GcloudSAFE
gcloud MCP server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/googleapis/gcloud-mcp/actions/workflows/presubmit.yml) [](https://github.com/googleapis/gcloud-mcp/blob/main/LICENSE)
The gcloud Model Context Protocol (MCP) server enables AI assistants to easily interact with the Google Cloud environment using the gcloud CLI. With the gcloud MCP server you can:
- Interact with Google Cloud using natural language. Describe the outcome
you want instead of memorizing complex command syntax, flags, and arguments.
- Automate and simplify complex workflows. Chain multiple cloud operations
into a single, repeatable command to reduce manual effort and the chance of error.
- Lower the barrier to entry for cloud management. Empower team members who
are less familiar with gcloud to perform powerful actions confidently and safely.
📡 Available MCP Servers
This repository also hosts other MCP servers in addition to the gcloud MCP server. An up to date list is below, and links to other Google Cloud MCP servers hosted outside of this repo are here.
b5325e67fe43OBSERVED · 2026-09-26Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add storage-mcp -- npx -y @google-cloud/[email protected]
{
"mcpServers": {
"storage-mcp": {
"command": "npx",
"args": [
"-y",
"@google-cloud/[email protected]"
]
}
}
}Exposed tools (64)
43 read · 15 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
check_iam_permissions | read | |
copy_object | read | |
copy_object_safe | read | |
create_backup_plan | write | |
create_backup_plan_association | write | |
create_backup_vault | write | |
create_bucket | write | |
csql_restore | read | |
delete_backup | destructive | |
delete_backup_plan | destructive | |
delete_backup_plan_association | destructive | |
delete_backup_vault | destructive | |
delete_bucket | destructive | |
delete_object | destructive | |
download_object | read | |
execute_insights_query | write | |
find_protectable_resources | read | |
get_backup | read | |
get_backup_plan | read | |
get_backup_plan_association | read | |
get_backup_vault | read | |
get_backupdr_operation | read | |
get_bucket_location | read | |
get_bucket_metadata | read | |
get_csql_operation | read | |
get_datasource | read | |
get_metadata_table_schema | read | |
get_trace | read | Use this as the primary tool to retrieve a single distributed trace from Google Cloud Trace. Traces provide a detailed view of the path of a request as it travels through your application |
list_alert_policies | read | Use this as the primary tool to list the alerting policies in a Google Cloud project. Alerting policies define the conditions under which you want to be notified about issues with your services. This is useful for understanding what alerts are currently configured. |
list_alerts | read | Use this as the primary tool to list the alerts in a Google Cloud project. An alert is the representation of a violation of an alert policy. This is useful for understanding current and past violations of an alert policy. |
list_backup_plan_associations | read | |
list_backup_plans | read | |
list_backup_vaults | read | |
list_backups | read | |
list_buckets | read | Use this as the primary tool to list the log buckets in a Google Cloud project. Log buckets are containers that store and organize your log data. This tool is useful for understanding how your logs are stored and for managing your logging configurations. |
list_datasources | read | |
list_group_stats | read | |
list_insights_configs | read | |
list_log_entries | read | Use this as the primary tool to search and retrieve log entries from Google Cloud Logging. It |
list_log_names | read | Use this as the primary tool to list the log names in a Google Cloud project. This is useful for discovering what logs are available for a project. Only logs which have log entries will be listed. |
list_log_scopes | read | Use this as the primary tool to list the log scopes in a Google Cloud project. Log scopes allow you to query logs from multiple projects in a single view. This is useful for centralized logging across a large organization. |
list_metric_descriptors | read | Use this as the primary tool to discover the types of metrics available in a Google Cloud project. This is a good first step to understanding what data is available for monitoring and building dashboards or alerts. |
list_objects | read | |
list_resource_backup_configs | read | |
list_sinks | read | |
list_time_series | read | Use this as the primary tool to retrieve metric data over a specific time period. This is the core tool for monitoring and observability, allowing you to get the actual data points for a given metric. |
list_traces | read | Use this as the primary tool to retrieve and examine distributed traces from Google Cloud Trace. Traces provide a detailed view of the path of a request as it travels through your application |
list_views | read | Use this as the primary tool to list the log views in a given log bucket. Log views provide fine-grained access control to the logs in your buckets. This is useful for managing who has access to which logs. |
move_object | write | |
new-vault | read | test vault |
plan-1 | read | updated test plan |
read_object_content | read | |
read_object_metadata | read | |
restore_backup | read | |
run_gcloud_command | write | |
trigger_backup | write | |
update_backup_plan | write | |
update_bucket_labels | write | |
update_object_metadata | write | |
upload_object | write | |
upload_object_safe | write | |
view_iam_policy | read | |
write_object | write | |
write_object_safe | write |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (22)
delete_backup, delete_backup_plan, delete_backup_plan_association, delete_backup_vault, delete_bucket, delete_object
.prettierignore
.prettierrc.json
.release-please-manifest.json
.prettierignore
.prettierignore
import pkg from '../../package.json' with { type: 'json' };import pkg from '../../package.json' with { type: 'json' };import { apiClientFactory } from '../../utility/api_client_factory.js';vi.mock('../../utility/api_client_factory.js');import { apiClientFactory } from '../../utility/api_client_factory.js';'UEsDBAoAAAAAAACp/1MAAAAAAAAAAAAAAAwDAAAAAFRFU1QudHh0VVQJAAMHo35lB6N+ZXV4CwABBPUBAAAEFAAAAE9iamVjdCBjb250ZW50UEsBAh4DCgAAAAAAAKn/UwAAAAAAAAAAAAAAAAwDAAAAAFRFU1QudHh0VVQFAAMHo35ldXgLAAEE9QEAAAQUAAAAUEs
@google-cloud/storage, @tsconfig/strictest, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, @vitest/coverage-v8, esbuild, eslint
@google-cloud/backupdr, @google-cloud/compute, @google-cloud/sql, @modelcontextprotocol/sdk, @types/yargs, process, yargs, zod
@modelcontextprotocol/sdk, @types/yargs, yargs, zod, typescript, typescript-eslint, @tsconfig/strictest, @types/node
@modelcontextprotocol/sdk, google-auth-library, googleapis, @types/yargs, yargs, zod, typescript, typescript-eslint
@google-cloud/bigquery, @google-cloud/service-usage, @google-cloud/storage, @google-cloud/storageinsights, @modelcontextprotocol/sdk, @types/yargs, chardet, google-auth-library
packages/storage-mcp/assets/chained.gif
packages/storage-mcp/assets/easy_access_3x.gif
packages/storage-mcp/assets/natural_language.gif
packages/storage-mcp/assets/storage_insights_aggregation.gif
packages/storage-mcp/assets/storage_insights_demo.mp4
Gates applied: no_behavioural_pass.
b5325e67fe43full audit observations/trust-audit/mcp-server/googleapis__gcloud.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-26 | b5325e67fe43 | SAFE | B | 89 | first audit |
Questions
What is the Gcloud MCP server?
gcloud MCP server
What tools does Gcloud expose?
64 in total: 43 read-only, 15 that write, and 6 that can delete or overwrite (delete_backup, delete_backup_plan, delete_backup_plan_association, delete_backup_vault, delete_bucket). Every one is listed on this page with its risk.
Is Gcloud safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Gcloud need?
No credential environment variables were found in its source, so it appears to need none.
How does Gcloud run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @google-cloud/storage-mcp at 0.6.0.
How current is this page?
The grade is for one exact copy of the source (b5325e67fe43), read on 2026-09-26. The repository is watched and re-audited when it changes.