← Explore all mcp servers

CLOUD OPERATIONS / Amazon Web Services

AWS CloudTrail MCP Server

Looks up CloudTrail events and runs CloudTrail Lake queries when configured for the selected account.

“The CloudTrail MCP Server provides specialized tools to address common security and operational scenarios including event lookup, user activity analysis, API call tracking, and advanced CloudTrail Lake analytics.”

01 / THE REASONING

Why this made the selection.

  • Looks up CloudTrail events and runs CloudTrail Lake queries when configured for the selected account.
  • Looking up recorded AWS API activity.

02 / THE REVIEW RECORD

What we actually inspected.

Source review has boundaries.
A clear record is more useful than a “safe” badge.

Material inspected

  • src/cloudtrail-mcp-server/README.md
  • LICENSE

Our findings

  • Event lookup and CloudTrail Lake are distinct capabilities; the README scopes event-history lookup to the recent management-event window.
  • CloudTrail Lake needs separate enabled data-store/query prerequisites; an absent result is not evidence no event occurred.
  • No event queries, audit records or account permissions were tested.

Not established by this review

  • The pinned documentation and selected source files were reviewed; the external server was not executed by this review.
  • No authenticated service requests, account mutations, tenant access controls, or end-to-end MCP client setup were tested.
  • A repository revision does not pin an unversioned or @latest registry package; resolved package provenance and runtime permission enforcement remain unverified.

The review applies to the material and revision named here. A newer upstream release can change its behavior.

03 / PUT IT TO WORK

Connect a server deliberately.

Upstream setup instructions ↗

DOCUMENTED COMMAND

uvx awslabs.cloudtrail-mcp-server@latest

Copying does not execute this command. It may retrieve a newer version than the reviewed source.

  1. Register the uvx command.
  2. Use credentials for the account you mean.

Before you start

  • uv
  • AWS credentials for the service

04 / FOLLOW THE EVIDENCE

The source trail.

Our notes are separate from the original resource.
Check upstream before adopting a new version.

  1. Server documentation ↗Checked

    https://github.com/awslabs/mcp/blob/49de7cc11ae064b9224f07ae050c612c3f92dd55/src/cloudtrail-mcp-server/README.md

    Supports: Install command and stated scope

  2. Repository licence ↗Checked

    https://github.com/awslabs/mcp/blob/49de7cc11ae064b9224f07ae050c612c3f92dd55/LICENSE

    Supports: Redistribution terms

Evidence & Ask