High Risk →

cdk_best_practices

Returns CDK best practices and security guidelines. ## Usage This tool provides comprehensive CDK development guidelines, security best practices, and architectural recommendations. Always run this tool when asked to generate or review CDK code and follow the guidelines returned. ## When to Us...

Part of the AWS Infrastructure as Code MCP Server MCP server. Enforce policies on this tool with Intercept, the open-source MCP proxy.

AI agents invoke cdk_best_practices to trigger processes or run actions in AWS Infrastructure as Code MCP Server. Execute operations can have side effects beyond the immediate call -- triggering builds, sending notifications, or starting workflows. Rate limits and argument validation are essential to prevent runaway execution.

cdk_best_practices can trigger processes with real-world consequences. An uncontrolled agent might start dozens of builds, send mass notifications, or kick off expensive compute jobs. Intercept enforces rate limits and validates arguments to keep execution within safe bounds.

Execute tools trigger processes. Rate-limit and validate arguments to prevent unintended side effects.

aws-infrastructure-as-code-mcp-server.yaml
tools:
  cdk_best_practices:
    rules:
      - action: allow
        rate_limit:
          max: 10
          window: 60
        validate:
          required_args: true

See the full AWS Infrastructure as Code MCP Server policy for all 8 tools.

Tool Name cdk_best_practices
Category Execute
Risk Level High

Agents calling execute-class tools like cdk_best_practices have been implicated in these attack patterns. Read the full case and prevention policy for each:

Browse the full MCP Attack Database →

Other tools in the Execute risk category across the catalogue. The same policy patterns (rate-limit, validate) apply to each.

cdk_best_practices is one of the high-risk operations in AWS Infrastructure as Code MCP Server. For the full severity-focused view — only the high-risk tools with their recommended policies — see the breakdown for this server, or browse all high-risk tools across every MCP server.

What does the cdk_best_practices tool do? +

Returns CDK best practices and security guidelines. ## Usage This tool provides comprehensive CDK development guidelines, security best practices, and architectural recommendations. Always run this tool when asked to generate or review CDK code and follow the guidelines returned. ## When to Use - Get CDK security best practices and compliance guidelines - Look up architectural patterns and recommendations - Get guidance on CDK application structure and organization - Research performance optimization techniques - Learn about proper construct usage and design patterns - Understand deployment and testing best practices ## Result Interpretation Returns JSON with: - knowledge_response: Details of the response - results: Array with single result containing: - rank: Always 1 - title: Document title or filename - url: Source URL of the CDK best practices - context: A summary of the CDK best practices - next_step_guidance: If present, suggested next actions to take for answering user query ## Args No parameters required - this tool returns the complete best practices guide. ## Returns Complete best practices documentation as text, including security guidelines, architectural patterns, development workflow, and compliance requirements.. It is categorised as a Execute tool in the AWS Infrastructure as Code MCP Server MCP Server, which means it can trigger actions or run processes. Use rate limits and argument validation.

How do I enforce a policy on cdk_best_practices? +

Add a rule in your Intercept YAML policy under the tools section for cdk_best_practices. You can allow, deny, rate-limit, or validate arguments. Then run Intercept as a proxy in front of the AWS Infrastructure as Code MCP Server MCP server.

What risk level is cdk_best_practices? +

cdk_best_practices is a Execute tool with high risk. Execute tools should be rate-limited and have argument validation enabled.

Can I rate-limit cdk_best_practices? +

Yes. Add a rate_limit block to the cdk_best_practices rule in your Intercept policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.

How do I block cdk_best_practices completely? +

Set action: deny in the Intercept policy for cdk_best_practices. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.

What MCP server provides cdk_best_practices? +

cdk_best_practices is provided by the AWS Infrastructure as Code MCP Server MCP server (awslabs.aws-iac-mcp-server). Intercept sits as a proxy in front of this server to enforce policies before tool calls reach the server.

Let agents act without letting them run wild.

Deterministic policy on every MCP tool call. Per-identity grants. Full audit log.

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.