Atlas / MCP servers / ahonn / Google Search Console

Google Search ConsoleSAFE

mcp/ahonn/google-search-console

A Model Context Protocol (MCP) server providing access to Google Search Console

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
8 7r · 1w · 0d
Transport
stdio · streamable-http
License
—
Stars
277
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server providing comprehensive access to Google Search Console data with enhanced analytics capabilities.

Features

  • Enhanced Search Analytics: Retrieve up to 25,000 rows of performance data
  • Advanced Filtering: Support for regex patterns and multiple filter operators
  • Quick Wins Detection: Automatically identify optimization opportunities
  • Rich Dimensions: Query, page, country, device, and search appearance analysis
  • Flexible Date Ranges: Customizable reporting periods with historical data access

Sponsored by

macuse.app is a native macOS application that gives your AI superpowers by integrating AI assistants with macOS apps like Calendar, Mail, and Notes, plus universal UI control for any application. Supports Claude Desktop, Cursor, and Raycast with one-click setup. Privacy-first, runs locally.

Prerequisites

  • Node.js 18 or later
  • Google Cloud Project with Search Console API enabled
  • Service Account credentials with Search Console access

Installation

npm install mcp-server-gsc

Authentication Setup

To obtain Google Search Console API credentials:

  1. Visit the Google Cloud Console
  2. Create a new project or select an existing one
  3. Enable the API:
  1. Create credentials:
  • Navigate to "APIs & Services" > "Credentials"
  • Click "Create Credentials" > "Service Account"
  • Fill in the service account details
  • Create a new key in JSON format
  • The credentials file (.json) will download automatically
  1. Grant access:
  • Open S
Read from source at commit 1ca60a48cb53OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add buffer-equal-constant-time --env GOOGLE_APPLICATION_CREDENTIALS=${GOOGLE_APPLICATION_CREDENTIALS} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "buffer-equal-constant-time": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "GOOGLE_APPLICATION_CREDENTIALS": "${GOOGLE_APPLICATION_CREDENTIALS}"
      }
    }
  }
}
03

Exposed tools (8)

7 read · 1 write · 0 destructive.

ToolRiskDescription
detect_quick_winsreadAutomatically detect SEO quick wins and optimization opportunities
enhanced_search_analyticsreadEnhanced search analytics with up to 25,000 rows, regex filters, and quick wins detection
get_sitemapreadGet a sitemap for a site in Google Search Console
index_inspectreadInspect a URL to see if it is indexed or can be indexed
list_sitemapsreadList sitemaps for a site in Google Search Console
list_sitesreadList all sites in Google Search Console
search_analyticsreadGet search performance data from Google Search Console
submit_sitemapwriteSubmit a sitemap for a site in Google Search Console
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@google-cloud/local-auth, @hono/mcp, @modelcontextprotocol/sdk, google-auth-library, googleapis, hono, zod, zod-to-json-schema
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-06 · audit v0.4.1 · source sha 1ca60a48cb53full audit observations/trust-audit/mcp-server/ahonn__google-search-console.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-061ca60a48cb53SAFEB89first audit
06

Questions

What is the Google Search Console MCP server?

A Model Context Protocol (MCP) server providing access to Google Search Console

What tools does Google Search Console expose?

8 in total: 7 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Google Search Console safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Google Search Console need?

It reads GOOGLE_APPLICATION_CREDENTIALS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Google Search Console run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as buffer-equal-constant-time at 1.0.2.

How current is this page?

The grade is for one exact copy of the source (1ca60a48cb53), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement