Access connection metadata and preview entity data from AWS Glue connections. This tool provides operations for discovering entities available through a connection, describing entity schemas, and previewing entity data. Useful for exploring data sources connected via AWS Glue connections such as...
High parameter count (11 properties); Single-target operation
Part of the Amazon Data Processing MCP Server MCP server. Enforce policies on this tool with Intercept, the open-source MCP proxy.
AI agents use manage_aws_glue_connection_metadata to create or modify resources in Amazon Data Processing MCP Server. Write operations carry medium risk because an autonomous agent could trigger bulk unintended modifications. Rate limits prevent a single agent session from making hundreds of changes in rapid succession. Argument validation ensures the agent passes expected values.
Without a policy, an AI agent could call manage_aws_glue_connection_metadata repeatedly, creating or modifying resources faster than any human could review. Intercept's rate limiting ensures write operations happen at a controlled pace, and argument validation catches malformed or unexpected inputs before they reach Amazon Data Processing MCP Server.
Write tools can modify data. A rate limit prevents runaway bulk operations from AI agents.
tools:
manage_aws_glue_connection_metadata:
rules:
- action: allow
rate_limit:
max: 30
window: 60 See the full Amazon Data Processing MCP Server policy for all 36 tools.
Agents calling write-class tools like manage_aws_glue_connection_metadata have been implicated in these attack patterns. Read the full case and prevention policy for each:
Other tools in the Write risk category across the catalogue. The same policy patterns (rate-limit, validate) apply to each.
Access connection metadata and preview entity data from AWS Glue connections. This tool provides operations for discovering entities available through a connection, describing entity schemas, and previewing entity data. Useful for exploring data sources connected via AWS Glue connections such as SaaS applications, databases, and other data stores. ## Requirements - The server must be run with the `--allow-sensitive-data-access` flag for get-entity-records operation - Appropriate AWS permissions for Glue connection metadata operations - A valid connection with credentials must exist ## Operations - **list-entities**: List available entities (e.g., tables, SObjects) for a connection - **describe-entity**: Get the schema/field details for a specific entity - **get-entity-records**: Preview data records from an entity (requires sensitive data access) ## Example ```python # List entities for a Salesforce connection manage_aws_glue_connection_metadata( operation='list-entities', connection_name='my-salesforce-connection', ) # Describe the Account entity manage_aws_glue_connection_metadata( operation='describe-entity', connection_name='my-salesforce-connection', entity_name='Account', ) # Preview records from the Account entity manage_aws_glue_connection_metadata( operation='get-entity-records', connection_name='my-salesforce-connection', entity_name='Account', limit=10, ) ``` Args: ctx: MCP context operation: Operation to perform connection_name: Name of the connection entity_name: Name of the entity catalog_id: Catalog ID parent_entity_name: Parent entity name for listing children next_token: Pagination token data_store_api_version: API version of the SaaS connector limit: Maximum number of records to fetch connection_options: Connector options for querying data filter_predicate: Filter predicate for the query selected_fields: List of fields to fetch Returns: Union of response types specific to the operation performed. It is categorised as a Write tool in the Amazon Data Processing MCP Server MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
Add a rule in your Intercept YAML policy under the tools section for manage_aws_glue_connection_metadata. You can allow, deny, rate-limit, or validate arguments. Then run Intercept as a proxy in front of the Amazon Data Processing MCP Server MCP server.
manage_aws_glue_connection_metadata is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the manage_aws_glue_connection_metadata rule in your Intercept policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the Intercept policy for manage_aws_glue_connection_metadata. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
manage_aws_glue_connection_metadata is provided by the Amazon Data Processing MCP Server MCP server (awslabs.aws-dataprocessing-mcp-server). Intercept sits as a proxy in front of this server to enforce policies before tool calls reach the server.
Deterministic policy on every MCP tool call. Per-identity grants. Full audit log.