
cloudcostwise
io.github.cloudwise-appv0.1.2Updated Oct 5, 2026
Find AWS waste with your own read-only credentials. Runs locally; nothing leaves your machine.
Overview
Runs read-only AWS waste checks locally and exposes scan results and fix guidance to an AI assistant.
- What it does
- Runs CloudWise's open waste checks against your own AWS account using read-only credentials. Its tools are scan, list_findings, explain_finding and fix_guidance; fix_guidance returns suggested steps and AWS CLI commands as text for review, and nothing is executed. It covers 20 of CloudWise's 46 service checks, including EC2, Lambda, S3, RDS, DynamoDB, EBS, EFS, ECR, ElastiCache, NAT gateways, load balancers, CloudWatch logs and dashboards, and RI/Savings Plans opportunities.
- When to use it
- Use it when you want an assistant to help find cost waste in an AWS account, for example asking where money is being wasted. It suits local, read-only inspection of your own account rather than automated remediation.
- Requirements
- Runs locally over stdio, started with uvx, so uv must be installed. It uses your AWS credentials through the standard credential chain or an AWS_PROFILE environment variable, and needs network access to AWS APIs. ReadOnlyAccess is enough; the README points to a minimal policy file.
Installation
In SourceWeft
- Open cloudcostwise in the dashboard and add it to a workspace.
- Enable the server for the chats that should use its tools.
Desktop only via STDIO. STDIO servers start a local process, so they need the SourceWeft desktop host.
Other MCP clients
Follow the launch instructions in the repository.
README
cloudcostwise
Find AWS waste from your terminal or your AI assistant. cloudcostwise runs CloudWise's open waste
checks on your own machine, with your own read-only AWS credentials.
- Nothing leaves your machine. The only network calls are AWS API calls in your account. No signup, no IAM role for a third party, no telemetry.
- It cannot change anything. Every AWS call goes through a guard that
refuses any operation that isn't a
Describe,List,Get,SearchorLookup, whatever your credentials allow. - 20 of CloudWise's 46 service checks: EC2, Lambda, SageMaker, WorkSpaces, Lightsail, EBS, S3, EFS, ECR, RDS, DynamoDB, ElastiCache, Elastic IPs, NAT gateways and load balancers, VPC endpoints, dangling DNS records, CloudWatch logs and dashboards, security posture, RI/Savings Plans opportunities, and Compute Optimizer.
Install and run
Options:
Use it from Claude Code, Codex or any MCP client
cloudcostwise mcp runs the same scan as an MCP server (stdio). Then ask your
assistant: "Where am I wasting money on AWS?"
The plugin and registry entries start the server with uvx, so install
uv first (brew install uv or pipx install uv).
Claude Code, as a plugin (asks for your AWS profile):
Claude Code, as a plain MCP server:
Codex (~/.codex/config.toml):
Tools, all read-only: scan, list_findings, explain_finding,
fix_guidance. fix_guidance returns the steps and AWS CLI command as text
for you to review; nothing is ever executed. The assistant is told about the
Cost Explorer cost before it scans, and include_cost_explorer=false skips it.
Permissions
ReadOnlyAccess (AWS managed) is enough. The minimal policy the checks use is
in docs/iam-policy.json. It was derived from a scan of
an account with most supported resource types; if a check lacks a permission,
the scan says so in its data warnings instead of failing.
How the numbers are counted
Each finding shows an estimated monthly saving. Advisory waste types, ones CloudWise could not validate against a real AWS resource, are listed but never added to the total.
What the hosted product adds
The other 26 service checks (Glue, ECS, Step Functions, Backup, CloudFront, commitments and more), history and trends, alerts, and safe automated fixes: https://cloudcostwise.io/connect?utm_source=cloudcostwise&utm_medium=cli.
License
FSL-1.1-ALv2. Each release becomes Apache-2.0 two years after it ships.
How we know it's right
See VALIDATION.md: the validation level of every waste type this tool reports, from L0 (unit-tested) to L2 (fired on a real AWS resource and stayed silent on a healthy twin) and beyond.
Source: README.md at commit 8b487b0
Tools
0Version history
1- v0.1.2LatestOct 5, 2026


