Data ProductCAUTION
A Model Context Protocol (MCP) server for discovering data products and requesting access in Data Mesh Manager, and executing queries on the data platform to access business data.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for discovering data products and requesting access in Data Mesh Manager, and executing queries on the data platform to access business data.
Concept
Idea: Enable AI agents to find and access any data product for semantic business context while enforcing data governance policies.
or, if you prefer:
Enable AI to answer any business question.
Data Products are managed high-quality business data sets shared with other teams within an organization and specified by data contracts. Data contracts describe the structure, semantics, quality, and terms of use. Data products provide the semantic context AI needs to understand not just what data exists, but what it means and how to use it correctly. We use Data Mesh Manager as a data product marketplace to search for available data products and evaluate if these are relevant for the task by analyzing its metadata.
Once a data product is identified, data governance plays a crucial role in ensuring that access to data products is controlled, queries are in line with the data contract's terms of use, and its compliance with organizational global policies. If necessary, the AI agent can request access to the data product's output port, which may require manual approval from the data product owner.
Finally, the LLM can generate SQL queries based on the data contracts data model descriptions and semantics. The SQL queries are executed, while security guardrails are in place to ensure that no sensitive data is misused and attack vectors (such as prompt injections) are mitigated. The results are returned to the AI agent, which can then use them to answer the
cd52d76fd51cOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add dataproduct_mcp --env BIGQUERY_CREDENTIALS_PATH=${BIGQUERY_CREDENTIALS_PATH} --env DATABRICKS_CLIENT_SECRET=${DATABRICKS_CLIENT_SECRET} --env DATAMESH_MANAGER_API_KEY=${DATAMESH_MANAGER_API_KEY} --env SNOWFLAKE_PASSWORD=${SNOWFLAKE_PASSWORD} -- uvx dataproduct_mcp{
"mcpServers": {
"dataproduct_mcp": {
"command": "uvx",
"args": [
"dataproduct_mcp"
],
"env": {
"BIGQUERY_CREDENTIALS_PATH": "${BIGQUERY_CREDENTIALS_PATH}",
"DATABRICKS_CLIENT_SECRET": "${DATABRICKS_CLIENT_SECRET}",
"DATAMESH_MANAGER_API_KEY": "${DATAMESH_MANAGER_API_KEY}",
"SNOWFLAKE_PASSWORD": "${SNOWFLAKE_PASSWORD}"
}
}
}
}Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
dataproduct_get | read | |
dataproduct_query | read | |
dataproduct_request_access | read | |
dataproduct_search | read |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
<a href="https://github.com/entropy-data/dataproduct-mcp" class="github-corner" aria-label="View source on GitHub"><svg width="80" height="80" viewBox="0 0 250 250" style="fill:#151513; color:#fff; po
Gates applied: no_behavioural_pass.
cd52d76fd51cfull audit observations/trust-audit/mcp-server/entropy-data__data-product.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | cd52d76fd51c | CAUTION | B | 89 | first audit |
Questions
What is the Data Product MCP server?
A Model Context Protocol (MCP) server for discovering data products and requesting access in Data Mesh Manager, and executing queries on the data platform to access business data.
What tools does Data Product expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Data Product safe to connect to an agent?
With care. The audit graded it B (89/100) and found 1 thing worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Data Product need?
It reads BIGQUERY_CREDENTIALS_PATH, DATABRICKS_CLIENT_SECRET, DATAMESH_MANAGER_API_KEY and SNOWFLAKE_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Data Product run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as dataproduct_mcp.
How current is this page?
The grade is for one exact copy of the source (cd52d76fd51c), read on 2026-10-08. The repository is watched and re-audited when it changes.