MCP 服务器

Stigmer

network.stigmer/stigmer-mcp
云与基础设施 开发者工具 安全 公开且可连接 MCP 2026-07-28

此 MCP 可以做什么

Discovers verified AWS method contracts, generates least-privilege IAM policies, and evaluates AWS authorization before and after policy creation.

authorize
Pre-flight authorization check for an AWS operation. Resolves the IAM actions the operation requires, then asks AWS's own policy simulator (SimulatePrincipalPolicy) whether the current role (or a given principal) allows them. Returns resolution (exact|partial|unresolved) and evaluation (allowed|denied|unknown) as separate fields. Requires AWS credentials; without them evaluation=unknown with the reason.
输入模式
{'type': 'object', 'properties': {'workflow': {'type': 'string', 'description': "A named workflow from list_workflows (e.g. 's3-multipart-kms')"}, 'operations': {'type': 'string', 'description': "IAM action strings or SDK symbols, comma-separated (e.g. 's3:PutObject' or 's3.PutObject')"}, 'principal_arn': {'type': 'string', 'description': 'Optional. IAM role/user ARN to simulate against. Defaults to the current caller via sts:GetCallerIdentity.'}}}
list_methods
List all methods for a given library or service. Use after list_services to drill into a specific one.
输入模式
{'type': 'object', 'required': ['service'], 'properties': {'service': {'type': 'string', 'description': 'Library or service name. Get these from list_services first.'}}}
list_services
List all libraries and services that have verified method contracts. Use this first to discover what's available, then query for specific methods.
输入模式
{'type': 'object', 'properties': {}}
list_workflows
List the curated named workflows that can generate least-privilege IAM policies.
输入模式
{'type': 'object', 'properties': {}}
policy
Generate a least-privilege IAM policy for an AWS workflow. Pass a named workflow, explicit IAM actions, or a description. Returns the exact policy with confidence tier and any unresolved operations.
输入模式
{'type': 'object', 'properties': {'workflow': {'type': 'string', 'description': "A named workflow from list_workflows (e.g. 's3-multipart-kms')"}, 'operations': {'type': 'string', 'description': "Explicit IAM action strings or SDK symbols, comma-separated (e.g. 's3:PutObject,s3:GetObject')"}, 'description': {'type': 'string', 'description': "Describe the workflow (e.g. 'upload a large file to S3 with KMS')"}}}
query
Search for verified method contracts for any library. Pass any text -- library name, method, what you're building, or an error you hit.
输入模式
{'type': 'object', 'properties': {'sig': {'type': 'string'}, 'limit': {'type': 'integer'}, 'query': {'type': 'string', 'description': "What are you looking for? A method name, a library, an error message, or what you're building. Examples: s3 put_object, auto_gptq import, pandas merge, ImportError peft."}, 'packages': {'type': 'array', 'items': {'type': 'string'}}, 'error_type': {'type': 'string', 'description': '(deprecated -- use query instead) Error type if searching by error'}}}
register
Register a fix. Three actions: confirm (it worked), append_thread (variant worked), new_receipt (nothing matched, I fixed it).
输入模式
{'type': 'object', 'required': ['action', 'library', 'symbol'], 'properties': {'env': {'type': 'string'}, 'fix': {'type': 'string'}, 'error': {'type': 'string'}, 'action': {'enum': ['confirm', 'append_thread', 'new_receipt'], 'type': 'string'}, 'symbol': {'type': 'string'}, 'library': {'type': 'string'}, 'version': {'type': 'string'}, 'error_class': {'type': 'string'}, 'receipt_sig': {'type': 'string'}}}
verify
Feed a generated policy back to AWS's own policy evaluation engine (SimulateCustomPolicy) and confirm it grants exactly the intended operations and nothing extra. Returns verified (True|False|unknown), grants_all, grants_extra. Requires AWS credentials; without them verified=unknown with the reason. Wildcarded operations are expanded to concrete actions first.
输入模式
{'type': 'object', 'properties': {'policy': {'type': 'string', 'description': 'Optional. A complete IAM policy JSON document to verify.'}, 'workflow': {'type': 'string', 'description': 'A named workflow from list_workflows to generate and then verify'}, 'operations': {'type': 'string', 'description': 'Intended IAM actions, comma-separated. Required if policy is provided.'}}}
已添加
register
2026年9月17日 12:54
已添加
authorize
2026年9月17日 12:54
已添加
verify
2026年9月17日 12:54
已添加
list_workflows
2026年9月17日 12:54
已添加
policy
2026年9月17日 12:54
已添加
list_methods
2026年9月17日 12:54
已添加
list_services
2026年9月17日 12:54
已添加
query
2026年9月17日 12:54