{"id":29202420,"url":"https://github.com/awsdataarchitect/agent2agent-strands-ai21-maestro","last_synced_at":"2026-07-30T12:31:51.080Z","repository":{"id":301911492,"uuid":"1009881270","full_name":"awsdataarchitect/agent2agent-strands-ai21-maestro","owner":"awsdataarchitect","description":"Agent-to-Agent AI Integration: AWS Security Analysis with AI21 Maestro \u0026 Strands Agents","archived":false,"fork":false,"pushed_at":"2025-06-29T14:29:36.000Z","size":114,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2025-06-29T15:31:38.182Z","etag":null,"topics":["agentic-ai","ai21labs","amazon-nova","mcp-tools","strands-agent"],"latest_commit_sha":null,"homepage":"https://vivek-aws.medium.com/aws-security-analysis-with-ai21-maestro-strands-agents-6731e97b7098","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/awsdataarchitect.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2025-06-27T22:08:27.000Z","updated_at":"2025-06-29T14:45:18.000Z","dependencies_parsed_at":"2025-06-29T15:42:25.020Z","dependency_job_id":null,"html_url":"https://github.com/awsdataarchitect/agent2agent-strands-ai21-maestro","commit_stats":null,"previous_names":["awsdataarchitect/agent2agent-strands-ai21-maestro"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/awsdataarchitect/agent2agent-strands-ai21-maestro","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/awsdataarchitect%2Fagent2agent-strands-ai21-maestro","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/awsdataarchitect%2Fagent2agent-strands-ai21-maestro/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/awsdataarchitect%2Fagent2agent-strands-ai21-maestro/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/awsdataarchitect%2Fagent2agent-strands-ai21-maestro/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/awsdataarchitect","download_url":"https://codeload.github.com/awsdataarchitect/agent2agent-strands-ai21-maestro/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/awsdataarchitect%2Fagent2agent-strands-ai21-maestro/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":279001435,"owners_count":26083078,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-10-09T02:00:07.460Z","response_time":59,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["agentic-ai","ai21labs","amazon-nova","mcp-tools","strands-agent"],"created_at":"2025-07-02T13:08:20.026Z","updated_at":"2025-10-09T12:34:49.402Z","avatar_url":"https://github.com/awsdataarchitect.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# AWS Security Analysis with AI21 Maestro \u0026 Strands Agents\n\n![AWS Security Analysis Architecture](aws_security_analysis.png)\n\nThis project demonstrates cutting-edge **agent-to-agent AI integration** using AI21 Maestro's requirement-driven report generation and Strands Agents for intelligent tool orchestration. The solution combines AWS Security Hub findings analysis and CloudTrail activity monitoring through **Model Context Protocol (MCP)** to provide comprehensive security insights powered by Amazon Bedrock Nova Premier and AI21's Jamba Mini 1.6 model.\n\n## 🤖 Agent-to-Agent AI Integration: The Future is Here\n\n• **Multi-Agent Architecture**: Built a Strands Agent that intelligently calls AI21 Maestro agentic tools through Model Context Protocol (MCP) - showcasing true agent-to-agent communication for AWS security analysis\n\n• **MCP-Powered Tool Orchestration**: Leveraging Model Context Protocol to enable seamless interoperability between Amazon Bedrock Nova Premier (Strands) and AI21's Jamba Mini - proving that different AI systems can work together harmoniously\n\n• **Intelligent Tool Selection**: The Strands Agent automatically determines when to invoke AI21 Maestro tools based on natural language queries - \"Check my security findings\" triggers Security Hub analysis, while \"Analyze suspicious activity\" calls CloudTrail monitoring\n\n• **Validated AI Output**: AI21 Maestro's requirement-based validation ensures consistent, professional security reports every time - no hallucinations, no formatting inconsistencies, just reliable enterprise-grade analysis\n\n• **Real-World Impact**: Transforming AWS security analysis from hours of manual work to seconds of AI-powered insights - analyzing thousands of Security Hub findings and CloudTrail events with structured, actionable recommendations\n\n• **Open Source Innovation**: Built with MCP compatibility in mind, making these agentic tools reusable across different AI frameworks - contributing to the broader AI ecosystem interoperability\n\n## 🚀 Features\n\n### Core Capabilities\n- **Security Hub Analysis**: Retrieves and analyzes AWS Security Hub findings with severity breakdown, affected resources, and issue categorization\n- **CloudTrail Monitoring**: Analyzes CloudTrail events for suspicious activities, user behavior patterns, and geographic anomalies\n- **AI21 Maestro Requirements**: Uses explicit constraints and validation cycles for consistent, professional security reports\n- **Intelligent Agent**: Strands Agent powered by Amazon Bedrock Nova Premier for natural language interaction\n\n### Technical Features\n- **MCP Tool Integration**: Two focused tools compatible with Model Context Protocol for cross-framework reusability\n- **Environment-based Configuration**: Secure API key management via environment variables\n- **Simplified Architecture**: Streamlined async/sync handling with `asyncio.run()`\n- **Enhanced Output Processing**: Clean response handling with proper text extraction\n- **Robust Error Handling**: Comprehensive error management for AWS API calls and AI model interactions\n\n## 📋 Requirements\n\n- Python 3.10+\n- AWS credentials configured with Security Hub and CloudTrail access\n- AI21 API key (set as environment variable)\n- Amazon Bedrock access (Nova Premier model)\n- Appropriate IAM permissions for:\n  - `securityhub:GetFindings`\n  - `cloudtrail:LookupEvents`\n  - `bedrock:InvokeModel`\n\n## 🛠 Installation\n\n1. Clone this repository\n2. Install dependencies:\n   ```bash\n   pip install -r requirements.txt\n   ```\n3. Set your AI21 API key as an environment variable:\n   ```bash\n   export AI21_API_KEY=your_ai21_api_key_here\n   ```\n4. Ensure AWS credentials are configured:\n   ```bash\n   aws configure\n   # or set environment variables\n   export AWS_ACCESS_KEY_ID=your_key\n   export AWS_SECRET_ACCESS_KEY=your_secret\n   export AWS_DEFAULT_REGION=us-east-1\n   ```\n\n## 🎯 Usage\n\n### Strands Agent with Agent-to-Agent Communication\n```bash\npython strands_ai21_maestro_agent.py\n```\n\n**Natural language interaction examples:**\n- \"Analyze my Security Hub findings\" → Triggers Security Hub analysis via AI21 Maestro\n- \"Check CloudTrail for suspicious activity\" → Invokes CloudTrail monitoring tool\n- \"What security issues should I prioritize?\" → Agent determines best analysis approach\n- \"Are there any failed login attempts?\" → Automatically selects CloudTrail analysis\n\n## 🔧 MCP Tools: Agent-to-Agent Communication\n\n### 1. `analyze_aws_security_hub()`\n**Purpose**: Strands Agent → AI21 Maestro for Security Hub analysis\n\n**Agent Communication Flow**:\n1. Strands Agent (Nova Premier) receives user query\n2. Agent determines Security Hub analysis is needed\n3. Invokes MCP tool via `@tool` decorator\n4. Tool calls AI21 Maestro with structured requirements\n5. Maestro (Jamba Mini 1.6) validates output against requirements\n6. Returns professional security report to Strands Agent\n7. Agent presents insights to user\n\n**AI21 Maestro Requirements**:\n- Markdown formatting with proper headers and code blocks\n- Include all numerical data in analysis\n- Prioritize CRITICAL and HIGH severity findings\n- Provide actionable remediation steps\n- Professional security analyst tone\n- Structured sections (Executive Summary, Severity Analysis, etc.)\n- Concise length under 300 words\n- No assumptions beyond provided data\n\n### 2. `analyze_aws_cloudtrail()`\n**Purpose**: Strands Agent → AI21 Maestro for CloudTrail insights\n\n**Agent Communication Flow**:\n1. User asks about suspicious activity or login patterns\n2. Strands Agent intelligently selects CloudTrail analysis\n3. MCP tool retrieves and processes CloudTrail events\n4. Sends structured data to AI21 Maestro with requirements\n5. Maestro generates validated security insights\n6. Agent receives and presents actionable recommendations\n\n**AI21 Maestro Requirements**:\n- Markdown formatting with headers and numbered lists\n- Highlight high-risk activities requiring investigation\n- Analyze user behavior patterns for anomalies\n- Geographic insights for unusual locations\n- Focus on failed operations as security indicators\n- Actionable security recommendations\n- Threat assessment with risk rating\n- Concise insights under 350 words\n\n## 🎯 AI21 Maestro Requirements System\n\nThis project showcases AI21 Maestro's powerful requirements feature for agent-to-agent communication:\n\n### How Agent-to-Agent Requirements Work\n- **Explicit Constraints**: Strands Agent defines up to 10 specific requirements for AI21 Maestro\n- **Generate → Validate → Fix Cycle**: Maestro creates, evaluates, and refines output until all requirements are met\n- **Scoring System**: Each requirement is scored 0.0 to 1.0, with refinement for scores \u003c 1.0\n- **Budget Control**: Process continues until requirements are satisfied or budget is exhausted\n\n### Agent Communication Flow\n```\nStrands Agent → MCP Tool → AI21 Maestro → Requirements Validation → Refined Output → Strands Agent → User\n     ↑                                                                                    ↓\n     ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ← ←\n```\n\nThis ensures consistent, professional security reports through validated agent-to-agent communication.\n\n## 📊 Example Agent-to-Agent Output\n\n### Security Hub Analysis (Strands → AI21 Maestro)\n```markdown\n## AWS Security Hub Analysis Report\n\n### Executive Summary\nYour AWS environment shows 18 active security findings requiring attention...\n\n### Severity Analysis\n- **CRITICAL**: 2 findings requiring immediate action\n- **HIGH**: 5 findings needing prompt remediation\n- **MEDIUM**: 8 findings for scheduled resolution\n\n### Recommended Actions\n1. **Immediate**: Address EC2 instance vulnerabilities\n2. **This Week**: Update S3 bucket policies\n3. **This Month**: Review IAM permissions\n```\n\n## 🏗 Multi-Agent Architecture\n\n### Agent Communication Components\n1. **Strands Agent (Python)** - Main orchestrator using Nova Premier for reasoning\n2. **MCP Protocol** - Enables seamless agent-to-agent communication\n3. **Two Specialized AI21 Maestro Tools** - Security Hub and CloudTrail analysis\n4. **Requirements Validation** - Ensures consistent, professional output\n5. **AWS Services Integration** - Real-time security data sources\n\n### Key Innovations in Agent-to-Agent Design\n- **Environment Variable Configuration**: Secure API key management\n- **Simplified Async Handling**: Clean `asyncio.run()` implementation for agent communication\n- **Enhanced Response Processing**: Proper text extraction from multi-agent responses\n- **MCP Compatibility**: Tools work across different AI frameworks\n- **Intelligent Tool Selection**: Agent automatically chooses appropriate analysis based on user intent\n\n## 🔒 Security Best Practices\n\n### Environment Variables\n```bash\n# Required for agent-to-agent communication\nexport AI21_API_KEY=your_ai21_api_key\n\n# AWS (if not using aws configure)\nexport AWS_ACCESS_KEY_ID=your_access_key\nexport AWS_SECRET_ACCESS_KEY=your_secret_key\nexport AWS_DEFAULT_REGION=us-east-1\n```\n\n### IAM Permissions (Minimum Required)\n```json\n{\n    \"Version\": \"2012-10-17\",\n    \"Statement\": [\n        {\n            \"Effect\": \"Allow\",\n            \"Action\": [\n                \"securityhub:GetFindings\",\n                \"cloudtrail:LookupEvents\",\n                \"bedrock:InvokeModel\"\n            ],\n            \"Resource\": \"*\"\n        }\n    ]\n}\n```\n\n## 🐛 Troubleshooting\n\n### Common Agent Communication Issues\n\n1. **Missing AI21 API Key**\n   ```\n   ValueError: AI21_API_KEY environment variable is required\n   ```\n   **Solution**: Set the environment variable for agent-to-agent communication\n\n2. **MCP Tool Response Processing**\n   - Enhanced response handling extracts clean text from agent communications\n   - Properly processes multi-agent response chains\n   - Removes thinking tags for clean output\n\n## 📁 Project Structure\n\n```\naws-security-analysis/\n├── strands_ai21_maestro_agent.py # Main agent-to-agent implementation\n├── requirements.txt             # Python dependencies\n└── README.md                   # This documentation\n```\n\n## 🔄 Dependencies\n\n```\nai21==2.0.0                    # AI21 Maestro agent integration\nboto3\u003e=1.28.0                  # AWS SDK\nbotocore\u003e=1.31.0               # AWS core functionality\npython-dateutil\u003e=2.8.2         # Date/time handling\nstrands-agents\u003e=0.1.0          # Strands agent framework\nstrands-agents-tools\u003e=0.1.0    # MCP tool support\n```\n\n## 🌟 Contributing to Agent-to-Agent AI\n\nThis project demonstrates the future of AI integration through:\n- **MCP Protocol adoption** for cross-framework compatibility\n- **Agent-to-agent communication** patterns\n- **Requirements-driven validation** for reliable outputs\n- **Open source innovation** in multi-AI orchestration\n\nContributions welcome to advance the agent-to-agent AI ecosystem!\n\n## 📄 License\n\n[MIT License](LICENSE)\n\n## 🆘 Support\n\nFor issues and questions:\n- AWS Security Hub: [AWS Documentation](https://docs.aws.amazon.com/securityhub/)\n- AI21 Maestro: [AI21 Documentation](https://docs.ai21.com/docs/ai21-maestro-in-depth-guide)\n- Strands Agents: [Strands Documentation](https://strandsagents.com)\n- Amazon Bedrock: [Bedrock Documentation](https://docs.aws.amazon.com/bedrock/)\n- Model Context Protocol: [MCP Documentation](https://modelcontextprotocol.io)","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fawsdataarchitect%2Fagent2agent-strands-ai21-maestro","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fawsdataarchitect%2Fagent2agent-strands-ai21-maestro","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fawsdataarchitect%2Fagent2agent-strands-ai21-maestro/lists"}