Atlas / MCP servers / googleapis / Gcloud

GcloudSAFE

mcp/googleapis/gcloud

gcloud MCP server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
64 43r · 15w · 6d
Transport
stdio
License
Apache-2.0
Stars
914
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/googleapis/gcloud-mcp/actions/workflows/presubmit.yml) [](https://github.com/googleapis/gcloud-mcp/blob/main/LICENSE)

The gcloud Model Context Protocol (MCP) server enables AI assistants to easily interact with the Google Cloud environment using the gcloud CLI. With the gcloud MCP server you can:

  • Interact with Google Cloud using natural language. Describe the outcome

you want instead of memorizing complex command syntax, flags, and arguments.

  • Automate and simplify complex workflows. Chain multiple cloud operations

into a single, repeatable command to reduce manual effort and the chance of error.

  • Lower the barrier to entry for cloud management. Empower team members who

are less familiar with gcloud to perform powerful actions confidently and safely.

📡 Available MCP Servers

This repository also hosts other MCP servers in addition to the gcloud MCP server. An up to date list is below, and links to other Google Cloud MCP servers hosted outside of this repo are here.

Read from source at commit b5325e67fe43OBSERVED · 2026-09-26
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add storage-mcp -- npx -y @google-cloud/[email protected]
claude-desktop
{
  "mcpServers": {
    "storage-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@google-cloud/[email protected]"
      ]
    }
  }
}
03

Exposed tools (64)

43 read · 15 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
check_iam_permissionsread
copy_objectread
copy_object_saferead
create_backup_planwrite
create_backup_plan_associationwrite
create_backup_vaultwrite
create_bucketwrite
csql_restoreread
delete_backupdestructive
delete_backup_plandestructive
delete_backup_plan_associationdestructive
delete_backup_vaultdestructive
delete_bucketdestructive
delete_objectdestructive
download_objectread
execute_insights_querywrite
find_protectable_resourcesread
get_backupread
get_backup_planread
get_backup_plan_associationread
get_backup_vaultread
get_backupdr_operationread
get_bucket_locationread
get_bucket_metadataread
get_csql_operationread
get_datasourceread
get_metadata_table_schemaread
get_tracereadUse this as the primary tool to retrieve a single distributed trace from Google Cloud Trace. Traces provide a detailed view of the path of a request as it travels through your application
list_alert_policiesreadUse this as the primary tool to list the alerting policies in a Google Cloud project. Alerting policies define the conditions under which you want to be notified about issues with your services. This is useful for understanding what alerts are currently configured.
list_alertsreadUse this as the primary tool to list the alerts in a Google Cloud project. An alert is the representation of a violation of an alert policy. This is useful for understanding current and past violations of an alert policy.
list_backup_plan_associationsread
list_backup_plansread
list_backup_vaultsread
list_backupsread
list_bucketsreadUse this as the primary tool to list the log buckets in a Google Cloud project. Log buckets are containers that store and organize your log data. This tool is useful for understanding how your logs are stored and for managing your logging configurations.
list_datasourcesread
list_group_statsread
list_insights_configsread
list_log_entriesreadUse this as the primary tool to search and retrieve log entries from Google Cloud Logging. It
list_log_namesreadUse this as the primary tool to list the log names in a Google Cloud project. This is useful for discovering what logs are available for a project. Only logs which have log entries will be listed.
list_log_scopesreadUse this as the primary tool to list the log scopes in a Google Cloud project. Log scopes allow you to query logs from multiple projects in a single view. This is useful for centralized logging across a large organization.
list_metric_descriptorsreadUse this as the primary tool to discover the types of metrics available in a Google Cloud project. This is a good first step to understanding what data is available for monitoring and building dashboards or alerts.
list_objectsread
list_resource_backup_configsread
list_sinksread
list_time_seriesreadUse this as the primary tool to retrieve metric data over a specific time period. This is the core tool for monitoring and observability, allowing you to get the actual data points for a given metric.
list_tracesreadUse this as the primary tool to retrieve and examine distributed traces from Google Cloud Trace. Traces provide a detailed view of the path of a request as it travels through your application
list_viewsreadUse this as the primary tool to list the log views in a given log bucket. Log views provide fine-grained access control to the logs in your buckets. This is useful for managing who has access to which logs.
move_objectwrite
new-vaultreadtest vault
plan-1readupdated test plan
read_object_contentread
read_object_metadataread
restore_backupread
run_gcloud_commandwrite
trigger_backupwrite
update_backup_planwrite
update_bucket_labelswrite
update_object_metadatawrite
upload_objectwrite
upload_object_safewrite
view_iam_policyread
write_objectwrite
write_object_safewrite
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (22)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_backup, delete_backup_plan, delete_backup_plan_association, delete_backup_vault, delete_bucket, delete_object
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
packages/backupdr-mcp/.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
packages/storage-mcp/.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/backupdr-mcp/src/commands/init-gemini-cli.test.ts:20
import pkg from '../../package.json' with { type: 'json' };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/backupdr-mcp/src/commands/init-gemini-cli.ts:19
import pkg from '../../package.json' with { type: 'json' };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/backupdr-mcp/src/tools/backup_plan_associations/create_backup_plan_association.test.ts:23
import { apiClientFactory } from '../../utility/api_client_factory.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/backupdr-mcp/src/tools/backup_plan_associations/create_backup_plan_association.test.ts:26
vi.mock('../../utility/api_client_factory.js');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/backupdr-mcp/src/tools/backup_plan_associations/create_backup_plan_association.ts:20
import { apiClientFactory } from '../../utility/api_client_factory.js';
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
packages/storage-mcp/tests/integration/gcs-mime-type.test.ts:80
'UEsDBAoAAAAAAACp/1MAAAAAAAAAAAAAAAwDAAAAAFRFU1QudHh0VVQJAAMHo35lB6N+ZXV4CwABBPUBAAAEFAAAAE9iamVjdCBjb250ZW50UEsBAh4DCgAAAAAAAKn/UwAAAAAAAAAAAAAAAAwDAAAAAFRFU1QudHh0VVQFAAMHo35ldXgLAAEE9QEAAAQUAAAAUEs
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@google-cloud/storage, @tsconfig/strictest, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, @vitest/coverage-v8, esbuild, eslint
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/backupdr-mcp/package.json
@google-cloud/backupdr, @google-cloud/compute, @google-cloud/sql, @modelcontextprotocol/sdk, @types/yargs, process, yargs, zod
Why it matters. 26 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/gcloud-mcp/package.json
@modelcontextprotocol/sdk, @types/yargs, yargs, zod, typescript, typescript-eslint, @tsconfig/strictest, @types/node
Why it matters. 20 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/observability-mcp/package.json
@modelcontextprotocol/sdk, google-auth-library, googleapis, @types/yargs, yargs, zod, typescript, typescript-eslint
Why it matters. 24 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/storage-mcp/package.json
@google-cloud/bigquery, @google-cloud/service-usage, @google-cloud/storage, @google-cloud/storageinsights, @modelcontextprotocol/sdk, @types/yargs, chardet, google-auth-library
Why it matters. 30 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
packages/storage-mcp/assets/chained.gif
packages/storage-mcp/assets/chained.gif
Why it matters. 9578608 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
packages/storage-mcp/assets/easy_access_3x.gif
packages/storage-mcp/assets/easy_access_3x.gif
Why it matters. 13346779 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
packages/storage-mcp/assets/natural_language.gif
packages/storage-mcp/assets/natural_language.gif
Why it matters. 14413030 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
packages/storage-mcp/assets/storage_insights_aggregation.gif
packages/storage-mcp/assets/storage_insights_aggregation.gif
Why it matters. 1205194 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
packages/storage-mcp/assets/storage_insights_demo.mp4
packages/storage-mcp/assets/storage_insights_demo.mp4
Why it matters. 7955547 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-26 · audit v0.4.1 · source sha b5325e67fe43full audit observations/trust-audit/mcp-server/googleapis__gcloud.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-26b5325e67fe43SAFEB89first audit
06

Questions

What is the Gcloud MCP server?

gcloud MCP server

What tools does Gcloud expose?

64 in total: 43 read-only, 15 that write, and 6 that can delete or overwrite (delete_backup, delete_backup_plan, delete_backup_plan_association, delete_backup_vault, delete_bucket). Every one is listed on this page with its risk.

Is Gcloud safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Gcloud need?

No credential environment variables were found in its source, so it appears to need none.

How does Gcloud run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @google-cloud/storage-mcp at 0.6.0.

How current is this page?

The grade is for one exact copy of the source (b5325e67fe43), read on 2026-09-26. The repository is watched and re-audited when it changes.

Advertisement