publisherBLOCK
Publisher is the open-source analytics engine for Malloy. It lets you define data models once — and use them everywhere.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Malloy Publisher
The Analytics Engine for Malloy
A post modern data stack — built for the AI era. One data model, served over MCP and REST to AI agents, applications, and BI tools.
Created and maintained by Credible, the company behind the AI Analytics Engine.
AI agents: read AGENTS.md first (raw: https://raw.githubusercontent.com/malloydata/publisher/main/AGENTS.md). It covers starting the server, connecting over MCP, the bundled skills, and the package format. Fetch the raw file, not a summary of this page.
A 60-second walkthrough — model in your IDE with the Malloy skills, serve with Publisher, build a data app, materialize on a schedule, and analyze. Watch the video for playback controls.
Modeling, a query engine, materialization, access control, and an API — the pieces you used to assemble from five projects — ship as one server, built assuming the first builder or consumer is an agent.
Write down what your data means, in Malloy: the sources, the joins, the measures, who may see what. The open-source Malloy skills ship
4ab820396e64OBSERVED · 2026-09-24Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add skills --env API_KEY=${API_KEY} --env BIGQUERY_PUBLIC_DATA_CREDENTIALS=${BIGQUERY_PUBLIC_DATA_CREDENTIALS} --env EMBEDDING_API_KEY=${EMBEDDING_API_KEY} --env GCS_TEST_KEY_ID=${GCS_TEST_KEY_ID} -- npx -y @malloy-publisher/[email protected]{
"mcpServers": {
"skills": {
"command": "npx",
"args": [
"-y",
"@malloy-publisher/[email protected]"
],
"env": {
"API_KEY": "${API_KEY}",
"BIGQUERY_PUBLIC_DATA_CREDENTIALS": "${BIGQUERY_PUBLIC_DATA_CREDENTIALS}",
"EMBEDDING_API_KEY": "${EMBEDDING_API_KEY}",
"GCS_TEST_KEY_ID": "${GCS_TEST_KEY_ID}"
}
}
}
}Exposed tools (14)
14 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Local | read | Stored in this browser only |
by_category | read | Revenue by product category |
control | read | |
control2 | read | a — b |
ecommerce | read | Ecommerce demo |
orders | read | keep me |
pkg | read | test |
pkg-1 | read | Updated description |
sales_by_state | read | Revenue by state |
spotify | read | music |
test-package | read | Test package |
testPackage | read | Test package |
top_products | read | Top products |
valid-project | read | Valid project |
Trust audit
BLOCKgrade F · trust 37/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
authorized_keys; public-key auth only.
.claude/skills/eval-answer
.claude/skills/eval-diagnose
.claude/skills/eval-import
.claude/skills/eval-improve
.claude/skills/eval-judge
logger.info(`Created ${storageType} secret: ${secretName}`);logger.info(`Created Azure secret: ${secretName}`);const baseUrl = `http://127.0.0.1:${opts.port}`;const mcpUrl = `http://127.0.0.1:${opts.mcpPort}/mcp`;connectionString: "postgresql://u:p@h/db",
"postgres://h?options=endpoint:foo@bar",
"tried postgres://u1:p1@h1/d1 then postgres://u2:p2@h2/d2",
"candidates: postgres://u1:p1@h1/d1,postgres://u2:p2@h2/d2",
"attach failed: host=h password=x and fallback postgres://u:p@h2/d",
const secret = "pg-password-that-must-not-be-logged";
const secret = "conn-password-that-must-not-be-logged";
password: "hunter2-should-never-appear",
const SECRET = "s3cret-value-not-a-real-credential";
const secret = "super-secret-token-value";
"privateKey": "-----BEGIN OPENSSH PRIVATE KEY-----\n...\n-----END OPENSSH PRIVATE KEY-----",
privateKey: "-----BEGIN PRIVATE KEY-----",
privateKey: "-----BEGIN PRIVATE KEY-----",
const SECRET = "-----BEGIN PRIVATE KEY-----AAAABBBBCCCC";
"could not parse key: -----BEGIN RSA PRIVATE KEY-----\n" +
Gates applied: no_behavioural_pass.
4ab820396e64full audit observations/trust-audit/mcp-server/malloydata__publisher.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-24 | 4ab820396e64 | BLOCK | F | 37 | first audit |
Questions
What is the publisher MCP server?
Publisher is the open-source analytics engine for Malloy. It lets you define data models once — and use them everywhere.
What tools does publisher expose?
14 in total: 14 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is publisher safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (37/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does publisher need?
It reads API_KEY, BIGQUERY_PUBLIC_DATA_CREDENTIALS, EMBEDDING_API_KEY, GCS_TEST_KEY_ID, GCS_TEST_SECRET, GIVEN_SPEC_SPEC_SECRET, GOOGLE_APPLICATION_CREDENTIALS, KEY_NAME, OPENAI_API_KEY, POSTGRES_TEST_PASSWORD, PUBLISHER_ALLOW_UNVERIFIED_SSH_HOST_KEY and S3_CREDENTIAL_CHAIN_POLICY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does publisher run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @malloy-publisher/skills at 0.1.24.
How current is this page?
The grade is for one exact copy of the source (4ab820396e64), read on 2026-09-24. The repository is watched and re-audited when it changes.