Atlas / MCP servers / bsmi021 / Gemini

GeminiCAUTION

mcp/bsmi021/gemini-5

This project provides a dedicated MCP (Model Context Protocol) server that wraps the @google/genai SDK. It exposes Google's Gemini model capabilities as standard MCP tools, allowing other LLMs (like Cline) or MCP-compatible systems to leverage Gemini's features as a backend workhorse.

Verdict
CAUTION
Grade
C
Trust score
77 /100
Exposed tools
12 12r · 0w · 0d
Transport
sse · stdio · streamable-http
License
MIT
Stars
36
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/bsmi021-mcp-gemini-server)

Table of Contents

  • Overview
  • File Uploads vs URL-Based Analysis
  • Features
  • Prerequisites
  • Installation & Setup
  • Configuration
  • Available Tools
  • Usage Examples
  • Supported Multimedia Analysis Use Cases
  • MCP Gemini Server and Gemini SDK's MCP Function Calling
  • Environment Variables
  • Security Considerations
  • Error Handling
  • Development and Testing
  • Contributing
  • Code Review Tools
  • Server Features
  • Known Issues

Overview

This project provides a dedicated MCP (Model Context Protocol) server that wraps the @google/genai SDK (v0.10.0). It exposes Google's Gemini model capabilities as standard MCP tools, allowing other LLMs (like Claude) or MCP-compatible systems to leverage Gemini's features as a backend workhorse.

This server aims to simplify integration with Gemini models by providing a consistent, tool-based interface managed via the MCP standard. It supports the latest Gemini models including gemini-1.5-pro-latest, gemini-1.5-flash, and gemini-2.5-pro models.

Important Note: This server does not support direct file uploads. Instead, it focuses on URL-based multimedia analysis for images and videos. For text-based content processing, use the standard content generation tools.

File Uploads vs URL-Based Analysis

❌ Not Supported: Direct File Uploads

This MCP Gemini Server does not support the following file upload operati

Read from source at commit c4ca84ee0d99OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-gemini-server --env GITHUB_API_TOKEN=${GITHUB_API_TOKEN} --env GOOGLE_GEMINI_API_KEY=${GOOGLE_GEMINI_API_KEY} --env MCP_CONNECTION_TOKEN=${MCP_CONNECTION_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-gemini-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "GITHUB_API_TOKEN": "${GITHUB_API_TOKEN}",
        "GOOGLE_GEMINI_API_KEY": "${GOOGLE_GEMINI_API_KEY}",
        "MCP_CONNECTION_TOKEN": "${MCP_CONNECTION_TOKEN}"
      }
    }
  }
}
03

Exposed tools (12)

12 read · 0 write · 0 destructive.

ToolRiskDescription
addToolreadA tool that adds two numbers
calculatereadPerform calculations
complexDataToolreadA tool that returns a complex JSON structure
complex_functionreadA function with complex nested parameters
echoToolreadA tool that echoes back the input message
gemini_code_review_streamreadStream code review results for local git diffs using Gemini models
get_weatherreadGet weather information
my-projectreadA TypeScript project
testFunctionreadA test function
test_functionreadTest function
tool1readFirst tool
tool2readSecond tool
04

Trust audit

CAUTIONgrade C · trust 77/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (23)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/services/mcp/McpClientService.ts:371
logger.debug(`Adding connection token to SSE request`);
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/server.ts:1
import { createServer } from "./createServer.js";
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/services/ExampleService.ts:1
import { ConfigurationManager } from "../config/ConfigurationManager.js";
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/services/index.ts:1
// Export all services from this barrel file
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/tools/exampleToolParams.ts:1
import { z } from "zod";
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
src/tools/index.ts:1
import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
LOWInventory / provenance · inv.hidden_file · CWE-1104
.eslintignore
.eslintignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
tests/.env.test.example
.env.test.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/gemini/GeminiCacheService.ts:6
} from "../../utils/errors.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/gemini/GeminiCacheService.ts:7
import { logger } from "../../utils/logger.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/gemini/GeminiCacheService.ts:8
import { CachedContentMetadata } from "../../types/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/gemini/GeminiChatService.ts:11
} from "../../utils/errors.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/gemini/GeminiChatService.ts:12
import { logger } from "../../utils/logger.js";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/integration/urlContextIntegration.test.vitest.ts:290
urls: ["http://192.168.1.1/admin"],
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/utils/UrlSecurityService.test.vitest.ts:163
await expect(service.validateUrl("http://127.0.0.1")).rejects.toThrow(
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/utils/UrlSecurityService.test.vitest.ts:166
await expect(service.validateUrl("http://0.0.0.0")).rejects.toThrow(
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/utils/UrlSecurityService.test.vitest.ts:172
await expect(service.validateUrl("http://192.168.1.1")).rejects.toThrow(
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/utils/UrlSecurityService.test.vitest.ts:175
await expect(service.validateUrl("http://10.0.0.1")).rejects.toThrow(
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
tests/unit/utils/UrlSecurityService.test.vitest.ts:261
await expect(service.validateUrl("https://gоogle.com")).rejects.toThrow(
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
tests/unit/utils/UrlSecurityService.test.vitest.ts:264
await expect(service.validateUrl("https://аpple.com")).rejects.toThrow(
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@google/genai, @modelcontextprotocol/sdk, @octokit/graphql, @octokit/rest, @types/better-sqlite3, @types/eventsource, @types/inquirer, @types/uuid
Why it matters. 37 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:1607
For running tests that require API access, create a `.env.test` file in the project root with the following variables:
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha c4ca84ee0d99full audit observations/trust-audit/mcp-server/bsmi021__gemini-5.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08c4ca84ee0d99CAUTIONC77first audit
06

Questions

What is the Gemini MCP server?

This project provides a dedicated MCP (Model Context Protocol) server that wraps the @google/genai SDK. It exposes Google's Gemini model capabilities as standard MCP tools, allowing other LLMs (like Cline) or MCP-compatible systems to leverage Gemini's features as a backend workhorse.

What tools does Gemini expose?

12 in total: 12 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Gemini safe to connect to an agent?

With care. The audit graded it C (77/100) and found 23 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Gemini need?

It reads GITHUB_API_TOKEN, GOOGLE_GEMINI_API_KEY and MCP_CONNECTION_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Gemini run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-gemini-server at 0.2.0.

How current is this page?

The grade is for one exact copy of the source (c4ca84ee0d99), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement