GCPSAFE
A Model Context Protocol (MCP) server that enables AI assistants like Claude to interact with your Google Cloud Platform environment. This allows for natural language querying and management of your GCP resources during conversations.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server that enables AI assistants like Claude to interact with your Google Cloud Platform environment. This allows for natural language querying and management of your GCP resources during conversations.
Features
- 🔍 Query and modify GCP resources using natural language
- ☁️ Support for multiple GCP projects
- 🌐 Multi-region support
- 🔐 Secure credential handling (no credentials are exposed to external services)
- 🏃♂️ Local execution with your GCP credentials
- 🔄 Automatic retries for improved reliability
Prerequisites
- Node.js
- Claude Desktop/Cursor/Windsurf
- GCP credentials configured locally (application default credentials)
Installation
- Clone the repository:
git clone https://github.com/eniayomi/gcp-mcp cd gcp-mcp
- Install dependencies:
npm install
Configuration
Claude Desktop
- Open Claude desktop app and go to Settings -> Developer -> Edit Config
- Add the following entry to your
claude_desktop_config.json:
via npm:
{
"mcpServers": {
"gcp": {
"command": "sh",
"args": ["-c", "npx -y gcp-mcp"]
}
}
}If you installed from source:
{
"mcpServers": {
"gcp": {
"command": "npm",
"args": [
"--silent",
"--prefix",
"/path/to/gcp-mcp",
"start"
]
}
}
}Replace /path/to/gcp-mcp with the actual path to your project directory if using source installation.
Cursor
- Open Cursor and go to Settings (⌘,)
- Navigate to AI -> Model Context Protocol
- Add a new MCP configuration:
{
"gcp": {
"command": "npx -y gcp-mcp"
}
}Windsurf
- Open
~/.windsurf/config.json(create if it doesn't exist) - Add the MCP configuration:
{
"mcpServers": {
"gcp": {
"command": "npx -y gcp-mcp"
}
}
}GCP Setup
- Set up GCP credentials:
- Set up application default credentials u
58100c7cd8f7OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add gcp-mcp -- npx -y [email protected]
{
"mcpServers": {
"gcp-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (9)
8 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get-billing-budget | read | Get billing budgets for the current project |
get-billing-info | read | Get billing information for the current project |
get-cost-forecast | read | Get cost forecast for the current project |
get-logs | read | Get Cloud Logging entries for the current project |
list-gke-clusters | read | List all GKE clusters in the current project |
list-projects | read | List all GCP projects accessible with current credentials |
list-sql-instances | read | List all Cloud SQL instances in the current project |
run-gcp-code | write | Run GCP code |
select-project | read | Selects GCP project to use for subsequent interactions |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (1)
@google-cloud/bigquery, @google-cloud/billing, @google-cloud/billing-budgets, @google-cloud/compute, @google-cloud/container, @google-cloud/functions, @google-cloud/logging, @google-cloud/resource-man
Gates applied: no_behavioural_pass.
58100c7cd8f7full audit observations/trust-audit/mcp-server/eniayomi__gcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 58100c7cd8f7 | SAFE | B | 89 | first audit |
Questions
What is the GCP MCP server?
A Model Context Protocol (MCP) server that enables AI assistants like Claude to interact with your Google Cloud Platform environment. This allows for natural language querying and management of your GCP resources during conversations.
What tools does GCP expose?
9 in total: 8 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is GCP safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does GCP need?
No credential environment variables were found in its source, so it appears to need none.
How does GCP run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as gcp-mcp at 1.0.2.
How current is this page?
The grade is for one exact copy of the source (58100c7cd8f7), read on 2026-10-06. The repository is watched and re-audited when it changes.