Atlas / MCP servers / cohnen / Google Ads

Google AdsBLOCK

mcp/cohnen/google-ads

An MCP tool that connects Google Ads with Claude AI/Cursor and others, allowing you to analyze your advertising data through natural language conversations. This integration gives you access to campaign information, performance metrics, keyword analytics, and ad management—all through simple chat wi

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio
License
MIT
Stars
709
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/cohnen-mcp-google-ads)

A tool that connects Google Ads with Claude AI, allowing you to analyze your advertising data through natural language conversations. This integration gives you access to campaign information, performance metrics, keyword analytics, and ad management—all through simple chat with Claude.

What Can This Tool Do For Advertising Professionals?

  1. Account Management
  2. See all your Google Ads accounts in one place
  3. Get account details and basic campaign information
  1. Campaign Analytics & Reporting
  2. Discover which campaigns are performing best
  3. Track impressions, clicks, conversions, and cost metrics
  4. Analyze performance trends over time
  5. Compare different time periods to spot changes
  6. Visualize your data with charts and graphs created by Claude
  1. Keyword & Ad Performance
  2. Identify top and underperforming keywords
  3. Analyze ad copy effectiveness
  4. Check quality scores and competitive metrics
  5. Get actionable insights on how to improve your campaigns
  1. Budget & Bid Management
  2. Monitor campaign budgets and spending
  3. Analyze bid strategies and performance
  4. Identify opportunities for optimization
  5. Get recommendations for budget allocation

Google Ads MCP Architecture Flow

flowchart TB
User(User) -->|Interacts with| Claude
Claude(Claude AI Assistant) -->|Makes requests to| MCP[Google Ads MCP Server]
User -->|Can also use| Cursor[Cursor AI Code Editor]
Cursor -->|Makes requests to| MCP

subgraph "MCP Server"
FastMCP[FastMCP Server] 
Tools[Available Tools]
Auth[Authentication]

FastMCP -->|Exposes| Tools
FastMCP -->|Uses| Auth
end

subgraph "Google Ads Tools"
List
Read from source at commit 7db598f8f3aaOBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-google-ads --env GOOGLE_ADS_AUTH_TYPE=${GOOGLE_ADS_AUTH_TYPE} --env GOOGLE_ADS_CLIENT_SECRET=${GOOGLE_ADS_CLIENT_SECRET} --env GOOGLE_ADS_CREDENTIALS_PATH=${GOOGLE_ADS_CREDENTIALS_PATH} --env GOOGLE_ADS_DEVELOPER_TOKEN=${GOOGLE_ADS_DEVELOPER_TOKEN} -- uvx mcp-google-ads
claude-desktop
{
  "mcpServers": {
    "mcp-google-ads": {
      "command": "uvx",
      "args": [
        "mcp-google-ads"
      ],
      "env": {
        "GOOGLE_ADS_AUTH_TYPE": "${GOOGLE_ADS_AUTH_TYPE}",
        "GOOGLE_ADS_CLIENT_SECRET": "${GOOGLE_ADS_CLIENT_SECRET}",
        "GOOGLE_ADS_CREDENTIALS_PATH": "${GOOGLE_ADS_CREDENTIALS_PATH}",
        "GOOGLE_ADS_DEVELOPER_TOKEN": "${GOOGLE_ADS_DEVELOPER_TOKEN}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
list_accountsread
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (10)

HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.cursor/rules/fastmcp.mdc:1259
47 | DB_DSN = "postgresql://postgres:postgres@localhost:54320/memory_db"
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
.cursor/rules/fastmcp.mdc:1519
307 |         "postgresql://postgres:postgres@localhost:54320/postgres"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/fastmcp.md:1259
47 | DB_DSN = "postgresql://postgres:postgres@localhost:54320/memory_db"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/fastmcp.md:1519
307 |         "postgresql://postgres:postgres@localhost:54320/postgres"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, google-auth, google-auth-oauthlib, google-auth-httplib2, requests, python-dotenv, matplotlib, pandas
Why it matters. 8 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:375
The application will automatically load these values from the `.env` file when it starts.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/fastmcp.md:844
378 |   # Or load from a .env file
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/fastmcp.md:2324
372 |             help="Load environment variables from a .env file",
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/fastmcp.md:2377
425 |         # Load from .env file if specified
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/fastmcp.md:2386
434 |                 logger.error(f"Failed to load .env file: {e}")
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 7db598f8f3aafull audit observations/trust-audit/mcp-server/cohnen__google-ads.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-287db598f8f3aaBLOCKD69first audit
06

Questions

What is the Google Ads MCP server?

An MCP tool that connects Google Ads with Claude AI/Cursor and others, allowing you to analyze your advertising data through natural language conversations. This integration gives you access to campaign information, performance metrics, keyword analytics, and ad management—all through simple chat wi

What tools does Google Ads expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Google Ads safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Google Ads need?

It reads GOOGLE_ADS_AUTH_TYPE, GOOGLE_ADS_CLIENT_SECRET, GOOGLE_ADS_CREDENTIALS_PATH and GOOGLE_ADS_DEVELOPER_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Google Ads run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcp-google-ads.

How current is this page?

The grade is for one exact copy of the source (7db598f8f3aa), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement