Atlas / MCP servers / entropy-data / Data Product

Data ProductCAUTION

mcp/entropy-data/data-product

A Model Context Protocol (MCP) server for discovering data products and requesting access in Data Mesh Manager, and executing queries on the data platform to access business data.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
4 4r · 0w · 0d
Transport
stdio
License
MIT
Stars
46
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for discovering data products and requesting access in Data Mesh Manager, and executing queries on the data platform to access business data.

Concept

Idea: Enable AI agents to find and access any data product for semantic business context while enforcing data governance policies.

or, if you prefer:

Enable AI to answer any business question.

Data Products are managed high-quality business data sets shared with other teams within an organization and specified by data contracts. Data contracts describe the structure, semantics, quality, and terms of use. Data products provide the semantic context AI needs to understand not just what data exists, but what it means and how to use it correctly. We use Data Mesh Manager as a data product marketplace to search for available data products and evaluate if these are relevant for the task by analyzing its metadata.

Once a data product is identified, data governance plays a crucial role in ensuring that access to data products is controlled, queries are in line with the data contract's terms of use, and its compliance with organizational global policies. If necessary, the AI agent can request access to the data product's output port, which may require manual approval from the data product owner.

Finally, the LLM can generate SQL queries based on the data contracts data model descriptions and semantics. The SQL queries are executed, while security guardrails are in place to ensure that no sensitive data is misused and attack vectors (such as prompt injections) are mitigated. The results are returned to the AI agent, which can then use them to answer the

Read from source at commit cd52d76fd51cOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add dataproduct_mcp --env BIGQUERY_CREDENTIALS_PATH=${BIGQUERY_CREDENTIALS_PATH} --env DATABRICKS_CLIENT_SECRET=${DATABRICKS_CLIENT_SECRET} --env DATAMESH_MANAGER_API_KEY=${DATAMESH_MANAGER_API_KEY} --env SNOWFLAKE_PASSWORD=${SNOWFLAKE_PASSWORD} -- uvx dataproduct_mcp
claude-desktop
{
  "mcpServers": {
    "dataproduct_mcp": {
      "command": "uvx",
      "args": [
        "dataproduct_mcp"
      ],
      "env": {
        "BIGQUERY_CREDENTIALS_PATH": "${BIGQUERY_CREDENTIALS_PATH}",
        "DATABRICKS_CLIENT_SECRET": "${DATABRICKS_CLIENT_SECRET}",
        "DATAMESH_MANAGER_API_KEY": "${DATAMESH_MANAGER_API_KEY}",
        "SNOWFLAKE_PASSWORD": "${SNOWFLAKE_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (4)

4 read · 0 write · 0 destructive.

ToolRiskDescription
dataproduct_getread
dataproduct_queryread
dataproduct_request_accessread
dataproduct_searchread
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

MEDIUMPrompt injection · prompt.hidden_style · CWE-94, CWE-1427
README.md:211
<a href="https://github.com/entropy-data/dataproduct-mcp" class="github-corner" aria-label="View source on GitHub"><svg width="80" height="80" viewBox="0 0 250 250" style="fill:#151513; color:#fff; po

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha cd52d76fd51cfull audit observations/trust-audit/mcp-server/entropy-data__data-product.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08cd52d76fd51cCAUTIONB89first audit
06

Questions

What is the Data Product MCP server?

A Model Context Protocol (MCP) server for discovering data products and requesting access in Data Mesh Manager, and executing queries on the data platform to access business data.

What tools does Data Product expose?

4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Data Product safe to connect to an agent?

With care. The audit graded it B (89/100) and found 1 thing worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Data Product need?

It reads BIGQUERY_CREDENTIALS_PATH, DATABRICKS_CLIENT_SECRET, DATAMESH_MANAGER_API_KEY and SNOWFLAKE_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Data Product run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as dataproduct_mcp.

How current is this page?

The grade is for one exact copy of the source (cd52d76fd51c), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement