← Back to Blog

Zero Strangers Connected an AWS Account. So the Scanner Runs on Your Machine.

Rick Wise6 min read
Build in PublicDeveloper ToolsAWSFinOps
Zero Strangers Connected an AWS Account. So the Scanner Runs on Your Machine.

For fourteen months I built CloudWise, a hosted tool that finds AWS waste and fixes it safely.

This summer I stopped building and ran an experiment with exactly one metric: would ten strangers connect an AWS account by October 12?

The answer was zero.

Why zero is the right answer

It took me too long to see it, but it's obvious from the other side of the table. Connecting a cost tool means creating an IAM role in your account and handing it to a vendor. When the vendor is one person you've never heard of, the sensible answer is no. It doesn't matter how good the scans are. Nobody gets far enough to see them.

I had been trying to fix a trust problem with features. Fourteen months of detectors, dashboards and an AI copilot, aimed at a step nobody would take.

So the scanner comes to you

Today the scanner is free and source-available (FSL-1.1-ALv2) as cloudcostwise. It runs on your machine, with your own read-only credentials:

pipx install cloudcostwise
cloudcostwise scan --profile my-profile --regions all

It checks 20 AWS services, including EC2, EBS, S3, RDS, DynamoDB, ElastiCache, Lambda, NAT gateways and load balancers, Elastic IPs, VPC endpoints, CloudWatch logs and dashboards, ECR, EFS, SageMaker, Lightsail, WorkSpaces, dangling DNS records, RI and Savings Plans opportunities, and Compute Optimizer. All 17 regions take a few minutes, four regions at a time.

It's also an MCP server. With uv installed, add it to Claude Code or Codex and ask "where am I wasting money on AWS?":

/plugin marketplace add cloudwise-app/cloudcostwise
/plugin install cloudcostwise@cloudcostwise

Three promises, enforced in code

It cannot change anything. Every AWS call goes through a guard that refuses any operation that isn't Describe, List, Get, Search or Lookup, before the request leaves your machine. If one were ever attempted, the scan stops with an error. Read-only by construction, not by policy.

Nothing is sent to CloudWise. No signup, no telemetry, no update checks. I recorded every network connection during a full scan: 48 hosts, all of them *.amazonaws.com. If you use it through Claude Code or Codex, the findings go to that assistant like any other tool output, so treat them the way you treat the rest of your session.

It tells you what it costs you. The RI and Savings Plans checks call Cost Explorer, which AWS bills at $0.01 per request, about $0.13 a scan. The tool says so before it runs, and --no-cost-explorer skips them.

What AWS's free tools don't flag

The fair question: AWS already has Cost Optimization Hub and Compute Optimizer for free, and Trusted Advisor's cost checks if you pay for a Business or Enterprise support plan. Use them. For idle EC2, RDS and NAT gateways and for rightsizing, this tool overlaps with them.

So I went through AWS's own lists of what those three cover (Trusted Advisor, Cost Optimization Hub, Compute Optimizer) and compared every check this tool has proven on real resources. Of its 42 proven checks, 15 flag waste that none of AWS's tools flag, and 9 more go further than the closest AWS check. A few:

  • Log groups set to never expire. They grow every month. Trusted Advisor does check log retention, but it flags retention that is too short, for compliance, so "never expire" passes.
  • Old and untagged ECR images. Trusted Advisor checks that a repository has a lifecycle policy. Nothing flags the images already piling up.
  • EFS file systems with no mount targets. Nothing can read them and they still bill. Trusted Advisor's EFS checks look at redundancy, throughput and backups, not this.
  • Lambda functions that would be about 20% cheaper on arm64, Redis clusters that would be about 20% cheaper on Valkey, ElastiCache versions paying the Extended Support surcharge, and anything in Lightsail. None of the three looks at these.

The full list, with the closest AWS check for each and the AWS page that says so, is in the README. The hosted product adds 14 more proven checks none of AWS's tools flag, across Glue, Step Functions, AWS Backup, AppSync, Elastic Beanstalk and KMS.

On my test account, where the resources are deliberately tiny, the scan reports some of them like this:

old_ecr_images  x1  $0.06/mo
    us-east-1       cwfx-old-ecr-images                         $0.06/mo
untagged_ecr_images  x1  $0.02/mo
    us-east-1       cwfx-untagged-ecr-images                    $0.02/mo
idle_efs  x1  $0.01/mo
    us-east-1       fs-090bfb32bd49de8b7                        $0.01/mo
no_retention_log_group  x1  $0.01/mo
    us-east-1       /aws/lambda/cwfx-clo464-docdb-connect       $0.01/mo

How I know the checks are right

Cost tools have a credibility problem: a wrong finding is worse than no finding. So every waste type is tracked in a validation ledger with levels:

  • L1: reviewed against current AWS documentation and pricing
  • L2: fired on a real AWS resource built to trigger it, and stayed silent on a healthy twin
  • L3: its finding rendered correctly in the product

Of the 91 waste types this tool can report, 49 are proven at L2 or above against real resources in a test account. The other 42 are desk-reviewed. Findings that couldn't be validated within budget are labelled advisory and never added to a savings total. The full table is public: VALIDATION.md.

I wrote most of this with Claude Code. The ledger is how I keep that honest.

What's free and what isn't

The free scanner is 20 of the 46 service checks in CloudWise. The other 26 (Glue, ECS, Step Functions, Backup, CloudFront, commitments and more) stay in the hosted product, along with history, alerts, savings reconciled against your actual bill, and fixes you approve, with rollback. If the local scan earns your trust, that's where the rest lives.

The license is the Functional Source License: read it, run it, use it at work. The one thing you can't do is sell it as a competing product. Each release becomes Apache 2.0 two years after it ships.

The ask

Run it on a real account and tell me where it's wrong. A false positive in your account is the most useful thing you could send me. Open an issue, or reply wherever you found this.

The repo: github.com/cloudwise-app/cloudcostwise

Stop wasting money on AWS

CloudWise monitors 45 AWS services and finds waste automatically. Free forever.

Start Free Scan →