A single static Go binary that speaks the Model Context Protocol
and lets an agent run AWS CLI commands: any aws <service> <operation>
invocation, across every service the CLI supports, with a read-only-by-default
safety gate on anything that mutates state.
No Python, no uv, no runtime dependency to install โ just a binary and
an .mcp.json. It shells out to the aws binary already installed and
configured on the host (profile, SSO, IAM role, or static keys โ whatever
the AWS CLI's own credential chain resolves) instead of reimplementing the
AWS SDK, so it gets the full breadth of the CLI for free rather than a
hand-curated subset of services.
โจ Why this exists
An agent that only has a narrow, hand-picked set of AWS tools hits a wall
the moment you need something outside that set. This connector instead
wraps the AWS CLI itself, so an agent can run aws s3 ls, aws ec2 describe-instances, aws iam list-users โ anything the CLI can do โ
without waiting on a new tool to be written for it. Mutating commands are
blocked by default and require both a server-level opt-in and a per-call
confirm=true, so exploring/debugging is safe out of the box.
| Tool | What it does | Write? |
|---|
aws_exec | Run any aws <service> <operation> ... command. Read-only by default โ mutating commands need AWS_MCP_ALLOW_WRITE=true on the server and confirm=true on the call. | โ
(gated) |
aws_help | Show aws <service> [subcommand] help text โ always safe, use it to check exact syntax before calling aws_exec. | |
aws_whoami | Show the AWS identity (account, ARN, user/role) the configured credentials resolve to. | |
aws_list_profiles | List named profiles configured in ~/.aws/config on the host. | |
Every tool accepts an optional response_format: markdown (default,
pretty tables for a chat UI) or json (for programmatic use).
๐ Quickstart
Fastest path: grab a prebuilt bundle from the latest release โ
download aws-mcp-connector-plugin-<version>-<os>-<arch>.zip, unzip it,
and point Cowork/Claude at the plugin/ folder inside (see step 4 of
SETUP.md). No Go toolchain required.
From source:
cd go-server
go mod tidy
go build -o aws-connector-server .
cp aws-connector-server ../plugin/servers/go/
export AWS_PROFILE=default
./go-server/aws-connector-server
Or make build โ see the Makefile for every shortcut
(test, vet, fmt, lint, tidy).
Full walkthrough โ including wiring this up as a Claude/Cowork plugin โ is
in SETUP.md.
๐ Configuration
Everything is environment variables, passed through by the plugin's
.mcp.json:
| Variable | Purpose | Default |
|---|
AWS_PROFILE | Named profile from ~/.aws/config to use. | unset (default profile) |
AWS_REGION | Default region if not set elsewhere. | AWS CLI's own default |
AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY / AWS_SESSION_TOKEN | Static credentials โ only needed if not using a profile/SSO/role. | unset |
AWS_MCP_ALLOW_WRITE | "true" to permit mutating commands at all (still needs confirm=true per call). | false (read-only) |
AWS_MCP_ALLOWED_SERVICES | Comma-separated allowlist of AWS CLI service names, e.g. "s3,ec2". | unset (unrestricted) |
AWS_MCP_CLI_PATH | Path to the aws binary. | aws resolved via PATH |
๐งช Quality bar
This isn't a toy script โ it's got the same checks you'd expect from a
production Go service:
- โ
Unit tests for every input-validation path (
go test ./...)
- โ
go vet + gofmt clean
- โ
golangci-lint (govet, staticcheck, errcheck, gosec, and more)
- โ
govulncheck โ no known vulnerabilities in the dependency graph
- โ
CodeQL static security analysis on every push
- โ
End-to-end verified against a real (or sandboxed) AWS CLI backend โ not mocks
- โ
Dependabot keeps Go modules and Actions current
All of it runs in CI on every push and PR.
๐ท๏ธ Releases & versioning
Versions follow semver and are cut automatically by
release-please from
Conventional Commits on main:
fix: ... โ patch (v0.1.0 โ v0.1.1)
feat: ... โ minor (v0.1.1 โ v0.2.0)
feat!: ... / BREAKING CHANGE: footer โ major (v0.2.0 โ v1.0.0)
Every merged PR updates a standing "chore(main): release vX.Y.Z" PR
with an auto-generated CHANGELOG.md. Merging that PR:
- tags the release and publishes it on GitHub
- builds and attaches zipped, ready-to-install plugin bundles for
linux/darwin/windows ร amd64/arm64
- regenerates
server.json from those exact assets (fresh version +
SHA-256 hashes) and publishes it to the
official MCP Registry via
mcp-publisher, authenticated with GitHub OIDC โ no stored secrets
See .github/workflows/release-please.yml
and .github/workflows/publish-mcp-registry.yml
(also runnable by hand for an existing tag via workflow_dispatch).
๐ Layout
aws-mcp-connector/
โโโ README.md โ you are here
โโโ SETUP.md โ step-by-step setup guide
โโโ CONTRIBUTING.md โ how to contribute
โโโ CODE_OF_CONDUCT.md
โโโ SECURITY.md โ vulnerability reporting
โโโ CODEOWNERS
โโโ LICENSE โ MIT
โโโ Makefile โ build / test / lint shortcuts
โโโ .golangci.yml โ lint rules
โโโ release-please-config.json โ semver/changelog automation config
โโโ .release-please-manifest.json
โโโ server.json โ MCP Registry manifest (regenerated fresh per release by CI)
โโโ scripts/
โ โโโ render-server-json.sh โ rebuilds server.json from a release's zip assets
โโโ .github/
โ โโโ workflows/
โ โ โโโ ci.yml โ build, vet, test, lint, govulncheck
โ โ โโโ codeql.yml โ security scanning
โ โ โโโ pr-title.yml โ Conventional Commits PR title check
โ โ โโโ release-please.yml โ version PRs, tagging, GitHub releases
โ โ โโโ publish-mcp-registry.yml โ publishes server.json to the MCP Registry
โ โ โโโ rebuild-release-assets.yml โ manual re-attach fallback
โ โโโ ISSUE_TEMPLATE/
โ โโโ PULL_REQUEST_TEMPLATE.md
โ โโโ dependabot.yml
โโโ go-server/ โ the MCP server source
โ โโโ main.go
โ โโโ main_test.go
โ โโโ go.mod / go.sum
โ โโโ README.md
โโโ plugin/ โ installable Cowork/Claude plugin
โโโ .claude-plugin/plugin.json
โโโ .mcp.json โ holds credentials locally โ never commit real ones
โโโ servers/go/ โ compiled binary goes here
๐ค Contributing
PRs and issues are very welcome โ see CONTRIBUTING.md
for the full guide (setup, coding conventions, how to add a new tool) and
the Code of Conduct.
main is protected: every change, including the maintainer's, lands via
pull request with CI green. PR titles must follow
Conventional Commits โ that's what
drives the automatic versioning above.
Found a security issue? Please follow SECURITY.md
instead of opening a public issue.
๐ License
MIT ยฉ FerhatDundar