Cloud RunBLOCK
MCP server to deploy apps to Cloud Run
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Enable MCP-compatible AI agents to deploy apps to Cloud Run.
"mcpServers":{
"cloud-run": {
"command": "npx",
"args": ["-y", "@google-cloud/cloud-run-mcp"]
}
}Deploy from Gemini CLI and other AI-powered CLI agents:
Deploy from AI-powered IDEs:
Deploy from AI assistant apps:
Deploy from agent SDKs, like the Google Gen AI SDK or Agent Development Kit.
[!NOTE] This is the repository of an MCP server to deploy code to Cloud Run, to learn how to host MCP servers on Cloud Run, visit the Cloud Run documentation.
Tools
deploy-file-contents: Deploys files to Cloud Run by providing their contents directly.list-services: Lists Cloud Run services in a given project and region.get-service: Gets details for a specific Cloud Run service.get-service-log: Gets Logs and Error Messages for a specific Cloud Run service.
deploy-local-folder\*: Deploys a local folder to a Google Cloud Run service.list-projects\*: Lists available GCP projects.create-project\*: Creates a new GCP project and attach it to the first available billing account. A project ID can be optionally specified.
\* only available when running locally
Prompts
Prompts are natural language commands that can be used to perform common tasks. They are shortcuts for
d176842d5d36OBSERVED · 2026-09-28Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add cloud-run-mcp --env GOOGLE_OAUTH_AUDIENCE=${GOOGLE_OAUTH_AUDIENCE} --env GOOGLE_OAUTH_CLIENT_ID=${GOOGLE_OAUTH_CLIENT_ID} --env GOOGLE_OAUTH_CLIENT_SECRET=${GOOGLE_OAUTH_CLIENT_SECRET} --env GOOGLE_OAUTH_REDIRECT_URI=${GOOGLE_OAUTH_REDIRECT_URI} -- npx -y @google-cloud/[email protected]{
"mcpServers": {
"cloud-run-mcp": {
"command": "npx",
"args": [
"-y",
"@google-cloud/[email protected]"
],
"env": {
"GOOGLE_OAUTH_AUDIENCE": "${GOOGLE_OAUTH_AUDIENCE}",
"GOOGLE_OAUTH_CLIENT_ID": "${GOOGLE_OAUTH_CLIENT_ID}",
"GOOGLE_OAUTH_CLIENT_SECRET": "${GOOGLE_OAUTH_CLIENT_SECRET}",
"GOOGLE_OAUTH_REDIRECT_URI": "${GOOGLE_OAUTH_REDIRECT_URI}"
}
}
}
}Exposed tools (8)
4 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
create_project | write | |
deploy_container_image | write | |
deploy_file_contents | write | |
deploy_local_folder | write | |
get_service | read | |
get_service_log | read | |
list_projects | read | |
list_services | read |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (18)
const serviceConfig = yaml.load(
const response = await fetch(`http://metadata.google.internal${path}`, {.c8rc.json
.env.gcloud-sdk-oauth
.prettierignore
.prettierrc.json
import { zipFiles } from '../../lib/util/archive.js';} from '../../lib/clients.js';
import { GCLOUD_AUTH } from '../../constants.js';return await esmock('../../../lib/cloud-api/build.js', {'../../../lib/cloud-api/helpers.js': {express
Flask, gunicorn
@dotenvx/dotenvx, @google-cloud/artifact-registry, @google-cloud/billing, @google-cloud/cloudbuild, @google-cloud/logging, @google-cloud/resource-manager, @google-cloud/run, @google-cloud/secret-manag
To install this as a [Gemini CLI](https://github.com/google-gemini/gemini-cli) extension, run the following command:
.github/images/deploy_from_apps.gif
.github/images/deploy_from_ide.gif
.github/images/deploycli.gif
Gates applied: no_behavioural_pass.
d176842d5d36full audit observations/trust-audit/mcp-server/googlecloudplatform__cloud-run.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | d176842d5d36 | BLOCK | D | 69 | first audit |
Questions
What is the Cloud Run MCP server?
MCP server to deploy apps to Cloud Run
What tools does Cloud Run expose?
8 in total: 4 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Cloud Run safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Cloud Run need?
It reads GOOGLE_OAUTH_AUDIENCE, GOOGLE_OAUTH_CLIENT_ID, GOOGLE_OAUTH_CLIENT_SECRET, GOOGLE_OAUTH_REDIRECT_URI, OAUTH_AUTHORIZATION_ENDPOINT, OAUTH_AUTHORIZATION_SERVER, OAUTH_ENABLED, OAUTH_PROTECTED_RESOURCE and OAUTH_TOKEN_ENDPOINT from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Cloud Run run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @google-cloud/cloud-run-mcp at 1.10.0.
How current is this page?
The grade is for one exact copy of the source (d176842d5d36), read on 2026-09-28. The repository is watched and re-audited when it changes.