AWS Security Hub MCP App brings exposure findings into your AI-assisted workflow (Preview)
AWS launched a preview of the AWS Security Hub MCP App, a local MCP server integrating Security Hub exposure findings into AI workflows like Claude Desktop to streamline security investigations.
The useful question is what changes for users, developers or buyers, and whether the announcement stays industry context or becomes something people can actually use.
The AWS Security Hub MCP App is a new local Model Context Protocol server that connects Security Hub exposure findings directly to AI-assisted tools such as Claude Desktop. This integration allows security teams to investigate exposures without switching contexts or manually triaging data, reducing the time spent gathering and correlating information. The app is designed to operate within existing AI workflows, enabling natural language queries to retrieve and analyze security posture details efficiently. All interactions are performed locally using established AWS credentials, ensuring no changes are made to the environment.
Users can now view top exposure findings, explore attack paths and network paths associated with specific findings, and examine correlated findings and affected resource configurations. The app also provides remediation recommendations tailored to the identified exposures. Each tool call generates both a text summary for AI reasoning and an interactive visualization for manual verification within the same conversation. This dual output supports both automated analysis and human oversight during investigations.
The Security Hub MCP App operates as a read-only tool, meaning it does not modify any resources or configurations in the AWS environment. It relies on the user’s existing AWS credentials and permissions, maintaining security best practices by limiting actions to data retrieval and analysis. The app is available at no additional cost to existing Security Hub customers, making it accessible without additional licensing fees.
The feature is currently available in preview across all AWS commercial Regions that support Security Hub. Organizations interested in testing the integration can refer to the AWS Security Hub User Guide and the AWS Security Hub product page for detailed instructions. For a complete list of supported Regions, users should consult the AWS Regional Services List. The preview period allows AWS to gather feedback before a potential general release.