vocabulary: "1.0.0" info: provider: "Amazon CloudTrail" description: "Vocabulary for Amazon CloudTrail APIs covering operations, schemas, and capability workflows." created: "2026-04-19" modified: "2026-04-19" operational: apis: - name: "Amazon CloudTrail API" namespace: cloudtrail baseUrl: https://cloudtrail.us-east-1.amazonaws.com status: active resources: [] actions: - name: list httpMethod: GET pattern: read - name: create httpMethod: POST pattern: write - name: get httpMethod: GET pattern: read - name: delete httpMethod: DELETE pattern: destructive authentication: schemes: - type: AWS Signature Version 4 apis: [cloudtrail] capability: workflows: - name: "Audit Trail Management" file: capabilities/audit-trail-management.yaml toolCount: 7 personas: [Security Analyst] personas: - id: security-analyst name: "Security Analyst" workflows: ["Audit Trail Management"] namespaces: - name: cloudtrail type: consumed baseUri: https://cloudtrail.us-east-1.amazonaws.com - name: cloudtrail-workflow-api type: rest-exposed port: 8080 - name: cloudtrail-workflow-mcp type: mcp-exposed port: 9090 binds: - name: AWS_ACCESS_KEY_ID workflows: ["Audit Trail Management"] - name: AWS_SECRET_ACCESS_KEY workflows: ["Audit Trail Management"] crossReference: []