AWS CLI
-
Run AWS CLI commands
Run AWS CLI commands for the selected services and regions allowed by the connection.
Enable scoped AWS access for selected sandbox tools and MCP servers.
Run AWS CLI commands for the selected services and regions allowed by the connection.
Retrieve CloudWatch metric data for namespaces, dimensions, statistics, percentiles, math expressions, or batched metric queries.
Get metadata for a CloudWatch metric.
Get recommended CloudWatch alarms for a metric based on best practices and statistical analysis.
Analyze CloudWatch metric data for trend, seasonality, and statistical properties.
Execute an instant PromQL query against CloudWatch.
Execute a PromQL range query over a time window.
Get values for a specific CloudWatch PromQL label.
Find time series matching CloudWatch PromQL label selectors.
List available CloudWatch PromQL label names.
Identify currently active CloudWatch alarms across the account.
Retrieve historical state changes and patterns for a CloudWatch alarm.
Find metadata about CloudWatch log groups.
Analyze CloudWatch logs for anomalies, message patterns, and error patterns.
Start a CloudWatch Logs Insights query and return the query ID for fetching results.
Run a Logs Insights query across multiple log groups and regions with batching, polling, and result merging.
Retrieve results for a CloudWatch Logs Insights query.
Cancel an in-progress CloudWatch Logs Insights query.
Credential safety
Mistle lets agents access connected services without placing provider credentials inside the sandbox. Approved outbound requests are routed through Mistle's credential proxy, where authentication happens outside the agent runtime.
Credentials stay encrypted in Mistle's control plane and are applied only when a request is authorized for the calling sandbox and organization.
Read the credential-less sandboxes article