Amazon GuardDuty MCP Server Integration Guide
Section A: Quick Answer & Architectural Summary
The Amazon GuardDuty Model Context Protocol (MCP) integration bridges AI coding assistants to the Amazon GuardDuty ai & ml API. It exposes 10 validated endpoint operations as callable tools for Claude Desktop, Cursor, and VS Code. Configuration is managed via hosted registry at /config/amazonaws-com-guardduty.json or local stdio bridge execution. Operates with zero authentication credentials out of the box. Contains 5 mutating operations (POST/PUT/DELETE); user confirmation is recommended before triggering write operations.
MCPBridge Editorial Verdict: Amazon GuardDuty
AI coding workflows requiring programmatic access to Amazon GuardDuty (AI & ML) endpoints
Low (1-2 mins)
Zero Authentication Required
Automated Spec Tracking
Claude Desktop, Cursor IDE, VS Code (Cline), Zed Editor
Read & Mutating endpoints; client confirmation and least-privilege token recommended
MCPBridge rates Amazon GuardDuty as a standardized OpenAPI-to-MCP bridge providing structured tool definitions across 10 endpoints.
Technical Overview & Protocol Integration
Amazon GuardDuty is a managed threat detection service provided by Amazon Web Services (AWS) that continuously monitors for malicious activity and unauthorized behavior across an organization's AWS accounts and workloads. By analyzing a broad spectrum of data sources including VPC flow logs, CloudTrail management and S3 data event logs, EKS audit logs, DNS logs, and EBS volume data, GuardDuty employs machine learning, anomaly detection, and integrated threat intelligence to identify potential security threats such as cryptocurrency mining, credential compromise, reconnaissance, and unauthorized access patterns. The GuardDuty API exposes a comprehensive set of management operations for security engineers and DevOps teams operating at enterprise scale. Its core capabilities include programmatically managing detectors (the foundational resource for threat monitoring), configuring administrator and member account relationships for centralized security governance, creating and managing IP address sets and threat lists for custom threat context, and applying granular filters to refine findings and reduce alert noise. Typical use cases span multi-account security orchestration, compliance auditing, automated incident response workflows, and security posture reporting across large cloud estates.
When exposed as tools to an AI coding assistant through the Model Context Protocol (MCP), the GuardDuty API unlocks a powerful paradigm where a developer can interact with their cloud security infrastructure using natural language. An AI agent gains the ability to query the current state of security monitoring configurations, inspect active detectors, review administrative relationships, and understand the filtering and IP set landscape — all without requiring the developer to memorize complex CLI syntax or navigate the AWS console. This integration is particularly valuable for security-focused development teams who need to audit configurations, remediate misconfigurations, or set up GuardDuty across new accounts rapidly. The MCP server transforms the AI assistant into a context-aware security operations companion that can reason about the current state of a GuardDuty deployment, identify gaps in monitoring coverage, and suggest or execute corrective actions. For example, when a developer asks the AI to assess their threat detection posture, the agent can enumerate all detectors, examine their settings, and provide a clear summary — bridging the gap between raw API responses and actionable human understanding.
The practical workflow benefits of this integration are substantial and multifaceted. A developer can instruct the AI to list all active detectors across regions and verify that monitoring is enabled in every expected account, automatically flagging any accounts where detectors are absent or misconfigured. When onboarding a new member account to an organization's security baseline, the developer can ask the AI to retrieve the current master-administrator relationship and then create or update the appropriate administrative delegation so the central security team maintains full visibility. If an SOC analyst reports that a specific set of known-external IP addresses should be whitelisted from findings, the developer can instruct the AI to retrieve the current IP set configuration and add or modify entries accordingly. Teams managing large numbers of custom finding filters can ask the AI to list existing filters, assess whether any are outdated or overlapping, and propose a cleaned-up configuration. When archiving stale findings to improve signal-to-noise ratio in dashboards, the agent can trigger the findings archive operation on demand. In a compliance context, the AI can be instructed to systematically audit the entire GuardDuty setup — checking detector status, filter definitions, IP sets, and administrative links — and produce a structured report suitable for an auditor or for inclusion in an internal security review document.
Developers implementing this MCP server should be acutely aware that the API operations carry significant security implications, as they control the configuration of a critical threat detection service. Authentication must be handled through properly scoped AWS IAM credentials with only the minimum permissions required for each operation — following the principle of least privilege is not merely a best practice here but a security imperative, since overly permissive credentials could allow an attacker to disable monitoring, delete findings, or manipulate administrative relationships to evade detection. It is strongly recommended that the MCP server's credentials be restricted to specific GuardDuty actions on specific detector IDs where possible, rather than granted blanket administrative access. All API calls should be transmitted over TLS, and the server should never log or expose sensitive credential material. Organizations should also consider implementing approval workflows for mutating operations such as creating administrators, modifying master relationships, or archiving findings, ensuring that no automated action undermines the integrity of the security monitoring pipeline. Regular audits of who and what has access to the GuardDuty API surface, combined with CloudTrail logging of all API invocations, will provide the accountability and visibility needed to maintain a robust security posture.
By translating the OpenAPI 3.0 specification for Amazon GuardDuty into native Model Context Protocol (MCP) tool definitions, developers and AI agents gain programmatic access to endpoints over stdio or HTTP transports. Every endpoint is translated into a discrete tool payload complete with input argument validation, parameter descriptions, and return type definitions.
2. Technical Specifications Matrix
System Specifications
| API Name | Amazon GuardDuty |
| Slug Identifier | amazonaws-com-guardduty |
| Category | AI & ML |
| Auth Method | None Required |
| Endpoint Count | 10 tools mapped |
| Spec Version | OpenAPI v2017-11-28 |
| Transport Type | STDIO |
| Publisher Source | auto |
3. Multi-Client Installation Matrix
Copy and paste these pre-formatted JSON snippets into your MCP client configuration files.
Claude Desktop
Add to claude_desktop_config.json
{
"mcpServers": {
"amazonaws-com-guardduty": {
"command": "npx",
"args": [
"-y",
"@modelcontextprotocol/server-openapi",
"https://api.apis.guru/v2/specs/amazonaws.com/guardduty/2017-11-28/openapi.json"
],
"env": {
"AMAZON_GUARDDUTY_API_KEY": "your_amazon_guardduty_api_key"
}
}
}
}Cursor IDE
Settings → MCP Servers → Add Hosted Config
{
"mcpServers": {
"amazonaws-com-guardduty": {
"url": "https://mcpbridge.org/config/amazonaws-com-guardduty.json"
}
}
}Saves as .cursor/mcp.json in the download. Move it to your project root.
VS Code / Cline
Use with MCP extension config
{
"mcpServers": {
"amazonaws-com-guardduty": {
"url": "https://mcpbridge.org/config/amazonaws-com-guardduty.json"
}
}
}4. Security Architecture & Credentials Reference
Key parameters and credential variable mappings for Amazon GuardDuty.
Security Considerations & Sandbox Guidance: Amazon GuardDuty
Authorization credential isolation, least privilege boundaries, and container sandboxing options.
None Required
Read & Mutating Operations
Local MCP bridge process making outbound HTTPS requests to upstream API
Isolation & Principle of Least Privilege
Ensure outbound network access to the API endpoint is permitted. Use restricted API tokens with minimal read/write scopes.
Actionable Operational Guidelines
- Verify network firewall rules allow outbound traffic to upstream API endpoints.
- Review arguments for mutating endpoints (/detector/{detectorId}/administrator, /detector/{detectorId}/master, /detector/{detectorId}/findings/archive) before execution.
- Apply token rate limits and monitor usage in your provider dashboard to prevent unexpected quota consumption.
| Variable Name | Required | Example Value |
|---|---|---|
| AMAZON_GUARDDUTY_API_KEY | REQUIRED | your_amazon_guardduty_api_key |
5. Endpoints & Tool Schemas Matrix
Search and inspect the 10 tool signatures mapped from OpenAPI.
Executable Code Integration Examples
Call Amazon GuardDuty endpoints via cURL, TypeScript, or Python REST SDKs.
curl -X GET "https://api.apis.guru/v2/specs/amazonaws.com/guardduty/2017-11-28/detector/{detectorId}/administrator" \
-H "Content-Type: application/json" \
# No auth requiredConcrete Real-World Use Cases for Amazon GuardDuty
Practical multi-step agentic workflows and prompt directives demonstrating concrete developer outcomes.
Automated Contextual Workflow Integration
The practical workflow benefits of this integration are substantial and multifaceted. A developer can instruct the AI to list all active detectors across regions and verify that monitoring is enabled in every expected account, automatically flagging any accounts where detectors are absent or misconfigured. When onboarding a new member account to an organization's security baseline, the developer can ask the AI to retrieve the current master-administrator relationship and then create or update the appropriate administrative delegation so the central security team maintains full visibility. If an SOC analyst reports that a specific set of known-external IP addresses should be whitelisted from findings, the developer can instruct the AI to retrieve the current IP set configuration and add or modify entries accordingly. Teams managing large numbers of custom finding filters can ask the AI to list existing filters, assess whether any are outdated or overlapping, and propose a cleaned-up configuration. When archiving stale findings to improve signal-to-noise ratio in dashboards, the agent can trigger the findings archive operation on demand. In a compliance context, the AI can be instructed to systematically audit the entire GuardDuty setup — checking detector status, filter definitions, IP sets, and administrative links — and produce a structured report suitable for an auditor or for inclusion in an internal security review document.
- AI assistant inspects prompt context and selects relevant tool
- Validates parameter payload against OpenAPI JSON Schema
- Executes tool call and formats structured API response
Data Inspection & Resource Querying
Query Amazon GuardDuty resources such as "/detector/{detectorId}/administrator" to retrieve contextual data directly during coding sessions.
- Agent selects /detector/{detectorId}/administrator tool
- Passes search filters or resource identifiers
- Renders JSON payload in chat context for developer review
Automated Mutation & Resource Creation
Execute state changes and create records through POST operations like "/detector/{detectorId}/administrator" with parameter validation.
- Agent constructs validated request body matching schema
- Prompts user for execution confirmation
- Executes tool and confirms response status
Good Fit vs. Poor Fit Criteria for Amazon GuardDuty
Architectural guidelines to determine when to adopt this integration and when to explore alternatives.
When to Choose / Good Fit
- AI coding assistants in Claude Desktop or Cursor requiring structured tool access to Amazon GuardDuty.
- Developers who want standardized OpenAPI-to-MCP translation without building custom server code.
- Workflows that benefit from automated parameter validation against official OpenAPI 3.0 schemas.
- Teams seeking zero-maintenance hosted JSON configurations for easy distribution.
When to Avoid / Poor Fit
- Ultra-high frequency data ingestion exceeding typical LLM context windows and token rate limits.
- Unattended autonomous agent loops with write access where human approval of mutations is mandatory.
- Environments lacking outbound internet access to upstream Amazon GuardDuty API servers.
Verification & Evidence Audit: Amazon GuardDuty
OpenAPI 3.0 specification parsed and validated via automated build pipeline.
Independent Evidence Checks
Valid specification version 2017-11-28 with 10 endpoints indexed.
No authentication required.
JSON Schemas mapped to MCP tools/call standard format.
Automated schema validation only; live upstream API calls require developer credentials.
Project Health & Maintenance Audit: Amazon GuardDuty
Activity & Cadence
Transparent Quality Score Breakdown
Alternatives & Comparison Table (AI & ML)
Comparative trade-offs between Amazon GuardDuty and similar ecosystem tools in the AI & ML category.
| Option | Best For | Main Difference vs. Amazon GuardDuty | Setup / Runtime | Explore |
|---|---|---|---|---|
| Amazon Augmented AI Runtime | Developers needing AI & ML operations with 5 tools | 5 endpoints vs 10 endpoints | auto / v2019-11-07 | View → |
| Amazon CodeGuru Profiler | Developers needing AI & ML operations with 10 tools | 10 endpoints vs 10 endpoints | auto / v2019-07-18 | View → |
| Amazon CodeGuru Reviewer | Developers needing AI & ML operations with 10 tools | 10 endpoints vs 10 endpoints | auto / v2019-09-19 | View → |
9. Error Resolution & Troubleshooting Guide
Contextual diagnostics for HTTP status codes and JSON-RPC tool bridge operations.
-32600 (Invalid Request)Root Cause: Malformed JSON-RPC payload sent to local MCP bridge process.
Resolution Action: Verify MCP client payload adheres to JSON-RPC 2.0 specification.
-32601 (Method Not Found)Root Cause: Requested operation does not exist in mapped Amazon GuardDuty OpenAPI endpoint schemas.
Resolution Action: Inspect Section 5 endpoints table to confirm valid method names and paths.
-32602 (Invalid Params)Root Cause: Missing or invalid parameters for target tool operation.
Resolution Action: Check parameter data types against OpenAPI JSON Schema specification.
429 Rate Limit ExceededRoot Cause: Upstream Amazon GuardDuty API request rate limit quota reached.
Resolution Action: Implement exponential backoff in tool execution loop or verify provider plan quotas.
OPENAPI_GATEWAY_TIMEOUTRoot Cause: Upstream Amazon GuardDuty endpoint response latency exceeded timeout threshold.
Resolution Action: Verify network connectivity and check provider system status dashboard.
Official Verified Sources for Amazon GuardDuty
Authoritative upstream repositories, specifications, package registries, and configuration endpoints.
Official Upstream Documentation
Official developer documentation and API reference for Amazon GuardDuty.
https://docs.aws.amazon.com/guardduty/OpenAPI 3.0 Specification
Machine-readable OpenAPI schema source used for MCP tool mapping.
https://api.apis.guru/v2/specs/amazonaws.com/guardduty/2017-11-28/openapi.jsonHosted MCPBridge Configuration
Pre-generated Model Context Protocol JSON configuration hosted on MCPBridge.
https://mcpbridge.org/config/amazonaws-com-guardduty.jsonOpenAPI-to-MCP Converter Tool
Client-side browser converter to customize or filter endpoint tools.
https://mcpbridge.org/convert/Claim & Maintainer Verification
Submit a claim to verify API publisher ownership and update metadata.
https://github.com/stormlive-ai/mcp-bridge-docs/issues/new?title=Claim+Listing%3A+Amazon+GuardDuty+%28api%3A+amazonaws-com-guardduty%29&labels=claim-listing&body=%23%23+Claim+Listing+Request%0A%0AI+would+like+to+claim+this+listing%3A%0A%0A-+**Type%3A**+api%0A-+**ID%3A**+amazonaws-com-guardduty%0A-+**Name%3A**+Amazon+GuardDuty%0A%0A%23%23%23+Your+Information%0A%0A**GitHub+Handle%3A**+%3C%21--+your+GitHub+username+--%3E%0A%0A**Email%3A**+%3C%21--+optional%2C+for+verification+--%3E%0A%0A**Relationship+to+this+API%3A**%0A-+%5B+%5D+I+am+the+API+provider+%2F+maintainer%0A-+%5B+%5D+I+am+an+authorized+representative%0A-+%5B+%5D+Other%3A%0A%0A%23%23%23+Verification+Method%0A-+%5B+%5D+I+will+add+a+CNAME%2FTXT+record+to+verify+domain+ownership%0A-+%5B+%5D+I+can+confirm+from+an+email+address+at+the+provider+domain%0A-+%5B+%5D+I+maintain+the+GitHub+repository%0A%0A%23%23%23+Updates+I%27d+Like+to+Make+%28optional%29%0A%3C%21--+What+would+you+like+to+update%3F+Description%2C+links%2C+category%2C+etc.+--%3E%0A%0A---%0A*Submitted+via+MCP-Bridge+claim+form*Frequently Asked Technical Questions: Amazon GuardDuty
Targeted developer questions regarding installation, client configuration, credentials, and error resolution.
The Amazon GuardDuty MCP server connects AI coding assistants (Claude Desktop, Cursor, VS Code, Zed) to the Amazon GuardDuty API using the Model Context Protocol. It converts 10 OpenAPI operations into native MCP tools callable during chat sessions.