Historical AWS analysis CLI; not a current Cyntrisec product.
io.github.cyntrisec/cyntrisec MCP Server
This MCP server is a historical AWS analysis command-line interface project. The source describes cyntrisec-cli as created before Cyntrisec narrowed its company focus to EphemeralML and AIR v1. It is explicitly noted as not a current Cyntrisec product.
🛠️ Key Features
Historical AWS analysis CLI (cyntrisec-cli)
Packaged as a Python project on PyPI
Apache 2.0 licensed (as stated in the excerpt)
🚀 Use Cases
Reviewing prior AWS analysis tooling implemented as a CLI
Using it as historical reference rather than current product functionality
⚡ Developer Benefits
Source available via project metadata (PyPI listing and license badge)
Context for “pre-company project” lineage and naming (cyntrisec-cli)
⚠️ Limitations
Not a current Cyntrisec product
Marked as historical (“historical pre-company project”) in the provided excerpt
Historical pre-company project.cyntrisec-cli was created before Cyntrisec narrowed its company focus to EphemeralML and AIR v1. It is not a current Cyntrisec product, support surface, or commercial offering. The PyPI package name cyntrisec, CLI command cyntrisec, and MCP server ID io.github.cyntrisec/cyntrisec are retained only to avoid breaking historical installs.
image-download
CAUTION
Historical Software Disclaimer: This tool is no longer an active Cyntrisec product. It is provided "as is", without warranty of any kind.
While the CLI is a read-only analysis tool by default, the user assumes all responsibility for any actions taken based on its findings.
Always review generated remediation plans and Terraform code before application.
Historical AWS capability graph analysis and attack path discovery CLI.
A read-only CLI tool that historically:
Scans AWS infrastructure via AssumeRole
Builds a capability graph (IAM, network, dependencies)
Discovers attack paths from internet to sensitive targets
Prioritizes fixes by ROI (security impact + cost savings)
CLI (scan) --AssumeRole--> AWS Session --Describe/Get/List--> AWS APIs (read-only)
|
v
Collectors -> normalize -> Assets + Relationships -> AwsGraph
|
v
Attack path search (BFS/DFS)
|
v
Min-cut (remediation cuts)
|
v
Cost engine (ROI)
Local artifacts: ~/.cyntrisec/scans/<scan_id>/*.json
Installation
bash
pip install cyntrisec
Windows PATH Fix
If you see "cyntrisec is not recognized", the Scripts folder isn't on PATH:
powershell
# Option 1: Run with python -m
python -m cyntrisec --help
# Option 2: Add to PATH for current session
$env:PATH += ";$env:APPDATA\Python\Python311\Scripts"
Quick Start
Prerequisite: Ensure you have AWS CLI installed and configured with credentials (e.g., aws configure) or environment variables set. terraform is required for the setup step.
bash
# 1. Create the read-only IAM role in your account
cyntrisec setup iam 123456789012 --output role.tf
# 2. Apply the Terraformcd your-infra && terraform apply
# 3. Run a scan
cyntrisec scan --role-arn arn:aws:iam::123456789012:role/CyntrisecReadOnly
# 4. View attack paths
cyntrisec analyze paths --min-risk 0.5
# 5. Find minimal fixes (prioritized by ROI)
cyntrisec cuts --format json
# 6. Generate HTML report
cyntrisec report --output report.html
Commands
Core Analysis
Command
Description
scan
Scan AWS infrastructure
analyze paths
View attack paths
analyze findings
View security findings
analyze stats
View scan statistics
analyze business
Business entrypoint analysis
report
Generate HTML/JSON report
Setup & Validation
Command
Description
setup iam
Generate IAM role Terraform
validate-role
Validate IAM role permissions
Remediation
Command
Description
cuts
Find minimal fixes (Cost & ROI prioritized)
waste
Find unused IAM permissions
remediate
Generate or optionally apply Terraform plans (gated)
Policy Testing
Command
Description
can
Test "can X access Y?"
diff
Compare scan snapshots
comply
Check CIS AWS / SOC2 compliance
Agentic Interface
Command
Description
manifest
Output machine-readable capabilities
explain
Natural language explanations
ask
Query scans in plain English
serve
Run as MCP server for AI agents
MCP Server Mode
The historical CLI can still run as an MCP server for compatibility with existing local setups:
bash
# Install with MCP support (now included by default)
pip install cyntrisec
bash
cyntrisec serve # Start stdio server
cyntrisec serve --list-tools # List available tools
This tool makes read-only API calls to your AWS account. The IAM role
should have only Describe*, Get*, List* permissions.
No Data Exfiltration
All data stays on your local machine. Nothing is sent to external servers.
Scan results are stored in ~/.cyntrisec/scans/.
No Auto-Remediation (Default Safe Mode)
By default, Cyntrisec is read-only and does not modify your AWS infrastructure.
It analyzes your account using read-only APIs.
It can generate remediation artifacts (e.g., Terraform modules) for you to review.
It does not apply changes automatically.
Optional Remediation Execution (Explicit Opt-In)
Cyntrisec includes an explicitly gated path that can execute Terraform only if you intentionally enable it.
This mode is:
Disabled by default
Requires --enable-unsafe-write-mode
Requires an additional explicit flag (e.g. --execute-terraform) to run Terraform
Intended for controlled environments (sandbox / CI with approvals), not unattended production
If you do not pass these flags, Cyntrisec will never run terraform apply.
Write Operations
Cyntrisec makes no AWS write API calls during scanning and analysis.
The only supported "write" behavior is optional execution of Terraform locally on your machine, and only when explicitly enabled via unsafe flags.
Every AWS API call is logged in CloudTrail under session name cyntrisec-cli.
Trust & Permissions
Cyntrisec runs with a read-only IAM role. Generate the recommended policy with
cyntrisec setup iam <ACCOUNT_ID> and keep permissions to Describe*, Get*,
and List*. Live modes (waste --live, can --live) require extra IAM
permissions; the generated policy and docs cover those additions.
Output Format
Primary output is JSON to stdout. When stdout is not a TTY, the CLI automatically switches to JSON: