Stigmer
Execution graph of AWS: verified contracts, least-privilege IAM policies, pre-flight authorization.
使うべきか
品質と安全性
ツール定義とプロトコルへの準拠に関する自動分析に基づいています。
コンテキストコスト
これは、サーバーのツールがモデルのコンテキストに読み込まれるたびに消費されるおおよそのトークン数です。数が多いほど、ほかのタスクに使える注意が減ります。
インストール
ワンクリックインストール
これを `claude_desktop_config.json` ファイルに追加してください:
{
"mcpServers": {
"stigmer-mcp": {
"url": "https://stigmer.network/mcp"
}
}
}リモートエンドポイント
https://stigmer.network/mcpstreamable-httpできること
ツール一覧
ツール(8)
🟢query(query, error_type, sig, packages, limit)
Search for verified method contracts for any library. Pass any text -- library name, method, what you're building, or an error you hit.
入力スキーマ
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "What are you looking for? A method name, a library, an error message, or what you're building. Examples: s3 put_object, auto_gptq import, pandas merge, ImportError peft."
},
"error_type": {
"type": "string",
"description": "(deprecated -- use query instead) Error type if searching by error"
},
"sig": {
"type": "string"
},
"packages": {
"type": "array",
"items": {
"type": "string"
}
},
"limit": {
"type": "integer"
}
}
}🟢list_services
List all libraries and services that have verified method contracts. Use this first to discover what's available, then query for specific methods.
入力スキーマ
{
"type": "object",
"properties": {}
}🟢list_methods(service)
List all methods for a given library or service. Use after list_services to drill into a specific one.
入力スキーマ
{
"type": "object",
"properties": {
"service": {
"type": "string",
"description": "Library or service name. Get these from list_services first."
}
},
"required": [
"service"
]
}⚪policy(workflow, operations, description)
Generate a least-privilege IAM policy for an AWS workflow. Pass a named workflow, explicit IAM actions, or a description. Returns the exact policy with confidence tier and any unresolved operations.
入力スキーマ
{
"type": "object",
"properties": {
"workflow": {
"type": "string",
"description": "A named workflow from list_workflows (e.g. 's3-multipart-kms')"
},
"operations": {
"type": "string",
"description": "Explicit IAM action strings or SDK symbols, comma-separated (e.g. 's3:PutObject,s3:GetObject')"
},
"description": {
"type": "string",
"description": "Describe the workflow (e.g. 'upload a large file to S3 with KMS')"
}
}
}🟢list_workflows
List the curated named workflows that can generate least-privilege IAM policies.
入力スキーマ
{
"type": "object",
"properties": {}
}⚪verify(workflow, operations, policy)
Feed a generated policy back to AWS's own policy evaluation engine (SimulateCustomPolicy) and confirm it grants exactly the intended operations and nothing extra. Returns verified (True|False|unknown), grants_all, grants_extra. Requires AWS credentials; without them verified=unknown with the reason. Wildcarded operations are expanded to concrete actions first.
入力スキーマ
{
"type": "object",
"properties": {
"workflow": {
"type": "string",
"description": "A named workflow from list_workflows to generate and then verify"
},
"operations": {
"type": "string",
"description": "Intended IAM actions, comma-separated. Required if policy is provided."
},
"policy": {
"type": "string",
"description": "Optional. A complete IAM policy JSON document to verify."
}
}
}🟢authorize(operations, workflow, principal_arn)
Pre-flight authorization check for an AWS operation. Resolves the IAM actions the operation requires, then asks AWS's own policy simulator (SimulatePrincipalPolicy) whether the current role (or a given principal) allows them. Returns resolution (exact|partial|unresolved) and evaluation (allowed|denied|unknown) as separate fields. Requires AWS credentials; without them evaluation=unknown with the reason.
入力スキーマ
{
"type": "object",
"properties": {
"operations": {
"type": "string",
"description": "IAM action strings or SDK symbols, comma-separated (e.g. 's3:PutObject' or 's3.PutObject')"
},
"workflow": {
"type": "string",
"description": "A named workflow from list_workflows (e.g. 's3-multipart-kms')"
},
"principal_arn": {
"type": "string",
"description": "Optional. IAM role/user ARN to simulate against. Defaults to the current caller via sts:GetCallerIdentity."
}
}
}⚪register(action, library, symbol, version, error, ...)
Register a fix. Three actions: confirm (it worked), append_thread (variant worked), new_receipt (nothing matched, I fixed it).
入力スキーマ
{
"type": "object",
"properties": {
"action": {
"type": "string",
"enum": [
"confirm",
"append_thread",
"new_receipt"
]
},
"library": {
"type": "string"
},
"symbol": {
"type": "string"
},
"version": {
"type": "string"
},
"error": {
"type": "string"
},
"fix": {
"type": "string"
},
"error_class": {
"type": "string"
},
"env": {
"type": "string"
},
"receipt_sig": {
"type": "string"
}
},
"required": [
"action",
"library",
"symbol"
]
}推奨プロンプト
queryquerylist_serviceslist_servicesコミュニティ
エビデンス