Atlas / MCP servers / malloydata / publisher

publisherBLOCK

mcp/malloydata/publisher

Publisher is the open-source analytics engine for Malloy. It lets you define data models once — and use them everywhere.

Verdict
BLOCK
Grade
F
Trust score
37 /100
Exposed tools
14 14r · 0w · 0d
Transport
streamable-http
License
MIT
Stars
111
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Malloy Publisher

The Analytics Engine for Malloy

A post modern data stack — built for the AI era. One data model, served over MCP and REST to AI agents, applications, and BI tools.

Created and maintained by Credible, the company behind the AI Analytics Engine.

AI agents: read AGENTS.md first (raw: https://raw.githubusercontent.com/malloydata/publisher/main/AGENTS.md). It covers starting the server, connecting over MCP, the bundled skills, and the package format. Fetch the raw file, not a summary of this page.

A 60-second walkthrough — model in your IDE with the Malloy skills, serve with Publisher, build a data app, materialize on a schedule, and analyze. Watch the video for playback controls.

Modeling, a query engine, materialization, access control, and an API — the pieces you used to assemble from five projects — ship as one server, built assuming the first builder or consumer is an agent.

Write down what your data means, in Malloy: the sources, the joins, the measures, who may see what. The open-source Malloy skills ship

Read from source at commit 4ab820396e64OBSERVED · 2026-09-24
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add skills --env API_KEY=${API_KEY} --env BIGQUERY_PUBLIC_DATA_CREDENTIALS=${BIGQUERY_PUBLIC_DATA_CREDENTIALS} --env EMBEDDING_API_KEY=${EMBEDDING_API_KEY} --env GCS_TEST_KEY_ID=${GCS_TEST_KEY_ID} -- npx -y @malloy-publisher/[email protected]
claude-desktop
{
  "mcpServers": {
    "skills": {
      "command": "npx",
      "args": [
        "-y",
        "@malloy-publisher/[email protected]"
      ],
      "env": {
        "API_KEY": "${API_KEY}",
        "BIGQUERY_PUBLIC_DATA_CREDENTIALS": "${BIGQUERY_PUBLIC_DATA_CREDENTIALS}",
        "EMBEDDING_API_KEY": "${EMBEDDING_API_KEY}",
        "GCS_TEST_KEY_ID": "${GCS_TEST_KEY_ID}"
      }
    }
  }
}
03

Exposed tools (14)

14 read · 0 write · 0 destructive.

ToolRiskDescription
LocalreadStored in this browser only
by_categoryreadRevenue by product category
controlread
control2reada — b
ecommercereadEcommerce demo
ordersreadkeep me
pkgreadtest
pkg-1readUpdated description
sales_by_statereadRevenue by state
spotifyreadmusic
test-packagereadTest package
testPackagereadTest package
top_productsreadTop products
valid-projectreadValid project
04

Trust audit

BLOCKgrade F · trust 37/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
api-doc.yaml:5037
authorized_keys; public-key auth only.
Why it matters. touches a credential store
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/eval-answer
.claude/skills/eval-answer
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/eval-diagnose
.claude/skills/eval-diagnose
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/eval-import
.claude/skills/eval-import
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/eval-improve
.claude/skills/eval-improve
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills/eval-judge
.claude/skills/eval-judge
Why it matters. link not followed
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/server/src/service/connection.ts:1690
logger.info(`Created ${storageType} secret: ${secretName}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
packages/server/src/service/connection.ts:1762
logger.info(`Created Azure secret: ${secretName}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
hammer/lib/server.ts:101
const baseUrl = `http://127.0.0.1:${opts.port}`;
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
hammer/lib/server.ts:102
const mcpUrl = `http://127.0.0.1:${opts.mcpPort}/mcp`;
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
packages/server/src/logger.spec.ts:29
connectionString: "postgresql://u:p@h/db",
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
packages/server/src/pg_helpers.spec.ts:104
"postgres://h?options=endpoint:foo@bar",
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
packages/server/src/pg_helpers.spec.ts:126
"tried postgres://u1:p1@h1/d1 then postgres://u2:p2@h2/d2",
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
packages/server/src/pg_helpers.spec.ts:134
"candidates: postgres://u1:p1@h1/d1,postgres://u2:p2@h2/d2",
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
packages/server/src/pg_helpers.spec.ts:148
"attach failed: host=h password=x and fallback postgres://u:p@h2/d",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/server/src/config.spec.ts:1007
const secret = "pg-password-that-must-not-be-logged";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/server/src/config.spec.ts:1063
const secret = "conn-password-that-must-not-be-logged";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/server/src/mcp/tools/search_database_schema_tool.spec.ts:78
password: "hunter2-should-never-appear",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/server/src/pg_helpers.spec.ts:248
const SECRET = "s3cret-value-not-a-real-credential";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/server/src/service/materialization_service.spec.ts:2467
const secret = "super-secret-token-value";
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/connections.md:271
"privateKey": "-----BEGIN OPENSSH PRIVATE KEY-----\n...\n-----END OPENSSH PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/server/src/logger.spec.ts:31
privateKey: "-----BEGIN PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/server/src/logger.spec.ts:79
privateKey: "-----BEGIN PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/server/src/mcp/tools/search_database_schema_tool.spec.ts:63
const SECRET = "-----BEGIN PRIVATE KEY-----AAAABBBBCCCC";
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/server/src/pg_helpers.spec.ts:369
"could not parse key: -----BEGIN RSA PRIVATE KEY-----\n" +

Gates applied: no_behavioural_pass.

Audited 2026-09-24 · audit v0.4.1 · source sha 4ab820396e64full audit observations/trust-audit/mcp-server/malloydata__publisher.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-244ab820396e64BLOCKF37first audit
06

Questions

What is the publisher MCP server?

Publisher is the open-source analytics engine for Malloy. It lets you define data models once — and use them everywhere.

What tools does publisher expose?

14 in total: 14 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is publisher safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (37/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does publisher need?

It reads API_KEY, BIGQUERY_PUBLIC_DATA_CREDENTIALS, EMBEDDING_API_KEY, GCS_TEST_KEY_ID, GCS_TEST_SECRET, GIVEN_SPEC_SPEC_SECRET, GOOGLE_APPLICATION_CREDENTIALS, KEY_NAME, OPENAI_API_KEY, POSTGRES_TEST_PASSWORD, PUBLISHER_ALLOW_UNVERIFIED_SSH_HOST_KEY and S3_CREDENTIAL_CHAIN_POLICY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does publisher run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @malloy-publisher/skills at 0.1.24.

How current is this page?

The grade is for one exact copy of the source (4ab820396e64), read on 2026-09-24. The repository is watched and re-audited when it changes.

Advertisement