Chaperoneflight recorder for AI agents on AWSFor judges

What did the agent do in your AWS account?

Every AWS call an AI coding agent makes, from CloudTrail: grouped into sessions, split from what people did, checked against risk rules, and turned into the permissions it actually needed.

Every session below is real, recorded by CloudTrail: Claude Code building Chaperone through the AWS MCP Server, and the person working beside it. Identifiers are masked, so the account shows as 111122223333, AWS's documentation placeholder.

Judging this entry? Start with the judges' guide

The agent asks Chaperone about its own work

A real run, sped up, identifiers masked. The same run on this site: the session with the demo queue.

Claude Code created and deleted a queue through the AWS MCP Server, then asked Chaperone "was anything I did risky?" The answer comes from CloudTrail, which the agent didn't write and can't edit: one destructive call, on a queue the same session created.

risky_calls("me") →
{
  "risky": {
    "destructive": {
      "calls": [{
        "time": "2026-09-27T22:30:13Z",
        "action": "sqs:DeleteQueue",
        "target": "https://sqs.us-east-1.amazonaws.com/111122223333/chaperone-demo-queue",
        "via": "mcp",
        "tool": "aws___run_script",
        "reasons": ["sqs:DeleteQueue removes or stops a resource"],
        "on_resource_created_this_session": true
      }]
    }
  },
  "summary": { "destructive": 1 }
}
Sessions recorded
23
14 by an AI agent
AWS calls
8,668
6,999 by the agent
Risky calls
23
destructive, identity, public or audit
Riskiest agent session
Identity escalation
iam:PutRolePolicy grants or assumes more access

Sessions