general MCP Server
Fast, opinionated AWS security scanner. Curated checks. Zero noise. Copy-paste fixes.
Discovered via unknown and last synced 3mo ago.
Install instructions not detected yet
Check the source repository for the latest setup steps.
55 fixers across 17 AWS services (direct API calls)
Example
What it catches
No findings
Bedrock no logging + no guardrails = undetected model abuse
Findings detected
Scan error
Free
`aws-eip-001,aws-iam-001`
Per-finding + per-chain
`eu-central-1,eu-west-1`
AWS + 13 others
`arn:aws:iam::...:role/auditor`
`high`
Prowler
Apache 2.0
Highlight
no
Year
IAM-only, optimised for privesc-to-admin
2025
What it does
partial (graph + web UI)
2025
Forward BFS from arbitrary AWS resource?
no
no (IAM policy analysis only)
76 of 77 GitHub Action tags force-pushed to a credential stealer
yes
SSRF → IMDSv1 → admin S3 (100M records, $190M total damage)
no for AWS (`lateral-movement` GCP only)
Infostealer-harvested credentials replayed against no-MFA tenants (165 orgs, $28M+ AT&T settlement)
v1.0, Oct 2024
no built-in (bring your own Cypher)
Detecting exposed AWS credentials in source code repositories, CI/CD pipelines, and configuration files using TruffleHog, git-secrets, and AWS-native detection mechanisms to prevent credential theft and unauthorized account access.
Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.
Implement Amazon Macie to automatically discover, classify, and protect sensitive data in S3 buckets using machine learning and pattern matching for PII, financial data, and credentials detection.
Implementing AWS Security Hub to aggregate security findings across AWS accounts, enable compliance standards like CIS AWS Foundations and PCI DSS, configure automated remediation with EventBridge and Lambda, and create custom security insights for organizational risk management.
Flexible and powerful framework for managing multiple AI agents and handling complex conversations
为独立开发者准备的精选技术栈和工具仓库来了!这里有你最需要的工具,帮你提升开发效率、节约成本,最重要的是——这些工具都是市场上热门的,经过验证的。🚀A curated collection of tech stacks and tools tailored for independent developers is here! these are proven, popular tools widely used in the industry. 🚀
Learn Cloud Applied Generative AI Engineering (GenEng) using OpenAI, Gemini, Streamlit, Containers, Serverless, Postgres, LangChain, Pinecone, and Next.js
The secure gateway connecting AI agents to enterprise systems.
Learn how to use the cloud-aws Claude skill. Complete guide with installation instructions and examples.
Learn how to use the detecting-aws-iam-privilege-escalation Claude skill. Complete guide with installation instructions and examples.
Learn how to use the detecting-aws-guardduty-findings-automation Claude skill. Complete guide with installation instructions and examples.