Atlas / MCP servers / krzko / Google Cloud

Google CloudSAFE

mcp/krzko/google-cloud

🤖 A Model Context Protocol (MCP) server for Google Cloud (GCP)

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
40 38r · 2w · 0d
Transport
stdio
License
Apache-2.0
Stars
80
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol server that connects to Google Cloud services to provide context and tools for interacting with your Google Cloud resources.

Services

Supported Google Cloud services:

Billing

Manage and analyse Google Cloud billing with cost optimisation insights:

Tools: gcp-billing-list-accounts, gcp-billing-get-account-details, gcp-billing-list-projects, gcp-billing-get-project-info, gcp-billing-list-services, gcp-billing-list-skus, gcp-billing-analyse-costs, gcp-billing-detect-anomalies, gcp-billing-cost-recommendations, gcp-billing-service-breakdown

Example prompts:

  • "Show me all my billing accounts"
  • "Analyse costs for project my-app-prod-123 for the last 30 days"
  • "Generate cost recommendations for billing account billingAccounts/123456-789ABC-DEF012"
  • "Check for billing anomalies in project my-ecommerce-456"

Error Reporting

Monitor and analyse application errors with automated investigation and remediation suggestions:

Tools: gcp-error-reporting-list-groups, gcp-error-reporting-get-group-details, gcp-error-reporting-analyse-trends

Example prompts:

  • "Show me error groups from project my-webapp-prod-789 for the last hour"
  • "Get details for error group projects/my-app-123/groups/xyz789"
  • "Analyse error trends for service m
Read from source at commit 362905660ef8OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add google-cloud-mcp --env GOOGLE_APPLICATION_CREDENTIALS=${GOOGLE_APPLICATION_CREDENTIALS} --env GOOGLE_PRIVATE_KEY=${GOOGLE_PRIVATE_KEY} --env LAZY_AUTH=${LAZY_AUTH} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "google-cloud-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "GOOGLE_APPLICATION_CREDENTIALS": "${GOOGLE_APPLICATION_CREDENTIALS}",
        "GOOGLE_PRIVATE_KEY": "${GOOGLE_PRIVATE_KEY}",
        "LAZY_AUTH": "${LAZY_AUTH}"
      }
    }
  }
}
03

Exposed tools (40)

38 read · 2 write · 0 destructive.

ToolRiskDescription
gcp-billing-analyse-costsread
gcp-billing-cost-recommendationsread
gcp-billing-detect-anomaliesread
gcp-billing-get-account-detailsread
gcp-billing-get-project-inforead
gcp-billing-list-accountsread
gcp-billing-list-projectsread
gcp-billing-list-servicesread
gcp-billing-list-skusread
gcp-billing-service-breakdownread
gcp-error-reporting-analyse-trendsread
gcp-error-reporting-get-group-detailsread
gcp-error-reporting-list-groupsread
gcp-iam-analyse-permission-gapsread
gcp-iam-get-project-policyread
gcp-iam-list-deployment-servicesread
gcp-iam-test-project-permissionsread
gcp-iam-test-resource-permissionsread
gcp-iam-validate-deployment-permissionsread
gcp-logging-query-logsread
gcp-logging-query-time-rangeread
gcp-logging-search-comprehensiveread
gcp-monitoring-list-metric-typesread
gcp-monitoring-query-metricsread
gcp-monitoring-query-natural-languageread
gcp-profiler-analyse-performanceread
gcp-profiler-compare-trendsread
gcp-profiler-list-profilesread
gcp-spanner-execute-querywrite
gcp-spanner-list-databasesread
gcp-spanner-list-instancesread
gcp-spanner-list-tablesread
gcp-spanner-query-countread
gcp-spanner-query-natural-languageread
gcp-trace-find-from-logsread
gcp-trace-get-traceread
gcp-trace-list-tracesread
gcp-trace-query-natural-languageread
gcp-utils-get-project-idread
gcp-utils-set-project-idwrite
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (15)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/billing/resources.ts:8
import { getProjectId } from "../../utils/auth.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/billing/resources.ts:9
import { stateManager } from "../../utils/state-manager.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/billing/resources.ts:10
import { GcpMcpError } from "../../utils/error.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/billing/resources.ts:11
import { logger } from "../../utils/logger.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/services/billing/tools.ts:6
import { getProjectId } from "../../utils/auth.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@google-cloud/billing, @google-cloud/iam, @google-cloud/logging, @google-cloud/monitoring, @google-cloud/resource-manager, @google-cloud/spanner, @google-cloud/trace-agent, @modelcontextprotocol/sdk
Why it matters. 24 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
llms-full.txt:1660
* **Streamable HTTP transport**: Uses HTTP POST for client-to-server messages with optional Server-Sent Events for streaming capabilities. This transport enables remote server communication and suppor
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
llms-full.txt:7315
MCP clients **MUST NOT** send tokens to the MCP server other than ones issued by the MCP server's authorization server.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
llms-full.txt:8269
Client->>+Server: POST InitializedNotification<br>Mcp-Session-Id: 1868a90c...
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
llms-full.txt:8273
Client->>+Server: POST ... request ...<br>Mcp-Session-Id: 1868a90c...
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
llms-full.txt:8286
Client->>+Server: POST ... notification/response ...<br>Mcp-Session-Id: 1868a90c...
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
src/services/monitoring/metrics_gcp.md
src/services/monitoring/metrics_gcp.md
Why it matters. 2087404 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
llms-full.txt:3186
load_dotenv()  # load environment variables from .env
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
llms-full.txt:4564
This creates the beginnings of a .NET console application that can read the API key from user secrets.
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
llms-full.txt:4814
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 362905660ef8full audit observations/trust-audit/mcp-server/krzko__google-cloud.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07362905660ef8SAFEB89first audit
06

Questions

What is the Google Cloud MCP server?

🤖 A Model Context Protocol (MCP) server for Google Cloud (GCP)

What tools does Google Cloud expose?

40 in total: 38 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Google Cloud safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Google Cloud need?

It reads GOOGLE_APPLICATION_CREDENTIALS, GOOGLE_PRIVATE_KEY and LAZY_AUTH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Google Cloud run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as google-cloud-mcp at 0.5.0.

How current is this page?

The grade is for one exact copy of the source (362905660ef8), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement