If your AI agent needs to audit AWS security posture without wrestling with SDKs or containers, this server exposes seven static binary scanners covering S3, IAM, EC2, EKS, RDS, CloudTrail, and CloudWatch Logs. Each scanner is a self-contained ~2MB Rust binary with zero dependencies. The MCP interface provides search and get operations that let agents discover the right scanner, fetch download commands with SHA256 verification, and run checks that return structured JSON with severity levels and remediation hints. Exit codes are designed for branching logic. You get 50 free scans per day over streamable HTTP, no API key required. Reach for this when you want agents to find misconfigurations like public S3 buckets, missing MFA, or unencrypted RDS instances using read-only IAM permissions.
Public tool metadata for what this MCP can expose to an agent.
searchFind k5e cloud security scanners by capability. Returns matching binaries with name, description, check count, and severity breakdown.1 paramsFind k5e cloud security scanners by capability. Returns matching binaries with name, description, check count, and severity breakdown.
querystringgetGet full metadata, SHA256 hash, download URL, and ready-to-run shell command for a k5e binary. Pass args to get a complete command; omit for a template with placeholders.2 paramsGet full metadata, SHA256 hash, download URL, and ready-to-run shell command for a k5e binary. Pass args to get a complete command; omit for a template with placeholders.
argsobjectnamestringsilenceper/mcp-k8s
azure/containerization-assist
io.github.evozim/aws-builder
reza-gholizade/k8s-mcp-server
flux159/mcp-server-kubernetes