Install
$ agentstack add mcp-sarteta-mcp-cloudwatch-explorer ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
mcp-cloudwatch-explorer
MCP-native AWS CloudWatch explorer. Lets an AI agent (Claude, etc) query metrics, alarms, and logs over MCP — read-only by design — so you can ask "what's wrong with prod?" in a chat and get a useful answer instead of a 4-tab CloudWatch console session.
flowchart LR
A[Claude / MCP client] -- tool call --> S[mcp-cloudwatch-explorer]
S -- boto3 cloudwatch / logs --> CW[CloudWatch metricsalarms · logs]
CW --> S
S -- ranked findings --> A
Tools exposed (implemented)
| Tool | Returns | |---|---| | list_alarms_in_alarm(region) | All CloudWatch alarms currently in ALARM state | | get_metric_stats(namespace, metric, dimensions, period_min, hours) | Datapoints for a metric over the last N hours | | recent_log_errors(log_group, hours) | Recent ERROR / Exception lines from a log group | | summarize_health(region) | One-shot health snapshot: alarms in ALARM + count by namespace |
Roadmap
top_metrics_by_breach(region, hours)— metrics that breached their threshold most in last N hours (needs CloudWatch metric history aggregation)
Why MCP
Standard CloudWatch usage:
- SSH or open Console.
- Click through dashboards.
- Filter by service.
- Try to remember the metric name.
- Eyeball the graph.
With MCP:
> Hey, looks like prod is slow. Anything alarming?
[claude calls list_alarms_in_alarm + summarize_health]
Yes — 2 alarms in ALARM right now in us-east-1:
- ALB-5xx-rate (api-prod) breached 3 times in last hour
- RDS-CPUUtilization (db-prod-1) at 87% sustained
Top recent log errors in /aws/lambda/api-prod:
- ConnectionPool exhausted (47x)
- DDB throttling on Users.GetItem (12x)
Probable root cause: connection pool saturation under high traffic
caused by the 5xx rate.
That's a 30-second triage instead of 5 minutes of console-clicking.
Quick start
pip install -e .
# AWS creds via your usual mechanism
export AWS_PROFILE=mycompany-readonly
python -m mcp_cloudwatch_explorer.server
For Claude Desktop, add to your MCP config:
{
"mcpServers": {
"cloudwatch-explorer": {
"command": "python",
"args": ["-m", "mcp_cloudwatch_explorer.server"],
"env": {"AWS_PROFILE": "mycompany-readonly"}
}
}
}
Safety
- Scoped IAM: needs only
cloudwatch:Describe*,cloudwatch:Get*,
logs:Describe*, logs:FilterLogEvents. Never write.
- No mutation tools. By design.
- Pagination + AWS API throttle handling on every
describe_*call.
Related projects
mcp-postgres-doctor— read-only Postgres diagnostics over MCP.mcp-aws-cost-doctor— AWS cost-leak finder over MCP.
The three together cover Postgres + AWS cost + AWS observability for one agent session — a single Claude conversation can audit your DB, your spend, and your alarms.
License
MIT
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: sarteta
- Source: sarteta/mcp-cloudwatch-explorer
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.