Atlas / MCP servers / idanfishman / Prometheus

PrometheusSAFE

mcp/idanfishman/prometheus-5

A Model Context Protocol (MCP) server implementation that provides AI agents with programmatic access to Prometheus metrics via a unified interface.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
10 8r · 2w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
27
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Prometheus MCP Server

[](https://www.npmjs.com/package/prometheus-mcp) [](https://github.com/idanfishman/prometheus-mcp/pkgs/container/prometheus-mcp) [](https://codecov.io/gh/idanfishman/prometheus-mcp) [](https://nodejs.org/) [](https://opensource.org/licenses/MIT)

A Model Context Protocol (MCP) server that provides seamless integration between AI assistants and Prometheus, enabling natural language interactions with your monitoring infrastructure. This server allows for effortless querying, discovery, and analysis of metrics through Visual Studio Code, Cursor, Windsurf, Claude Desktop, and other MCP clients.

Key Features

  • Fast and lightweight. Direct API integration with Prometheus, no complex parsing needed.
  • LLM-friendly. Structured JSON responses optimized for AI assistant consumption.
  • Configurable capabilities. Enable/disable tool categories based on your security and operational requirements.
  • Dual transport support. Works with both stdio and HTTP transports for maximum compatibility.

Requirements

  • Node.js 20.19.0 or newer
  • Access to a Prometheus server
  • VS Code, Cursor, Windsurf, Claude Desktop or any other MCP client

Getting Started

First, install the Prometheus MCP server with your client. A typical configuration looks like this:

Read from source at commit 6913cb0d7bdeOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add prometheus-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "prometheus-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (10)

8 read · 2 write · 0 destructive.

ToolRiskDescription
prometheus_build_inforeadGet Prometheus build information
prometheus_label_valuesreadGet available values for a specific label
prometheus_list_labelsreadList all available Prometheus labels
prometheus_list_metricsreadList all available Prometheus metrics
prometheus_list_targetsreadList all available Prometheus targets
prometheus_metric_metadatareadGet metadata for a specific Prometheus metric
prometheus_querywriteExecute PromQL queries against Prometheus
prometheus_query_rangewriteExecute PromQL range queries for time-series data
prometheus_runtime_inforeadGet Prometheus runtime information
prometheus_scrape_pool_targetsreadGet targets for a specific scrape pool
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cmd/cmd.ts:7
import packageJSON from "../../package.json";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/server/server.test.ts:19
vi.mock("../../package.json", () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/server/server.ts:6
import packageJSON from "../../package.json";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, express, pino, yargs, zod, @eslint/js, @tsconfig/recommended
Why it matters. 23 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
examples/dba/prompts/weekly-newsletter-generator.md:9
You are a senior PostgreSQL DBA creating executive-level reporting for technical leadership. Your audience includes database administrators, application developers, infrastructure teams, and technical

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 6913cb0d7bdefull audit observations/trust-audit/mcp-server/idanfishman__prometheus-5.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-086913cb0d7bdeSAFEB89first audit
06

Questions

What is the Prometheus MCP server?

A Model Context Protocol (MCP) server implementation that provides AI agents with programmatic access to Prometheus metrics via a unified interface.

What tools does Prometheus expose?

10 in total: 8 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Prometheus safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Prometheus need?

No credential environment variables were found in its source, so it appears to need none.

How does Prometheus run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as prometheus-mcp at 1.1.3.

How current is this page?

The grade is for one exact copy of the source (6913cb0d7bde), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement