feat(aws): expand SES/STS/Secrets Manager tool coverage, fix API alignment gaps (#5450)

* feat(aws): expand SES/STS/Secrets Manager tool coverage, fix API alignment gaps

- SES: add suppression list management, email identity CRUD, template
  update, configuration set creation, custom verification email (10
  new tools); fix silent httpsPolicy drop in create_configuration_set
  and unvalidated suppression reason enum in list_suppressed_destinations
- STS: add AssumeRoleWithWebIdentity and AssumeRoleWithSAML (unsigned,
  no static credentials required); extend assume_role with
  policyArns/tags/transitiveTagKeys session params
- Secrets Manager: add describe_secret, tag_resource, untag_resource,
  restore_secret, rotate_secret; fix list_secrets dropping
  rotation/version metadata fields; normalize tool versions to 1.0.0
  and alphabetize registry entries

All 31 tools verified param-by-param against live AWS API docs across
two independent audit passes.

* fix(aws): address review findings on SES config/identity and Secrets Manager rotation

- ses_create_configuration_set: validate suppressedReasons against
  BOUNCE/COMPLAINT enum before calling AWS (was silently reaching AWS
  as a generic 500 for bad values); tags now a proper Zod array schema
  instead of a string with route-side JSON.parse
- ses_create_email_identity: dkimSigningAttributes and tags now proper
  Zod object/array schemas instead of strings with route-side
  JSON.parse, matching the pattern used elsewhere (e.g. sts_assume_role
  tags, secrets_manager_tag_resource)
- secrets_manager_rotate_secret: reject automaticallyAfterDays and
  scheduleExpression when both are supplied — AWS RotationRules
  accepts only one
- sts createUnauthenticatedSTSClient: corrected a misleading comment
  claiming these calls are fully unsigned; the SDK still falls through
  its default credential provider chain

* fix(ses): correct json input types for tags/dkimSigningAttributes

The SES block declared the tags and dkimSigningAttributes block inputs
as 'string' instead of 'json', so the generic block executor never
parsed the JSON code-editor value before forwarding it — workflow runs
sent a raw JSON string where the contract now expects a structured
object/array, failing validation. Also corrected the corresponding
tool param TypeScript types, which were still typed as string | null.

* fix(ses): stop coercing switch string 'false' to true in create_configuration_set

Boolean('false') evaluates to true, so turning off the
reputationMetricsEnabled or sendingEnabled switch sent the opposite of
the user's choice to SES. Match the established === 'true' string
comparison pattern used elsewhere in the codebase.

* fix(sts): stop double-parsing assume_role session tags input

tags was declared as a 'json' block input, so the generic executor
JSON.parse'd it before the switch-case handler ran — but that handler
already converts the raw table-rows array (or a passthrough string)
into the JSON string the sts_assume_role contract expects. Declaring
it 'json' broke that conversion for non-string inputs. Reverted to
'string' so the handler's existing string/array disambiguation runs
on the untouched raw value.

* fix(sts): supply placeholder credentials to the unauthenticated client

createUnauthenticatedSTSClient omitted credentials entirely, so the
SDK's signing middleware fell through the default credential provider
chain and threw CredentialsProviderError before the request was sent
in any environment with no ambient AWS identity — even though
AssumeRoleWithWebIdentity/AssumeRoleWithSAML never check the
signature. Static placeholder credentials skip that resolution
without granting or requiring any real IAM identity.
This commit is contained in:
Waleed
2026-07-06 17:26:44 -07:00
committed by GitHub
parent f111de3150
commit fb3f95d5dc
78 changed files with 6182 additions and 66 deletions
@@ -28,7 +28,7 @@ In Sim, the AWS Secrets Manager integration allows your workflows to securely re
## Usage Instructions
Integrate AWS Secrets Manager into the workflow. Can retrieve, create, update, list, and delete secrets.
Integrate AWS Secrets Manager into the workflow. Can retrieve, create, update, list, delete, describe, tag, untag, restore, and rotate secrets.
@@ -78,7 +78,7 @@ List secrets stored in AWS Secrets Manager
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `secrets` | json | List of secrets with name, ARN, description, and dates |
| `secrets` | json | List of secrets with name, ARN, description, dates, rotation rules/window, and version-to-stage mappings |
| `nextToken` | string | Pagination token for the next page of results |
| `count` | number | Number of secrets returned |
@@ -154,4 +154,131 @@ Delete a secret from AWS Secrets Manager
| `arn` | string | ARN of the deleted secret |
| `deletionDate` | string | Scheduled deletion date |
### `secrets_manager_describe_secret`
Retrieve full metadata for a secret in AWS Secrets Manager, including rotation configuration and replication status, without exposing the secret value
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `secretId` | string | Yes | The name or ARN of the secret to describe |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `name` | string | Name of the secret |
| `arn` | string | ARN of the secret |
| `description` | string | Description of the secret |
| `kmsKeyId` | string | KMS key ID used to encrypt the secret |
| `rotationEnabled` | boolean | Whether automatic rotation is enabled |
| `rotationLambdaARN` | string | ARN of the Lambda function used for rotation |
| `rotationRules` | json | Rotation schedule configuration |
| `lastRotatedDate` | string | Date the secret was last rotated |
| `lastChangedDate` | string | Date the secret was last changed |
| `lastAccessedDate` | string | Date the secret was last accessed |
| `deletedDate` | string | Scheduled deletion date |
| `nextRotationDate` | string | Date the secret is next scheduled to rotate |
| `tags` | array | Tags attached to the secret |
| `versionIdsToStages` | json | Map of version IDs to their staging labels |
| `owningService` | string | ID of the AWS service that manages this secret, if any |
| `createdDate` | string | Date the secret was created |
| `primaryRegion` | string | The primary region of the secret, if replicated |
| `replicationStatus` | array | Replication status for each region the secret is replicated to |
### `secrets_manager_tag_resource`
Attach tags to a secret in AWS Secrets Manager
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `secretId` | string | Yes | The name or ARN of the secret to tag |
| `tags` | json | Yes | Tags to attach, as an array of \{key, value\} pairs \(max 50\) |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `message` | string | Operation status message |
| `name` | string | Name or ARN of the tagged secret |
### `secrets_manager_untag_resource`
Remove tags from a secret in AWS Secrets Manager
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `secretId` | string | Yes | The name or ARN of the secret to untag |
| `tagKeys` | json | Yes | Tag keys to remove, as an array of strings \(max 50\) |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `message` | string | Operation status message |
| `name` | string | Name or ARN of the untagged secret |
### `secrets_manager_restore_secret`
Cancel a scheduled deletion for a secret in AWS Secrets Manager, restoring access to it
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `secretId` | string | Yes | The name or ARN of the secret to restore |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `message` | string | Operation status message |
| `name` | string | Name of the restored secret |
| `arn` | string | ARN of the restored secret |
### `secrets_manager_rotate_secret`
Start or reconfigure rotation for a secret in AWS Secrets Manager
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `secretId` | string | Yes | The name or ARN of the secret to rotate |
| `clientRequestToken` | string | No | Idempotency token for the new secret version \(32-64 characters\) |
| `rotationLambdaARN` | string | No | ARN of the Lambda function that performs rotation \(omit for managed rotation\) |
| `automaticallyAfterDays` | number | No | Number of days between rotations \(1-1000\). Mutually exclusive with schedule expression |
| `duration` | string | No | Length of the rotation window in hours, e.g. "3h" |
| `scheduleExpression` | string | No | A cron\(\) or rate\(\) expression defining the rotation schedule |
| `rotateImmediately` | boolean | No | Whether to rotate immediately \(default true\) or wait for the next scheduled window |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `message` | string | Operation status message |
| `name` | string | Name of the secret |
| `arn` | string | ARN of the secret |
| `versionId` | string | ID of the new secret version created by rotation |
+229 -1
View File
@@ -27,7 +27,7 @@ In Sim, the AWS SES integration is designed for workflows that need reliable, pr
## Usage Instructions
Integrate AWS SES v2 into the workflow. Send simple, templated, and bulk emails. Manage email templates and retrieve account sending quota and verified identity information.
Integrate AWS SES v2 into the workflow. Send simple, templated, and bulk emails. Manage email templates, identities, configuration sets, and the account suppression list, and retrieve account sending quota and verified identity information.
@@ -238,4 +238,232 @@ Delete an existing SES email template
| --------- | ---- | ----------- |
| `message` | string | Confirmation message for the deleted template |
### `ses_update_template`
Update the subject, HTML, and text content of an existing SES email template
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `templateName` | string | Yes | The name of the template to update |
| `subjectPart` | string | Yes | The subject line of the template |
| `htmlPart` | string | No | The HTML body of the template |
| `textPart` | string | No | The plain text body of the template |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `message` | string | Confirmation message |
### `ses_put_suppressed_destination`
Add an email address to the account-level SES suppression list
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `emailAddress` | string | Yes | The email address to add to the suppression list |
| `reason` | string | Yes | The reason the address is suppressed: BOUNCE or COMPLAINT |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `message` | string | Confirmation message |
### `ses_delete_suppressed_destination`
Remove an email address from the account-level SES suppression list
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `emailAddress` | string | Yes | The email address to remove from the suppression list |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `message` | string | Confirmation message |
### `ses_get_suppressed_destination`
Retrieve details for a specific email address on the SES suppression list
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `emailAddress` | string | Yes | The suppressed email address to look up |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `emailAddress` | string | The suppressed email address |
| `reason` | string | The reason the address is suppressed |
| `lastUpdateTime` | string | When the address was added to the suppression list |
| `messageId` | string | The message ID associated with the bounce or complaint event |
| `feedbackId` | string | The feedback ID associated with the bounce or complaint event |
### `ses_list_suppressed_destinations`
List email addresses on the account-level SES suppression list
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `reasons` | string | No | Comma-separated suppression reasons to filter by: BOUNCE, COMPLAINT |
| `startDate` | string | No | Only include addresses suppressed after this ISO 8601 date |
| `endDate` | string | No | Only include addresses suppressed before this ISO 8601 date |
| `pageSize` | number | No | Maximum number of results to return |
| `nextToken` | string | No | Pagination token from a previous list response |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `destinations` | array | List of suppressed destinations with email address, reason, and last update |
| `nextToken` | string | Pagination token for the next page of results |
| `count` | number | Number of suppressed destinations returned |
### `ses_create_email_identity`
Start verification of a new SES email address or domain identity
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `emailIdentity` | string | Yes | The email address or domain to verify |
| `dkimSigningAttributes` | json | No | Bring-your-own-DKIM signing attributes as JSON \(domainSigningSelector, domainSigningPrivateKey, nextSigningKeyLength\). Domain identities only. |
| `tags` | json | No | JSON array of tags to associate with the identity: \[\{"key":"","value":""\}\] |
| `configurationSetName` | string | No | Default configuration set to use when sending from this identity |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `identityType` | string | The identity type: EMAIL_ADDRESS or DOMAIN |
| `verifiedForSendingStatus` | boolean | Whether the identity is verified and can send email |
| `dkimAttributes` | json | DKIM signing status and CNAME tokens for the identity |
### `ses_delete_email_identity`
Delete a verified SES email address or domain identity
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `emailIdentity` | string | Yes | The email address or domain identity to delete |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `message` | string | Confirmation message |
### `ses_get_email_identity`
Retrieve verification status, DKIM, Mail-From, and policy details for an SES identity
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `emailIdentity` | string | Yes | The email address or domain identity to look up |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `identityType` | string | The identity type: EMAIL_ADDRESS or DOMAIN |
| `verifiedForSendingStatus` | boolean | Whether the identity is verified and can send email |
| `verificationStatus` | string | Verification status: PENDING, SUCCESS, FAILED, TEMPORARY_FAILURE, NOT_STARTED |
| `feedbackForwardingStatus` | boolean | Whether bounce/complaint notifications are forwarded by email |
| `configurationSetName` | string | Default configuration set for this identity |
| `dkimAttributes` | json | DKIM signing status and CNAME tokens for the identity |
| `mailFromAttributes` | json | Custom MAIL FROM domain configuration for the identity |
| `policies` | json | Sending authorization policies attached to the identity |
| `tags` | array | Tags associated with the identity |
| `verificationInfo` | json | Additional verification diagnostics \(error type, last checked/success time\) |
### `ses_create_configuration_set`
Create an SES configuration set to control tracking, delivery, reputation, sending, and suppression behavior for emails
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `configurationSetName` | string | Yes | Name of the configuration set \(letters, numbers, hyphens, underscores\) |
| `customRedirectDomain` | string | No | Custom domain to use for open/click tracking links |
| `httpsPolicy` | string | No | HTTPS policy for tracking links: REQUIRE, REQUIRE_OPEN_ONLY, or OPTIONAL |
| `tlsPolicy` | string | No | Whether delivery requires TLS: REQUIRE or OPTIONAL |
| `sendingPoolName` | string | No | Dedicated IP pool to associate with the configuration set |
| `reputationMetricsEnabled` | boolean | No | Whether to collect reputation metrics for emails using this configuration set |
| `sendingEnabled` | boolean | No | Whether sending is enabled for this configuration set |
| `suppressedReasons` | string | No | Comma-separated reasons that trigger suppression: BOUNCE, COMPLAINT |
| `tags` | json | No | JSON array of tags to associate with the configuration set: \[\{"key":"","value":""\}\] |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `message` | string | Confirmation message |
### `ses_send_custom_verification_email`
Send a branded custom verification email to an address using a custom verification email template
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `accessKeyId` | string | Yes | AWS access key ID |
| `secretAccessKey` | string | Yes | AWS secret access key |
| `emailAddress` | string | Yes | The email address to verify |
| `templateName` | string | Yes | The name of the custom verification email template to use |
| `configurationSetName` | string | No | Configuration set to use when sending the verification email |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `messageId` | string | SES message ID for the sent verification email |
@@ -50,6 +50,9 @@ Assume an IAM role and receive temporary security credentials
| `externalId` | string | No | External ID for cross-account access |
| `serialNumber` | string | No | MFA device serial number or ARN |
| `tokenCode` | string | No | MFA token code \(6 digits\) |
| `policyArns` | string | No | Comma-separated ARNs of up to 10 IAM managed policies to use as session policies |
| `tags` | string | No | JSON object of up to 50 session tag key/value pairs for attribute-based access control |
| `transitiveTagKeys` | string | No | Comma-separated tag keys that propagate through role chaining |
#### Output
@@ -64,6 +67,73 @@ Assume an IAM role and receive temporary security credentials
| `packedPolicySize` | number | Percentage of allowed policy size used |
| `sourceIdentity` | string | Source identity set on the role session, if any |
### `sts_assume_role_with_web_identity`
Assume an IAM role using an OIDC/OAuth 2.0 web identity token (e.g. GitHub Actions OIDC, EKS IRSA, Google/Facebook federation) and receive temporary security credentials
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `roleArn` | string | Yes | ARN of the IAM role to assume |
| `roleSessionName` | string | Yes | Identifier for the assumed role session |
| `webIdentityToken` | string | Yes | OAuth 2.0 access token or OpenID Connect ID token from the identity provider \(up to 20000 chars\) |
| `providerId` | string | No | Fully qualified host of a legacy OAuth 2.0 provider \(e.g. www.amazon.com\); omit for OpenID Connect providers |
| `policyArns` | string | No | Comma-separated ARNs of up to 10 IAM managed policies to use as session policies |
| `policy` | string | No | JSON IAM policy to further restrict session permissions \(max 2048 chars\) |
| `durationSeconds` | number | No | Duration of the session in seconds \(900-43200, default 3600\) |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `accessKeyId` | string | Temporary access key ID |
| `secretAccessKey` | string | Temporary secret access key |
| `sessionToken` | string | Temporary session token |
| `expiration` | string | Credential expiration timestamp |
| `assumedRoleArn` | string | ARN of the assumed role |
| `assumedRoleId` | string | Assumed role ID with session name |
| `subjectFromWebIdentityToken` | string | Unique user identifier from the identity provider's token subject claim |
| `audience` | string | Intended audience \(client ID\) of the web identity token |
| `provider` | string | Issuing authority of the presented web identity token |
| `packedPolicySize` | number | Percentage of allowed policy size used |
| `sourceIdentity` | string | Source identity set on the role session, if any |
### `sts_assume_role_with_saml`
Assume an IAM role using a SAML 2.0 authentication response from an enterprise identity provider and receive temporary security credentials
#### Input
| Parameter | Type | Required | Description |
| --------- | ---- | -------- | ----------- |
| `region` | string | Yes | AWS region \(e.g., us-east-1\) |
| `roleArn` | string | Yes | ARN of the IAM role to assume |
| `principalArn` | string | Yes | ARN of the SAML provider in IAM that describes the identity provider |
| `samlAssertion` | string | Yes | Base64-encoded SAML authentication response from the identity provider |
| `policyArns` | string | No | Comma-separated ARNs of up to 10 IAM managed policies to use as session policies |
| `policy` | string | No | JSON IAM policy to further restrict session permissions \(max 2048 chars\) |
| `durationSeconds` | number | No | Duration of the session in seconds \(900-43200, default 3600\) |
#### Output
| Parameter | Type | Description |
| --------- | ---- | ----------- |
| `accessKeyId` | string | Temporary access key ID |
| `secretAccessKey` | string | Temporary secret access key |
| `sessionToken` | string | Temporary session token |
| `expiration` | string | Credential expiration timestamp |
| `assumedRoleArn` | string | ARN of the assumed role |
| `assumedRoleId` | string | Assumed role ID with session name |
| `subject` | string | Value of the NameID element in the Subject of the SAML assertion |
| `subjectType` | string | Format of the name ID \(e.g. transient, persistent\) |
| `issuer` | string | Value of the Issuer element of the SAML assertion |
| `audience` | string | Value of the SAML assertion's SubjectConfirmationData Recipient attribute |
| `nameQualifier` | string | Hash uniquely identifying the issuer, account, and SAML provider |
| `packedPolicySize` | number | Percentage of allowed policy size used |
| `sourceIdentity` | string | Source identity set on the role session, if any |
### `sts_get_caller_identity`
Get details about the IAM user or role whose credentials are used to call the API