mrkeyoor.com_
Wed 30 Sept 15:11 UTC
LLM Toolsevaluationupdated 30 Sept 2026

agent-toolkit-for-aws review

Agent Toolkit for AWS gives coding agents AWS instructions, plugins, and a managed Model Context Protocol server. It helps Claude Code, Codex, Cursor, Kiro, fx, and other clients choose services, inspect documentation, call AWS APIs, and carry out cloud work under your AWS permissions.

Verdict

Our lab produced no install or test result because this Python repository had no supported harness path and no Dockerfile. Agent Toolkit for AWS is still the best first trial for an AWS team that wants vendor-supported MCP, Claude Code and Codex plugins, local skills, IAM controls, and CloudTrail records in one place. Do not connect it to a powerful account until agent-specific permissions and human approval boundaries are written down.

We ran it

Screenshot of agent-toolkit-for-aws (github.com/aws/agent-toolkit-for-aws)

Answers from our run

Did you run agent-toolkit-for-aws yourself?

No. Its code is Python, and it carries no manifest our lab installs from, and no Dockerfile, so there was nothing standard to install, build or test. This review is written from the repository's own documentation.

Who should not use agent-toolkit-for-aws?

Teams that cannot give an agent any AWS execution path: the managed MCP server can call AWS APIs and run scripts, so IAM design is part of setup.

What are the alternatives to agent-toolkit-for-aws?

AWS Labs MCP servers, AWS CLI, AWS CDK. Our lab produced no install or test result because this Python repository had no supported harness path and no Dockerfile.

Setup3/5Plugin paths are short; IAM and client differences are not
Docs4/5Clear client recipes and a separate AWS user guide
Community4/52,758 stars and active issue work on September 30, 2026
Maturity3/5GA badge and AWS support, but no GitHub release exists yet

Who it’s for

AWS teams that want one supported agent layer for architecture, deployment, operations, data, or Bedrock work.
Claude Code, Codex, and Cursor users who prefer a packaged plugin over assembling skills and MCP configuration by hand.
Platform teams prepared to restrict agent activity with IAM and review it through CloudTrail.
Developers who want local AWS guidance even when they do not enable runtime API access.

Who it’s NOT for

Teams that cannot give an agent any AWS execution path: the managed MCP server can call AWS APIs and run scripts, so IAM design is part of setup.
Organizations requiring the complete tool plane to be self-hosted: the main AWS MCP endpoint is a managed AWS service.
Multi-cloud teams seeking neutral advice: the plugins are built to select, migrate to, and operate AWS services.
Codex users installing aws-agents-for-devsecops without checking issue 198: its default MCP URL interpolation can fail before startup, while the other named plugins use different configurations.
Graviton migration teams relying on remote transform verification: open issue 64 says that path still runs its post-transform build and tests on x86.

Setup reality

We did not run this repository. The lab harness had no supported ecosystem for its Python code, and the repository had no Dockerfile, so there are no measured install, build, test, dependency, timing, or audit results to report.

The shortest supported path is aws configure agent-toolkit, while Claude Code, Codex, and Cursor can install plugins. Kiro, fx, and other clients need uv, an MCP configuration, and optional local skills. AWS credentials are required for API calls and script execution, but not for documentation search or skill discovery.

Real deployment effort sits in IAM policy, account and region selection, audit review, and deciding which plugins may act. The repository has no GitHub release yet, despite its GA badge, so pinning and change control need extra attention.

Five plugins split AWS work by job

Agent Toolkit for AWS packages 5 named plugins rather than presenting one huge instruction file. aws-core covers service choice, infrastructure, serverless, containers, storage, observability, billing, SDK use, and deployment. Other plugins focus on Bedrock and AgentCore, data analytics, development security work, or startup architecture and migration. Claude Code, Codex, and Cursor can install these bundles, which combine agent skills with the AWS MCP Server configuration.

The toolkit has 3 separable layers. Skills are local instruction folders loaded when a task matches. Rules files tell an agent how a project expects AWS work to happen. The managed MCP server supplies live documentation, API access, and script execution. Kiro and fx users configure that server and install skills independently. This separation is useful when a team wants better AWS answers before it is ready to let the agent touch an account.

What happened when we ran it

No sandbox result exists for this repository. Our harness did not support its Python ecosystem, and the repository provides no Dockerfile that the lab could use as a defined runtime path. We therefore have no measured install duration, dependency footprint, build result, test count, vulnerability audit, or runtime behavior. Any claim that it was easy to install or passed tests would be invented.

The missing run matters more here because the product spans local files, client plugin formats, a proxy launched through uvx, and a managed AWS endpoint. The Kiro example contacts an endpoint in us-east-1 while passing us-west-2 as the working region. A useful evaluation must include the exact client, region, authentication method, IAM policy, and a harmless API call whose CloudTrail record you can inspect. Our lab did none of those things.

The server reaches 300-plus AWS services, so IAM decides the risk

The AWS MCP Server advertises access across more than 300 AWS services through one authenticated endpoint. It also offers isolated Python script execution and current AWS documentation search. Documentation lookup and local skill discovery do not need AWS credentials. API calls and scripts do. That distinction lets a team begin with research, then add account access only after it has decided what the agent may read or change.

AWS supplies IAM context conditions intended to distinguish agent actions from human actions. The README also points to 2 operating records: CloudTrail events for requests and CloudWatch metrics for monitoring. Those controls are the strongest reason to prefer this toolkit over handing a model a broadly configured shell. They are not automatic least privilege. A role that can create, delete, or modify resources remains powerful when the caller is an agent, even if every call is recorded.

Claude Code and Codex get direct plugin commands, with one Codex fault

Claude Code can install 3 main plugins, aws-core, aws-agents, and aws-data-analytics, from Anthropic's official marketplace. Codex users add the AWS repository as a plugin marketplace and browse aws-core through /plugins. Cursor has a team marketplace route. Kiro and fx use direct MCP JSON plus skills. Every route eventually needs a deliberate choice between local guidance and authenticated execution.

Open issue 198 narrows a current Codex problem to the aws-agents-for-devsecops plugin version 1.0.0. Its MCP URL contains shell-style region interpolation that Codex 0.145.0.289 keeps as literal text, so the HTTP client fails before MCP initialization. The reporter tested aws-core, aws-agents, and aws-data-analytics successfully in the same installation. This is not evidence that every Codex plugin is broken, but it is a reason to verify each installed bundle.

The GA badge arrived before a GitHub release

GitHub showed 2,758 stars, 28 open issues, and 17 open pull requests on September 30, 2026. The repository was created on April 23 and pushed on September 30. Recent activity included startup migration work, observability guidance, model catalog updates, and Well-Architected proposals. That combination shows a young repository receiving daily work, not a finished interface that changes only on a slow release schedule.

There was no latest GitHub release to inspect on September 30, even though the README status badge says GA. Teams that require immutable release artifacts should decide whether to pin a commit, consume a marketplace version, or wait for repository tags. Open issue 64 also records an x86 limit in remote post-transform verification for a Graviton migration path. Active development is useful, but these details belong in an adoption ticket.

It replaces a collection only when the supported path covers your task

AWS began publishing MCP servers, skills, and plugins through AWS Labs in 2025, and now calls Agent Toolkit their successor. The older awslabs/mcp project remains available and accepts contributions while selected work moves over. That makes the toolkit the sensible starting point, especially for agent-aware IAM conditions and central audit records. It does not mean every specialized Labs server has an equivalent bundle here today.

Adopt it one permission slice at a time. Start with 1 read-only account role, confirm the CloudTrail identity, then authorize narrow changes with a person reviewing the plan. The toolkit makes that progression possible across several coding agents. Its value disappears if the first setup step attaches broad credentials and treats an audit log as permission to let the model do anything.

Alternatives

ProjectWhat it isPick it when
AWS Labs MCP servers gh↗A collection of specialized open-source MCP servers for AWS services and workflows.pick this instead when you need one narrow local server that has not moved into the supported toolkit.
AWS CLIThe official command-line client for direct AWS service operations.pick this instead when a person or scripted pipeline should issue explicit commands without an agent layer.
AWS CDKInfrastructure as code for defining AWS resources in supported programming languages.pick this instead when reviewable infrastructure definitions matter more than conversational cloud operation.

What people are saying

  1. [github-trending] aws/agent-toolkit-for-aws

Sources

  1. Agent Toolkit for AWS README
  2. AWS MCP Server tools
  3. Codex DevSecOps MCP URL issue
  4. ARM64 remote transform issue

More llm tools reviews

agent-memory · codex-astra-luna-orchestrator · okf-agent-memory · mlc-llm · awesome-openclaw-skills · TensorFold · the whole board →