Atlas / MCP servers / leonardosepulvedat / mcp-google-analytics

mcp-google-analyticsSAFE

mcp/leonardosepulvedat/mcp-google-analytics

GA4 MCP that reads AND writes: reports, funnels, audits, and server-side events (Measurement Protocol). 26 tools.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
26 12r · 14w · 0d
Transport
stdio
License
MIT
Stars
2
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for Google Analytics 4, providing comprehensive integration with both the Google Analytics Data API (for reading reports) and Measurement Protocol v2 (for sending events).

The GA4 MCP that reads AND writes. Most GA4 MCP servers (including Google's official one) are read-only. This one gives your AI agent the full loop: run reports and funnels, audit your setup (custom dimensions, key events, compatibility checks), send ecommerce and conversion events server-side, and verify them in the realtime report — 26 tools in one npx command.

Built for agencies too: every read tool accepts an optional propertyId, so one conversation can query all your clients' properties — no reconfiguration between clients. See Multi-Property Mode.

[](https://www.npmjs.com/package/mcp-google-analytics) [](https://www.npmjs.com/package/mcp-google-analytics) [](https://github.com/leonardosepulvedat/mcp-google-analytics/actions/workflows/ci.yml) [](https://opensource.org/licenses/MIT) [](https://smithery.ai/servers/lsepulvedatabares/mcp-google-analytics)

⚡ One-Click Install

You only need two values to start (same as any other GA4 MCP): the service account JSON and your property ID. Sending events is an optional extra.

[](cursor://anysphere.cursor-deeplink/mcp/install?name=google-analytics&config=eyJjb21tYW5kIjoibnB4IiwiYXJncyI6WyIteSIsIm1jcC1nb29nbGUtYW5hbHl0aWNzIl0sImVudiI6eyJHQV9TRVJWSUNFX0FDQ09VTlRfSlNPTiI6Ii

Read from source at commit 9e3cb0c12327OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-google-analytics --env GA_SERVICE_ACCOUNT_JSON=${GA_SERVICE_ACCOUNT_JSON} --env GA_API_SECRET=${GA_API_SECRET} -- npx -y [email protected]
03

Exposed tools (26)

12 read · 14 write · 0 destructive.

ToolRiskDescription
ga_batch_run_reportswrite
ga_check_compatibilityread
ga_get_account_summariesread
ga_get_metadataread
ga_get_propertyread
ga_list_accountsread
ga_list_custom_dimensionsread
ga_list_custom_metricsread
ga_list_data_streamsread
ga_list_google_ads_linksread
ga_list_key_eventsread
ga_list_propertiesread
ga_run_funnel_reportwrite
ga_run_pivot_reportwrite
ga_run_realtime_reportwrite
ga_run_reportwrite
ga_send_add_to_cartwrite
ga_send_begin_checkoutwrite
ga_send_eventwrite
ga_send_loginwrite
ga_send_pageviewwrite
ga_send_purchasewrite
ga_send_refundwrite
ga_send_signupwrite
ga_send_view_itemwrite
ga_validate_eventread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, google-auth-library, zod, @types/node, typescript, vitest
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:41
- Documentation only: added an at-a-glance table of all 18 tools, five new Measurement Protocol usage examples (validation, server-side conversions, ecommerce funnel with shared `client_id`, custom au
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 9e3cb0c12327full audit observations/trust-audit/mcp-server/leonardosepulvedat__mcp-google-analytics.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-079e3cb0c12327SAFEB89first audit
06

Questions

What is the mcp-google-analytics MCP server?

GA4 MCP that reads AND writes: reports, funnels, audits, and server-side events (Measurement Protocol). 26 tools.

What tools does mcp-google-analytics expose?

26 in total: 12 read-only, 14 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is mcp-google-analytics safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does mcp-google-analytics need?

It reads GA_API_SECRET and GA_SERVICE_ACCOUNT_JSON from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does mcp-google-analytics run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-google-analytics at 1.3.1.

How current is this page?

The grade is for one exact copy of the source (9e3cb0c12327), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement