目录 / cloud-security-scanner
cloud-security-scanner
Cloud security scanning tools for AI agents. 7 purpose-built AWS scanners that check for misconfigurations across S3, IAM, EC2, EKS, RDS, CloudTrail, and CloudWatch Logs. Each scanner is a static ~2MB binary that outputs JSONL. Checks include public access, missing encryption, stale credentials, weak password policies, disabled logging, and more. ## Tools - **search** — Find scanners by capability (e.g. "encryption", "public access", "iam") - **get** — Get download URL, SHA256 hash, and a ready-to-run shell command for any scanner ## Scanners | Scanner | Service | Checks | |---|---|---| | k5e-aws-s3 | S3 | encryption, public access, versioning, logging, lifecycle | | k5e-aws-iam | IAM | root MFA, stale access keys, password policy | | k5e-aws-ec2 | EC2 | public SSH, security groups, EBS encryption, IMDSv2 | | k5e-aws-eks | EKS | public endpoint, logging, secrets encryption | | k5e-aws-rds | RDS | public access, encryption, backups | | k5e-aws-cloudtrail | CloudTrail | multi-region, log validation, KMS encryption | | k5e-aws-cloudwatch-logs | CloudWatch Logs | retention, encryption, metric filters | Built by [Kloudle](https://kloudle.com).
接入信息
- 传输形态
- http
- 鉴权方式
- 鉴权未知
- 端点
https://cloud-security-scanner--kloudle.run.tools
{
"mcpServers": {
"cloud-security-scanner": {
"url": "https://cloud-security-scanner--kloudle.run.tools"
}
}
}
能力清单
| 工具 | 说明 |
|---|---|
| search | Find k5e cloud security scanners by capability. Returns matching binaries with name, description, check count, and severity breakdown. |
| get | Get full metadata, SHA256 hash, download URL, and ready-to-run shell command for a k5e binary. Pass args to get a complete command; omit for a template with placeholders. |
提交举报 / 纠错
侵权举报经核验成立后,我们会即时下线该条目并删除已存的内容副本。