# setup_check

Check if AWS Security Agent prerequisites are configured. Verifies agent space and service role are available. If not ready, lists existing agent spaces to help with setup.

Agent View of the PolicyLayer registry record for `setup_check`. HTML page: https://policylayer.com/tools/aws/setup-check

## Facts

- Tool: `setup_check`
- Server: AWS (`@awslabs/mcp`) — https://policylayer.com/tools/aws.md
- Install: `npx -y @awslabs/mcp`
- Homepage: https://github.com/awslabs/mcp
- Risk category: Read (Low risk)
- Registry record: grade F, identity verified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Allowed

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "setup_check",
    "arguments": {}
  }
}
```

## Why setup_check is rated Low

The tool only reads and verifies configuration state (checks prerequisites, verifies availability, lists spaces). No data is modified, executed, or deleted. It is a purely diagnostic/informational operation.

From the tool's own definition: "Check if AWS Security Agent prerequisites are configured. Verifies agent space and service role are available. If not ready, lists existing agent spaces to help with setup."

## Use case

AI agents call setup_check to retrieve information from AWS without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches AWS:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "setup_check": {}
  }
}
```

## Other tools on AWS (299)

- `bulk_delete_by_criteria` — Destructive — https://policylayer.com/tools/aws/bulk-delete-by-criteria.md
- `cache_delete` — Destructive — https://policylayer.com/tools/aws/cache-delete.md
- `cache_delete_many` — Destructive — https://policylayer.com/tools/aws/cache-delete-many.md
- `cache_delete_multi` — Destructive — https://policylayer.com/tools/aws/cache-delete-multi.md
- `cache_flush_all` — Destructive — https://policylayer.com/tools/aws/cache-flush-all.md
- `delete` — Destructive — https://policylayer.com/tools/aws/delete.md
- `delete_access_key` — Destructive — https://policylayer.com/tools/aws/delete-access-key.md
- `delete_datastore` — Destructive — https://policylayer.com/tools/aws/delete-datastore.md
- `delete_group` — Destructive — https://policylayer.com/tools/aws/delete-group.md
- `delete_image_set` — Destructive — https://policylayer.com/tools/aws/delete-image-set.md
- `delete_instance_in_series` — Destructive — https://policylayer.com/tools/aws/delete-instance-in-series.md
- `delete_instance_in_study` — Destructive — https://policylayer.com/tools/aws/delete-instance-in-study.md
- `delete_patient_studies` — Destructive — https://policylayer.com/tools/aws/delete-patient-studies.md
- `delete_resource` — Destructive — https://policylayer.com/tools/aws/delete-resource.md
- `delete_role_policy` — Destructive — https://policylayer.com/tools/aws/delete-role-policy.md
- `delete_series_by_uid` — Destructive — https://policylayer.com/tools/aws/delete-series-by-uid.md
- `delete_study` — Destructive — https://policylayer.com/tools/aws/delete-study.md
- `delete_user` — Destructive — https://policylayer.com/tools/aws/delete-user.md
- `delete_user_policy` — Destructive — https://policylayer.com/tools/aws/delete-user-policy.md
- `detach_user_policy` — Destructive — https://policylayer.com/tools/aws/detach-user-policy.md
- `json_arrtrim` — Destructive — https://policylayer.com/tools/aws/json-arrtrim.md
- `json_clear` — Destructive — https://policylayer.com/tools/aws/json-clear.md
- `json_del` — Destructive — https://policylayer.com/tools/aws/json-del.md
- `list_pop_left` — Destructive — https://policylayer.com/tools/aws/list-pop-left.md
- `list_trim` — Destructive — https://policylayer.com/tools/aws/list-trim.md
- `remove_instance_from_image_set` — Destructive — https://policylayer.com/tools/aws/remove-instance-from-image-set.md
- `remove_series_from_image_set` — Destructive — https://policylayer.com/tools/aws/remove-series-from-image-set.md
- `set_pop` — Destructive — https://policylayer.com/tools/aws/set-pop.md
- `sorted_set_remove_by_lex` — Destructive — https://policylayer.com/tools/aws/sorted-set-remove-by-lex.md
- `sorted_set_remove_by_score` — Destructive — https://policylayer.com/tools/aws/sorted-set-remove-by-score.md
- …and 269 more: https://policylayer.com/tools/aws.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=aws · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/aws
