Atlas / MCP servers / aiven-open / Aiven

AivenCAUTION

mcp/aiven-open/aiven

Model Context Protocol server for Aiven

Verdict
CAUTION
Grade
D
Trust score
69 /100
Exposed tools
—
Transport
stdio · streamable-http
License
Apache-2.0
Stars
28
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for the Aiven cloud data platform.

Manage PostgreSQL, Apache Kafka, applications, and other Aiven services directly from AI assistants like Claude, Cursor, and VS Code Copilot.

[!WARNING] Use with care. This MCP server can create, modify, and delete Aiven services and data on your behalf. AI agents may execute destructive actions (dropping databases, deleting services, producing messages) based on their interpretation of your prompts. You are fully responsible for the actions taken through this tool. Permissions: Access is governed by the Aiven user permissions associated with the authenticated account. The MCP server can only perform actions that your Aiven user is allowed to do. AI Agent Security: AI agents may need access credentials (database connection strings, streaming tokens) to act on your behalf. Review what your agent is doing, especially in production environments. Follow your organization's security policies and do a risk assessment before giving AI agents access to sensitive resources.

Quick Start

Option 1: Remote (hosted by Aiven)

The MCP server is hosted at https://mcp.aiven.live/mcp. Your MCP client will prompt you to authorize on Aiven.

Claude Code

claude mcp add --scope user --transport http aiven-mcp "https://mcp.aiven.live/mcp"

Cursor

[](https://cursor.com/en-US/install-mcp?name=aiven-mcp&config=eyJ1cmwiOiJodHRwczovL21jcC5haXZlbi5saXZlL21jcCJ9)

Or manually add to Cursor MCP settings:

{
"mcpServers": {
"aiven-mcp": {
"url": "https://mcp.aiven.live/mcp"
}
}
}

VS Code / Copilot

Add to .vscode/mcp.json in your workspace:

{
"servers": {
"aiven-mcp": {
"type": "http",
"url": "https://mcp.aiven.live/mcp"
}
}
}

Read-Only Mode

Read from source at commit f28780bd906aOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-aiven --env AIVEN_TOKEN=${AIVEN_TOKEN} -- npx -y [email protected]
03

Trust audit

CAUTIONgrade D · trust 69/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (18)

MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/runtime/connection-info.test.ts:63
service_uri: 'postgres://u:p@h:5432/defaultdb',
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/runtime/reasoning-redaction.test.ts:7
expect(scrubReasoning('use postgres://admin:[email protected]:5432/main to query')).toBe(
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/runtime/redact.test.ts:146
message: 'error connecting to postgres://avnadmin:AVNS_secret@pg-host:5432/defaultdb',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/runtime/service-integrations.test.ts:84
password: 'resolved-password-must-not-be-returned',
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/runtime/connection-info.test.ts:84
access_key: '-----BEGIN PRIVATE KEY-----\nkey\n-----END PRIVATE KEY-----',
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/runtime/reasoning-redaction.test.ts:56
const key = '-----BEGIN PRIVATE KEY-----\nMIIBVwIBADANBg\n-----END PRIVATE KEY-----';
LOWInventory / provenance · inv.hidden_file · CWE-1104
.lintstagedrc
.lintstagedrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/applications/handlers.ts:2
import type { AivenClient } from '../../client.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/applications/handlers.ts:3
import type { ToolDefinition, ToolResult, HandlerContext, RequestOptions } from '../../types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/applications/handlers.ts:13
} from '../../types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/applications/handlers.ts:14
import { errorMessage } from '../../errors.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/applications/handlers.ts:15
import { redactSensitiveData } from '../../security.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, express, google-auth-library, express-rate-limit, libpg-query, openapi-fetch, yaml, zod
Why it matters. 23 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:194
Production HTTP traffic is rate-limited in two layers: Cloudflare enforces a per-client-IP limit (configured in the Cloudflare dashboard), and this server enforces `MCP_HTTP_RATE_LIMIT_*` per bearer t
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:12
> **AI Agent Security:** AI agents may need access credentials (database connection strings, streaming tokens) to act on your behalf. Review what your agent is doing, especially in production environm
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f28780bd906afull audit observations/trust-audit/mcp-server/aiven-open__aiven.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f28780bd906aCAUTIOND69first audit
05

Questions

What is the Aiven MCP server?

Model Context Protocol server for Aiven

Is Aiven safe to connect to an agent?

With care. The audit graded it D (69/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Aiven need?

It reads AIVEN_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Aiven run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-aiven at 1.17.1.

How current is this page?

The grade is for one exact copy of the source (f28780bd906a), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement