Atlas / MCP servers / ergut / BigQuery

BigQuerySAFE

mcp/ergut/bigquery-1

A Model Context Protocol (MCP) server that provides secure, read-only access to BigQuery datasets. Enables Large Language Models (LLMs) to safely query and analyze data through a standardized interface.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
1 0r · 1w · 0d
Transport
stdio
License
MIT
Stars
148
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

What is this? 🤔

This is a server that lets your LLMs (like Claude) talk directly to your BigQuery data — read-only, with no ability to mutate your warehouse. Think of it as a friendly translator that sits between your AI assistant and your database, making sure they can chat securely and efficiently.

Quick Example

You: "What were our top 10 customers last month?"
Claude: *queries your BigQuery database and gives you the answer in plain English*

No more writing SQL queries by hand - just chat naturally with your data!

How Does It Work? 🛠️

This server uses the Model Context Protocol (MCP), which is like a universal translator for AI-database communication. MCP is supported by Claude Desktop, Claude Code, and a growing number of other AI clients.

Here's all you need to do:

  1. Set up authentication (see below)
  2. Add your project details to your MCP client's config file
  3. Start chatting with your BigQuery data naturally!

What Can It Do? 📊

  • Read-only by design — only SELECT statements are allowed. Every query is validated by BigQuery's own dry-run planner before execution, so INSERT, UPDATE, DELETE, DROP, TRUNCATE, EXPORT DATA, and MERGE are all rejected. The AI agent cannot mutate your warehouse, period.
  • Run SQL queries by just asking questions in plain English
  • Access both tables and materialized views in your datasets
  • Explore dataset schemas with clear labeling of resource types (tables vs views)
  • Analyze data within configurable safe limits (set via config.json or --maximum-bytes-billed)
  • Protect sensitive data — define field-level access restrictions to prevent AI agents from reading PII, PHI, financial data, and secrets. The agent receives clear guidance on how to reformulate queries using aggregates or EXCEPT clauses, so it remains useful without
Read from source at commit fc8c8cd1eab5OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-bigquery-server -- npx -y @ergut/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-bigquery-server": {
      "command": "npx",
      "args": [
        "-y",
        "@ergut/[email protected]"
      ]
    }
  }
}
03

Exposed tools (1)

0 read · 1 write · 0 destructive.

ToolRiskDescription
querywriteRun a read-only BigQuery SQL query
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@google-cloud/bigquery, shx, typescript, vitest
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
PROTECTION.md:121
> **Note: Restricted fields in WHERE, ORDER BY, and other clauses are blocked**, not just fields in SELECT. Even though the query results don't contain the restricted column, the full SQL query text i
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha fc8c8cd1eab5full audit observations/trust-audit/mcp-server/ergut__bigquery-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07fc8c8cd1eab5SAFEB89first audit
06

Questions

What is the BigQuery MCP server?

A Model Context Protocol (MCP) server that provides secure, read-only access to BigQuery datasets. Enables Large Language Models (LLMs) to safely query and analyze data through a standardized interface.

What tools does BigQuery expose?

1 in total: 0 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is BigQuery safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does BigQuery need?

No credential environment variables were found in its source, so it appears to need none.

How does BigQuery run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @ergut/mcp-bigquery-server at 1.0.4.

How current is this page?

The grade is for one exact copy of the source (fc8c8cd1eab5), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement