Same. I’ve had good results with read only accounts / tokens and let the agent have at it. Also works with terraform, aws cli, etc.
One does not need a new/separate tool to do any of this, just include it in your agents instructions.