Auditing and documenting cloud infrastructure

Combining the AWS MCP Server, Cloudflare API MCP Server, and Filesystem MCP: audit resources and configuration across two cloud providers and save the findings as a report.

  • Skill Road
  • Auditing and documenting cloud infrastructure

Anyone running infrastructure across more than one cloud provider knows the problem: getting a complete overview of resources, configuration, and potential risks means clicking through several separate consoles. This workflow connects the AWS MCP Server and the Cloudflare API MCP Server with Filesystem MCP, so an agent can query resources and configuration across both providers and save the findings locally as a readable, version-controllable report, instead of only presenting information fleetingly in the chat. The AWS MCP Server gives authenticated access to over 300 AWS services through a single endpoint, the Cloudflare API MCP Server covers DNS, Workers, Zero Trust, and other Cloudflare products through a compact Code Mode approach, and Filesystem MCP writes the collected result as a file into the project directory.

How the three tools work together

The agent first queries relevant resources via the AWS MCP Server, such as running EC2 instances, S3 bucket configurations, or IAM roles with especially broad permissions. In parallel or afterward, it uses the Cloudflare API MCP Server to query DNS records, firewall rules, or Zero Trust policies for the associated domains. Instead of only summarizing the findings in conversation, the agent writes them via Filesystem MCP as a structured Markdown document into a designated folder, such as docs/infrastructure-audit/, where it can be version-controlled with git and compared over time.

A typical step-by-step run

A typical request is: "Create a report of all publicly reachable S3 buckets in my AWS account and all Cloudflare firewall rules for domain X, and save it to docs/infrastructure-audit/2026-09-report.md." The agent queries bucket configurations via the AWS MCP Server, checks the active firewall rules for the named domain via the Cloudflare API MCP Server, and combines both results into a joint report, which Filesystem MCP then saves as a file. Repeating this request regularly builds up a history of audit reports that can be used to track infrastructure changes over time.

Why this combination pays off

Without the AWS MCP Server or the Cloudflare API MCP Server, a human would have to manually gather the relevant information from two separate web consoles, which costs a lot of time for recurring checks. Without Filesystem MCP, every audit run disappears at the end of the chat session, making it hard to compare changes between two points in time. Only the combination of two cloud-provider servers and a local storage location turns a one-off query into a repeatable, documented review process.

Who this workflow fits

This workflow is particularly useful for DevOps and infrastructure teams that regularly run security or cost reviews across multiple cloud providers and have so far had to manually switch between consoles for that. It also suits preparing compliance evidence or internal audits well, since every report remains traceable as a file. For teams that only use one of the two cloud providers, only the matching MCP server together with Filesystem MCP is needed accordingly.

Frequently asked setup questions

Does each of the two cloud servers need its own credentials? Yes, the AWS MCP Server uses IAM credentials via OAuth or SigV4, and the Cloudflare API MCP Server uses its own OAuth or API token — both are configured independently of each other. Should an agent also be allowed write access to the infrastructure for this workflow? For pure audit purposes, a narrowly scoped, read-only access profile is recommended; changes to the infrastructure should always be confirmed by a human. How often should the report be refreshed? That depends on your needs — for security-critical environments, a weekly or monthly cadence is a reasonable starting point.

Building blocks of this workflow

Free

Categories