CLOUD OPERATIONS / Amazon Web Services
AWS CloudTrail MCP Server
Looks up CloudTrail events and runs CloudTrail Lake queries when configured for the selected account.
“The CloudTrail MCP Server provides specialized tools to address common security and operational scenarios including event lookup, user activity analysis, API call tracking, and advanced CloudTrail Lake analytics.”
01 / THE REASONING
Why this made the selection.
- Looks up CloudTrail events and runs CloudTrail Lake queries when configured for the selected account.
- Looking up recorded AWS API activity.
02 / THE REVIEW RECORD
What we actually inspected.
Source review has boundaries.
A clear record is more useful than a “safe” badge.
Material inspected
- src/cloudtrail-mcp-server/README.md
- LICENSE
Our findings
- Event lookup and CloudTrail Lake are distinct capabilities; the README scopes event-history lookup to the recent management-event window.
- CloudTrail Lake needs separate enabled data-store/query prerequisites; an absent result is not evidence no event occurred.
- No event queries, audit records or account permissions were tested.
Not established by this review
- The pinned documentation and selected source files were reviewed; the external server was not executed by this review.
- No authenticated service requests, account mutations, tenant access controls, or end-to-end MCP client setup were tested.
- A repository revision does not pin an unversioned or @latest registry package; resolved package provenance and runtime permission enforcement remain unverified.
The review applies to the material and revision named here. A newer upstream release can change its behavior.
03 / PUT IT TO WORK
Connect a server deliberately.
DOCUMENTED COMMAND
uvx awslabs.cloudtrail-mcp-server@latest Copying does not execute this command. It may retrieve a newer version than the reviewed source.
- Register the uvx command.
- Use credentials for the account you mean.
Before you start
- uv
- AWS credentials for the service
04 / FOLLOW THE EVIDENCE
The source trail.
Our notes are separate from the original resource.
Check upstream before adopting a new version.
- Server documentation ↗Checked
https://github.com/awslabs/mcp/blob/49de7cc11ae064b9224f07ae050c612c3f92dd55/src/cloudtrail-mcp-server/README.md
Supports: Install command and stated scope
- Repository licence ↗Checked
https://github.com/awslabs/mcp/blob/49de7cc11ae064b9224f07ae050c612c3f92dd55/LICENSE
Supports: Redistribution terms