optimised for privesc-to-admin

Cryptomining

2025

Capability

What it does

awspx

partial (graph + web UI)

Codefinger

2025

Tool

Forward BFS from arbitrary AWS resource?

ScoutSuite

no

Cloudsplaining

no (IAM policy analysis only)

2026

76 of 77 GitHub Action tags force-pushed to a credential stealer

no

yes

2019

SSRF → IMDSv1 → admin S3 (100M records, $190M total damage)

CloudFox

no for AWS (`lateral-movement` GCP only)

2024

Infostealer-harvested credentials replayed against no-MFA tenants (165 orgs, $28M+ AT&T settlement)

yes

v1.0, Oct 2024

Cartography

no built-in (bring your own Cypher)