Atlas / MCP servers / googlecloudplatform / Cloud Run

Cloud RunBLOCK

mcp/googlecloudplatform/cloud-run

MCP server to deploy apps to Cloud Run

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
8 4r · 4w · 0d
Transport
sse · stdio · streamable-http
License
Apache-2.0
Stars
631
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Enable MCP-compatible AI agents to deploy apps to Cloud Run.

"mcpServers":{
"cloud-run": {
"command": "npx",
"args": ["-y", "@google-cloud/cloud-run-mcp"]
}
}

Deploy from Gemini CLI and other AI-powered CLI agents:

Deploy from AI-powered IDEs:

Deploy from AI assistant apps:

Deploy from agent SDKs, like the Google Gen AI SDK or Agent Development Kit.

[!NOTE] This is the repository of an MCP server to deploy code to Cloud Run, to learn how to host MCP servers on Cloud Run, visit the Cloud Run documentation.

Tools

  • deploy-file-contents: Deploys files to Cloud Run by providing their contents directly.
  • list-services: Lists Cloud Run services in a given project and region.
  • get-service: Gets details for a specific Cloud Run service.
  • get-service-log: Gets Logs and Error Messages for a specific Cloud Run service.
  • deploy-local-folder\*: Deploys a local folder to a Google Cloud Run service.
  • list-projects\*: Lists available GCP projects.
  • create-project\*: Creates a new GCP project and attach it to the first available billing account. A project ID can be optionally specified.

\* only available when running locally

Prompts

Prompts are natural language commands that can be used to perform common tasks. They are shortcuts for

Read from source at commit d176842d5d36OBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add cloud-run-mcp --env GOOGLE_OAUTH_AUDIENCE=${GOOGLE_OAUTH_AUDIENCE} --env GOOGLE_OAUTH_CLIENT_ID=${GOOGLE_OAUTH_CLIENT_ID} --env GOOGLE_OAUTH_CLIENT_SECRET=${GOOGLE_OAUTH_CLIENT_SECRET} --env GOOGLE_OAUTH_REDIRECT_URI=${GOOGLE_OAUTH_REDIRECT_URI} -- npx -y @google-cloud/[email protected]
claude-desktop
{
  "mcpServers": {
    "cloud-run-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@google-cloud/[email protected]"
      ],
      "env": {
        "GOOGLE_OAUTH_AUDIENCE": "${GOOGLE_OAUTH_AUDIENCE}",
        "GOOGLE_OAUTH_CLIENT_ID": "${GOOGLE_OAUTH_CLIENT_ID}",
        "GOOGLE_OAUTH_CLIENT_SECRET": "${GOOGLE_OAUTH_CLIENT_SECRET}",
        "GOOGLE_OAUTH_REDIRECT_URI": "${GOOGLE_OAUTH_REDIRECT_URI}"
      }
    }
  }
}
03

Exposed tools (8)

4 read · 4 write · 0 destructive.

ToolRiskDescription
create_projectwrite
deploy_container_imagewrite
deploy_file_contentswrite
deploy_local_folderwrite
get_serviceread
get_service_logread
list_projectsread
list_servicesread
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (3 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (18)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
lib/deployment/deployer.js:819
const serviceConfig = yaml.load(
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
lib/cloud-api/metadata.js:26
const response = await fetch(`http://metadata.google.internal${path}`, {
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWInventory / provenance · inv.hidden_file · CWE-1104
.c8rc.json
.c8rc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.gcloud-sdk-oauth
.env.gcloud-sdk-oauth
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/local/archive.test.js:22
import { zipFiles } from '../../lib/util/archive.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/local/clients.test.js:10
} from '../../lib/clients.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/local/clients.test.js:11
import { GCLOUD_AUTH } from '../../constants.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/local/cloud-api/build.test.js:101
return await esmock('../../../lib/cloud-api/build.js', {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/local/cloud-api/build.test.js:102
'../../../lib/cloud-api/helpers.js': {
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
example-sources-to-deploy/nodejs/package.json
express
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
example-sources-to-deploy/python/pip-project/requirements.txt
Flask, gunicorn
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@dotenvx/dotenvx, @google-cloud/artifact-registry, @google-cloud/billing, @google-cloud/cloudbuild, @google-cloud/logging, @google-cloud/resource-manager, @google-cloud/run, @google-cloud/secret-manag
Why it matters. 20 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
README.md:66
To install this as a [Gemini CLI](https://github.com/google-gemini/gemini-cli) extension, run the following command:
Why it matters. remote text is to be obeyed as instructions
INFOInventory / provenance · inv.oversize · CWE-1104
.github/images/deploy_from_apps.gif
.github/images/deploy_from_apps.gif
Why it matters. 8439298 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
.github/images/deploy_from_ide.gif
.github/images/deploy_from_ide.gif
Why it matters. 4004371 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
.github/images/deploycli.gif
.github/images/deploycli.gif
Why it matters. 2420206 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha d176842d5d36full audit observations/trust-audit/mcp-server/googlecloudplatform__cloud-run.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-28d176842d5d36BLOCKD69first audit
06

Questions

What is the Cloud Run MCP server?

MCP server to deploy apps to Cloud Run

What tools does Cloud Run expose?

8 in total: 4 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Cloud Run safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Cloud Run need?

It reads GOOGLE_OAUTH_AUDIENCE, GOOGLE_OAUTH_CLIENT_ID, GOOGLE_OAUTH_CLIENT_SECRET, GOOGLE_OAUTH_REDIRECT_URI, OAUTH_AUTHORIZATION_ENDPOINT, OAUTH_AUTHORIZATION_SERVER, OAUTH_ENABLED, OAUTH_PROTECTED_RESOURCE and OAUTH_TOKEN_ENDPOINT from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Cloud Run run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @google-cloud/cloud-run-mcp at 1.10.0.

How current is this page?

The grade is for one exact copy of the source (d176842d5d36), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement