GeminiCAUTION
This project provides a dedicated MCP (Model Context Protocol) server that wraps the @google/genai SDK. It exposes Google's Gemini model capabilities as standard MCP tools, allowing other LLMs (like Cline) or MCP-compatible systems to leverage Gemini's features as a backend workhorse.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/bsmi021-mcp-gemini-server)
Table of Contents
- Overview
- File Uploads vs URL-Based Analysis
- Features
- Prerequisites
- Installation & Setup
- Configuration
- Available Tools
- Usage Examples
- Supported Multimedia Analysis Use Cases
- MCP Gemini Server and Gemini SDK's MCP Function Calling
- Environment Variables
- Security Considerations
- Error Handling
- Development and Testing
- Contributing
- Code Review Tools
- Server Features
- Known Issues
Overview
This project provides a dedicated MCP (Model Context Protocol) server that wraps the @google/genai SDK (v0.10.0). It exposes Google's Gemini model capabilities as standard MCP tools, allowing other LLMs (like Claude) or MCP-compatible systems to leverage Gemini's features as a backend workhorse.
This server aims to simplify integration with Gemini models by providing a consistent, tool-based interface managed via the MCP standard. It supports the latest Gemini models including gemini-1.5-pro-latest, gemini-1.5-flash, and gemini-2.5-pro models.
Important Note: This server does not support direct file uploads. Instead, it focuses on URL-based multimedia analysis for images and videos. For text-based content processing, use the standard content generation tools.
File Uploads vs URL-Based Analysis
❌ Not Supported: Direct File Uploads
This MCP Gemini Server does not support the following file upload operati
c4ca84ee0d99OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-gemini-server --env GITHUB_API_TOKEN=${GITHUB_API_TOKEN} --env GOOGLE_GEMINI_API_KEY=${GOOGLE_GEMINI_API_KEY} --env MCP_CONNECTION_TOKEN=${MCP_CONNECTION_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"mcp-gemini-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"GITHUB_API_TOKEN": "${GITHUB_API_TOKEN}",
"GOOGLE_GEMINI_API_KEY": "${GOOGLE_GEMINI_API_KEY}",
"MCP_CONNECTION_TOKEN": "${MCP_CONNECTION_TOKEN}"
}
}
}
}Exposed tools (12)
12 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
addTool | read | A tool that adds two numbers |
calculate | read | Perform calculations |
complexDataTool | read | A tool that returns a complex JSON structure |
complex_function | read | A function with complex nested parameters |
echoTool | read | A tool that echoes back the input message |
gemini_code_review_stream | read | Stream code review results for local git diffs using Gemini models |
get_weather | read | Get weather information |
my-project | read | A TypeScript project |
testFunction | read | A test function |
test_function | read | Test function |
tool1 | read | First tool |
tool2 | read | Second tool |
Trust audit
CAUTIONgrade C · trust 77/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (23)
logger.debug(`Adding connection token to SSE request`);
import { createServer } from "./createServer.js";import { ConfigurationManager } from "../config/ConfigurationManager.js";// Export all services from this barrel file
import { z } from "zod";import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";.eslintignore
.prettierrc.json
.env.test.example
} from "../../utils/errors.js";
import { logger } from "../../utils/logger.js";import { CachedContentMetadata } from "../../types/index.js";} from "../../utils/errors.js";
import { logger } from "../../utils/logger.js";urls: ["http://192.168.1.1/admin"],
await expect(service.validateUrl("http://127.0.0.1")).rejects.toThrow(await expect(service.validateUrl("http://0.0.0.0")).rejects.toThrow(await expect(service.validateUrl("http://192.168.1.1")).rejects.toThrow(await expect(service.validateUrl("http://10.0.0.1")).rejects.toThrow(await expect(service.validateUrl("https://gоogle.com")).rejects.toThrow(await expect(service.validateUrl("https://аpple.com")).rejects.toThrow(@google/genai, @modelcontextprotocol/sdk, @octokit/graphql, @octokit/rest, @types/better-sqlite3, @types/eventsource, @types/inquirer, @types/uuid
For running tests that require API access, create a `.env.test` file in the project root with the following variables:
Gates applied: no_behavioural_pass.
c4ca84ee0d99full audit observations/trust-audit/mcp-server/bsmi021__gemini-5.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | c4ca84ee0d99 | CAUTION | C | 77 | first audit |
Questions
What is the Gemini MCP server?
This project provides a dedicated MCP (Model Context Protocol) server that wraps the @google/genai SDK. It exposes Google's Gemini model capabilities as standard MCP tools, allowing other LLMs (like Cline) or MCP-compatible systems to leverage Gemini's features as a backend workhorse.
What tools does Gemini expose?
12 in total: 12 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Gemini safe to connect to an agent?
With care. The audit graded it C (77/100) and found 23 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Gemini need?
It reads GITHUB_API_TOKEN, GOOGLE_GEMINI_API_KEY and MCP_CONNECTION_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Gemini run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-gemini-server at 0.2.0.
How current is this page?
The grade is for one exact copy of the source (c4ca84ee0d99), read on 2026-10-08. The repository is watched and re-audited when it changes.