Raw scan report

Aws Safe — the complete, unedited output of the deterministic mcptrustchecker engine v1.13.0, scanned . Every finding, capability tag and score component below is exactly what the engine produced — no AI, no post-processing.

← Back to the scan page
{
  "tool": {
    "name": "mcptrustchecker",
    "version": "1.13.0",
    "methodologyVersion": "mcptrustchecker-1.13"
  },
  "target": {
    "id": "aws-safe-mcp",
    "source": {
      "kind": "package",
      "origin": "aws-safe-mcp"
    },
    "server": {
      "name": "aws-safe-mcp"
    }
  },
  "grade": "A",
  "score": {
    "score": 99,
    "threatScore": 100,
    "grade": "A",
    "band": "A",
    "categorySubtotals": {
      "injection": 0,
      "exfiltration": 0,
      "permissions": 0,
      "supply-chain": 0,
      "network": 0,
      "hygiene": 0
    },
    "vector": [
      {
        "kind": "client",
        "term": "capability-exposure",
        "level": "minimal",
        "label": "capability blast radius (minimal) — client exposure if the model is manipulated",
        "appliedPenalty": 0
      },
      {
        "kind": "client",
        "term": "verification-discount",
        "level": "repo",
        "label": "publisher verification (public source) — no provenance, but the source is public and inspectable",
        "appliedPenalty": 1
      },
      {
        "kind": "client",
        "term": "coverage-honesty",
        "level": "source",
        "label": "inspection depth (source) — how much of the target the scan could see",
        "appliedPenalty": 0
      }
    ],
    "gatesFired": [],
    "methodologyVersion": "mcptrustchecker-1.13"
  },
  "capability": {
    "level": "minimal",
    "reasons": [],
    "tags": []
  },
  "coverage": {
    "level": "source",
    "inputs": {
      "toolSurface": true,
      "implementationSource": true,
      "packageMetadata": true,
      "liveTransport": false
    },
    "caveats": [
      "Tools were statically extracted from the published source (82 recovered), not enumerated from a running server. Tool-poisoning, Unicode-smuggling, capability and toxic-flow analysis ran on this inferred surface, but a mis-parsed registration could be missed or mis-attributed, so tool-derived findings are capped below “confirmed”. To grade the real runtime surface, scan the running server: --command \"npx -y <package>\"."
    ]
  },
  "findings": [],
  "toxicFlows": [],
  "capabilities": [
    {
      "tool": "get_aws_auth_status",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_aws_identity",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_iam_role_summary",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "explain_iam_simulation_denial",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "list_kms_keys",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_kms_key_summary",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "check_kms_dependent_path",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "find_kms_key_lifecycle_blast_radius",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "list_lambda_functions",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_lambda_summary",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_lambda_event_source_mapping_diagnostics",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_lambda_alias_version_summary",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "investigate_lambda_deployment_drift",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_lambda_recent_errors",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "investigate_lambda_failure",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "investigate_lambda_cold_start_init",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "investigate_lambda_timeout_root_cause",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "audit_async_lambda_failure_path",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "investigate_lambda_concurrency_bottlenecks",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "explain_lambda_dependencies",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "explain_lambda_network_access",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "simulate_lambda_security_group_path",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "check_lambda_permission_path",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "check_lambda_to_sqs_sendability",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "prove_lambda_invocation_path",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "analyze_cross_account_lambda_invocation",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "list_step_functions",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_step_function_execution_summary",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "investigate_step_function_failure",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "audit_step_function_retry_catch_safety",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "explain_step_function_dependencies",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "list_s3_buckets",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "list_s3_objects",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_s3_bucket_summary",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "check_s3_notification_destination_readiness",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "list_dynamodb_tables",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_dynamodb_table_summary",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "check_dynamodb_stream_lambda_readiness",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "list_sqs_queues",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_sqs_queue_summary",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "explain_sqs_queue_dependencies",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "check_sqs_to_lambda_delivery",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "investigate_sqs_backlog_stall",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "analyze_queue_dlq_replay_readiness",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "list_sns_topics",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_sns_topic_summary",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "explain_sns_topic_dependencies",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "audit_sns_fanout_delivery_readiness",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "list_ecs_clusters",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "list_ecs_services",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_ecs_service_summary",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "list_cloudwatch_alarms",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_cloudwatch_alarm_summary",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "find_cloudwatch_alarm_coverage_gaps",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "list_cloudwatch_log_groups",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "search_cloudwatch_logs",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "query_cloudwatch_logs_insights",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "check_cloudwatch_logs_writeability",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "list_api_gateways",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_api_gateway_summary",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_api_gateway_authorizer_summary",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "analyze_api_gateway_authorizer_failures",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "explain_api_gateway_dependencies",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "investigate_api_gateway_route",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "list_eventbridge_rules",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_eventbridge_time_sources",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "explain_eventbridge_rule_dependencies",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "investigate_eventbridge_rule_delivery",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "audit_eventbridge_target_retry_dlq_safety",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "explain_event_driven_flow",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "diagnose_region_partition_mismatches",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "search_aws_resources",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "search_aws_resources_by_tag",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_cross_service_incident_brief",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "build_log_signal_correlation_timeline",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "plan_end_to_end_transaction_trace",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "get_risk_scored_dependency_health_summary",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "export_application_dependency_graph",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "run_first_blocked_edge_incident",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "analyze_resource_policy_condition_mismatches",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "audit_multi_region_drift_failover_readiness",
      "tags": [],
      "reasons": {}
    },
    {
      "tool": "generate_application_health_narrative",
      "tags": [],
      "reasons": {}
    }
  ],
  "surfaceDigest": "f1b74eee198981b26328e9568e90f72d95462937ed9227c1cc1fd9487f90cdd8",
  "stats": {
    "tools": 82,
    "prompts": 0,
    "resources": 0,
    "findingsBySeverity": {
      "critical": 0,
      "high": 0,
      "medium": 0,
      "low": 0,
      "info": 0
    }
  }
}