BigQuerySAFE
A Model Context Protocol (MCP) server that provides secure, read-only access to BigQuery datasets. Enables Large Language Models (LLMs) to safely query and analyze data through a standardized interface.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
What is this? 🤔
This is a server that lets your LLMs (like Claude) talk directly to your BigQuery data — read-only, with no ability to mutate your warehouse. Think of it as a friendly translator that sits between your AI assistant and your database, making sure they can chat securely and efficiently.
Quick Example
You: "What were our top 10 customers last month?" Claude: *queries your BigQuery database and gives you the answer in plain English*
No more writing SQL queries by hand - just chat naturally with your data!
How Does It Work? 🛠️
This server uses the Model Context Protocol (MCP), which is like a universal translator for AI-database communication. MCP is supported by Claude Desktop, Claude Code, and a growing number of other AI clients.
Here's all you need to do:
- Set up authentication (see below)
- Add your project details to your MCP client's config file
- Start chatting with your BigQuery data naturally!
What Can It Do? 📊
- Read-only by design — only
SELECTstatements are allowed. Every query is validated by BigQuery's own dry-run planner before execution, soINSERT,UPDATE,DELETE,DROP,TRUNCATE,EXPORT DATA, andMERGEare all rejected. The AI agent cannot mutate your warehouse, period. - Run SQL queries by just asking questions in plain English
- Access both tables and materialized views in your datasets
- Explore dataset schemas with clear labeling of resource types (tables vs views)
- Analyze data within configurable safe limits (set via
config.jsonor--maximum-bytes-billed) - Protect sensitive data — define field-level access restrictions to prevent AI agents from reading PII, PHI, financial data, and secrets. The agent receives clear guidance on how to reformulate queries using aggregates or
EXCEPTclauses, so it remains useful without
fc8c8cd1eab5OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-bigquery-server -- npx -y @ergut/[email protected]
{
"mcpServers": {
"mcp-bigquery-server": {
"command": "npx",
"args": [
"-y",
"@ergut/[email protected]"
]
}
}
}Exposed tools (1)
0 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
query | write | Run a read-only BigQuery SQL query |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (2)
@google-cloud/bigquery, shx, typescript, vitest
> **Note: Restricted fields in WHERE, ORDER BY, and other clauses are blocked**, not just fields in SELECT. Even though the query results don't contain the restricted column, the full SQL query text i
Gates applied: no_behavioural_pass.
fc8c8cd1eab5full audit observations/trust-audit/mcp-server/ergut__bigquery-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | fc8c8cd1eab5 | SAFE | B | 89 | first audit |
Questions
What is the BigQuery MCP server?
A Model Context Protocol (MCP) server that provides secure, read-only access to BigQuery datasets. Enables Large Language Models (LLMs) to safely query and analyze data through a standardized interface.
What tools does BigQuery expose?
1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is BigQuery safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does BigQuery need?
No credential environment variables were found in its source, so it appears to need none.
How does BigQuery run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @ergut/mcp-bigquery-server at 1.0.4.
How current is this page?
The grade is for one exact copy of the source (fc8c8cd1eab5), read on 2026-10-07. The repository is watched and re-audited when it changes.