Odel
aws mcp connector

aws mcp connector

Local
@ferhatdundarGoMITUpdated 3w ago

MCP server for the AWS CLI. Read-only by default; single Go binary.

๐Ÿ”Œ aws-mcp-connector

Talk to AWS CLI from an MCP-speaking agent.

CI CodeQL Latest release MCP Registry Go Reference License: MIT MCP Conventional Commits PRs Welcome


A single static Go binary that speaks the Model Context Protocol and lets an agent run AWS CLI commands: any aws <service> <operation> invocation, across every service the CLI supports, with a read-only-by-default safety gate on anything that mutates state.

No Python, no uv, no runtime dependency to install โ€” just a binary and an .mcp.json. It shells out to the aws binary already installed and configured on the host (profile, SSO, IAM role, or static keys โ€” whatever the AWS CLI's own credential chain resolves) instead of reimplementing the AWS SDK, so it gets the full breadth of the CLI for free rather than a hand-curated subset of services.

โœจ Why this exists

An agent that only has a narrow, hand-picked set of AWS tools hits a wall the moment you need something outside that set. This connector instead wraps the AWS CLI itself, so an agent can run aws s3 ls, aws ec2 describe-instances, aws iam list-users โ€” anything the CLI can do โ€” without waiting on a new tool to be written for it. Mutating commands are blocked by default and require both a server-level opt-in and a per-call confirm=true, so exploring/debugging is safe out of the box.

๐Ÿงฐ Tools

ToolWhat it doesWrite?
aws_execRun any aws <service> <operation> ... command. Read-only by default โ€” mutating commands need AWS_MCP_ALLOW_WRITE=true on the server and confirm=true on the call.โœ… (gated)
aws_helpShow aws <service> [subcommand] help text โ€” always safe, use it to check exact syntax before calling aws_exec.
aws_whoamiShow the AWS identity (account, ARN, user/role) the configured credentials resolve to.
aws_list_profilesList named profiles configured in ~/.aws/config on the host.

Every tool accepts an optional response_format: markdown (default, pretty tables for a chat UI) or json (for programmatic use).

๐Ÿš€ Quickstart

Fastest path: grab a prebuilt bundle from the latest release โ€” download aws-mcp-connector-plugin-<version>-<os>-<arch>.zip, unzip it, and point Cowork/Claude at the plugin/ folder inside (see step 4 of SETUP.md). No Go toolchain required.

From source:

# 1. Build
cd go-server
go mod tidy
go build -o aws-connector-server .
cp aws-connector-server ../plugin/servers/go/

# 2. Set up auth โ€” needs the aws CLI itself installed and configured
#    (aws configure / aws sso login) โ€” see SETUP.md
export AWS_PROFILE=default   # optional, only if not using "default"

# 3. Run
./go-server/aws-connector-server   # serves MCP over stdio

Or make build โ€” see the Makefile for every shortcut (test, vet, fmt, lint, tidy).

Full walkthrough โ€” including wiring this up as a Claude/Cowork plugin โ€” is in SETUP.md.

๐Ÿ” Configuration

Everything is environment variables, passed through by the plugin's .mcp.json:

VariablePurposeDefault
AWS_PROFILENamed profile from ~/.aws/config to use.unset (default profile)
AWS_REGIONDefault region if not set elsewhere.AWS CLI's own default
AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY / AWS_SESSION_TOKENStatic credentials โ€” only needed if not using a profile/SSO/role.unset
AWS_MCP_ALLOW_WRITE"true" to permit mutating commands at all (still needs confirm=true per call).false (read-only)
AWS_MCP_ALLOWED_SERVICESComma-separated allowlist of AWS CLI service names, e.g. "s3,ec2".unset (unrestricted)
AWS_MCP_CLI_PATHPath to the aws binary.aws resolved via PATH

๐Ÿงช Quality bar

This isn't a toy script โ€” it's got the same checks you'd expect from a production Go service:

  • โœ… Unit tests for every input-validation path (go test ./...)
  • โœ… go vet + gofmt clean
  • โœ… golangci-lint (govet, staticcheck, errcheck, gosec, and more)
  • โœ… govulncheck โ€” no known vulnerabilities in the dependency graph
  • โœ… CodeQL static security analysis on every push
  • โœ… End-to-end verified against a real (or sandboxed) AWS CLI backend โ€” not mocks
  • โœ… Dependabot keeps Go modules and Actions current

All of it runs in CI on every push and PR.

๐Ÿท๏ธ Releases & versioning

Versions follow semver and are cut automatically by release-please from Conventional Commits on main:

  • fix: ... โ†’ patch (v0.1.0 โ†’ v0.1.1)
  • feat: ... โ†’ minor (v0.1.1 โ†’ v0.2.0)
  • feat!: ... / BREAKING CHANGE: footer โ†’ major (v0.2.0 โ†’ v1.0.0)

Every merged PR updates a standing "chore(main): release vX.Y.Z" PR with an auto-generated CHANGELOG.md. Merging that PR:

  1. tags the release and publishes it on GitHub
  2. builds and attaches zipped, ready-to-install plugin bundles for linux/darwin/windows ร— amd64/arm64
  3. regenerates server.json from those exact assets (fresh version + SHA-256 hashes) and publishes it to the official MCP Registry via mcp-publisher, authenticated with GitHub OIDC โ€” no stored secrets

See .github/workflows/release-please.yml and .github/workflows/publish-mcp-registry.yml (also runnable by hand for an existing tag via workflow_dispatch).

๐Ÿ“ Layout

aws-mcp-connector/
โ”œโ”€โ”€ README.md                  โ† you are here
โ”œโ”€โ”€ SETUP.md                   โ† step-by-step setup guide
โ”œโ”€โ”€ CONTRIBUTING.md             โ† how to contribute
โ”œโ”€โ”€ CODE_OF_CONDUCT.md
โ”œโ”€โ”€ SECURITY.md                 โ† vulnerability reporting
โ”œโ”€โ”€ CODEOWNERS
โ”œโ”€โ”€ LICENSE                     โ† MIT
โ”œโ”€โ”€ Makefile                    โ† build / test / lint shortcuts
โ”œโ”€โ”€ .golangci.yml                โ† lint rules
โ”œโ”€โ”€ release-please-config.json  โ† semver/changelog automation config
โ”œโ”€โ”€ .release-please-manifest.json
โ”œโ”€โ”€ server.json                  โ† MCP Registry manifest (regenerated fresh per release by CI)
โ”œโ”€โ”€ scripts/
โ”‚   โ””โ”€โ”€ render-server-json.sh    โ† rebuilds server.json from a release's zip assets
โ”œโ”€โ”€ .github/
โ”‚   โ”œโ”€โ”€ workflows/
โ”‚   โ”‚   โ”œโ”€โ”€ ci.yml                     โ† build, vet, test, lint, govulncheck
โ”‚   โ”‚   โ”œโ”€โ”€ codeql.yml                 โ† security scanning
โ”‚   โ”‚   โ”œโ”€โ”€ pr-title.yml               โ† Conventional Commits PR title check
โ”‚   โ”‚   โ”œโ”€โ”€ release-please.yml         โ† version PRs, tagging, GitHub releases
โ”‚   โ”‚   โ”œโ”€โ”€ publish-mcp-registry.yml   โ† publishes server.json to the MCP Registry
โ”‚   โ”‚   โ””โ”€โ”€ rebuild-release-assets.yml โ† manual re-attach fallback
โ”‚   โ”œโ”€โ”€ ISSUE_TEMPLATE/
โ”‚   โ”œโ”€โ”€ PULL_REQUEST_TEMPLATE.md
โ”‚   โ””โ”€โ”€ dependabot.yml
โ”œโ”€โ”€ go-server/                  โ† the MCP server source
โ”‚   โ”œโ”€โ”€ main.go
โ”‚   โ”œโ”€โ”€ main_test.go
โ”‚   โ”œโ”€โ”€ go.mod / go.sum
โ”‚   โ””โ”€โ”€ README.md
โ””โ”€โ”€ plugin/                     โ† installable Cowork/Claude plugin
    โ”œโ”€โ”€ .claude-plugin/plugin.json
    โ”œโ”€โ”€ .mcp.json                โ† holds credentials locally โ€” never commit real ones
    โ””โ”€โ”€ servers/go/              โ† compiled binary goes here

๐Ÿค Contributing

PRs and issues are very welcome โ€” see CONTRIBUTING.md for the full guide (setup, coding conventions, how to add a new tool) and the Code of Conduct.

main is protected: every change, including the maintainer's, lands via pull request with CI green. PR titles must follow Conventional Commits โ€” that's what drives the automatic versioning above.

Found a security issue? Please follow SECURITY.md instead of opening a public issue.

๐Ÿ“„ License

MIT ยฉ FerhatDundar