Atlas / MCP servers / michsob / PowerPlatform

PowerPlatformSAFE

mcp/michsob/powerplatform

PowerPlatform CLI and MCP tools

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
66 45r · 18w · 3d
Transport
stdio
License
MIT
Stars
44
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server and standalone CLI for querying and configuring PowerPlatform / Dataverse environments. Supports multiple environments, entity metadata, records, plugins, flows, solutions, workflows, business rules, security roles, custom APIs, web resources, and more — including write operations for automated environment setup.

Why MCP + CLI?

MCP integrates directly with AI clients (Claude, Cursor, GitHub Copilot) for interactive, conversational exploration of your environments.

CLI writes results to a file system cache instead of returning them inline. MCP tool responses are bound by the AI client's context window, which can truncate or degrade results when querying environments with hundreds of entities, flows, or plugin steps. The CLI avoids this limitation by persisting full results to disk, making them available for follow-up analysis without context pressure. Both interfaces share the same tools and capabilities.

Installation

Requires Node.js 22+ (< 25).

MCP Server

npm install -g powerplatform-mcp
# or
npx powerplatform-mcp

CLI

npm install -g powerplatform-cli
# or
npx powerplatform-cli

Docker

# MCP Server
docker pull ghcr.io/michsob/powerplatform-mcp
docker run --env-file .env ghcr.io/michsob/powerplatform-mcp

# CLI
docker pull ghcr.io/michsob/powerplatform-cli
docker run --env-file .env ghcr.io/michsob/powerplatform-cli entity-attributes account

Configuration

The tool supports multiple environments. Define them via environment variables:

POWERPLATFORM_ENVIRONMENTS=DEV,UAT,PROD

# For each environment, set:
POWERPLATFORM_DEV_URL=https://dev-org.crm.dynamics.com
POWERPLATFORM_DEV_CLIENT_ID=your-client-id
POWERPLATFORM_DEV_CLIENT_SECRET=your-client-secret
POWERPLATFORM_DEV_TENANT_ID=your-tenant-id

POWERPLATFORM_UAT_URL=https://uat-org.crm.dynamics.com
POWERPLATFORM_UAT_CLIENT_ID=...
POWERPLATFORM_UAT_CLIE
Read from source at commit 4baaf4ebca6aOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add powerplatform-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "powerplatform-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (66)

45 read · 18 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add-security-role-privilegeswrite
add-solution-componentwrite
cancel-flow-runwrite
check-component-dependenciesread
check-delete-eligibilitydestructive
clone-security-roleread
create-custom-apiwrite
create-custom-api-request-parameterwrite
create-custom-api-response-propertywrite
create-entity-alternate-keywrite
create-entity-string-attributewrite
create-environment-variablewrite
create-plugin-stepwrite
create-security-rolewrite
create-web-resourcewrite
delete-security-roledestructive
export-solutionread
get-all-plugin-stepsread
get-business-ruleread
get-business-rulesread
get-connection-referencesread
get-custom-apiread
get-custom-api-request-parametersread
get-custom-api-response-propertiesread
get-custom-apisread
get-entity-attributeread
get-entity-attributesread
get-entity-keysread
get-entity-metadataread
get-entity-plugin-pipelineread
get-entity-relationshipsread
get-environment-variablesread
get-flow-definitionread
get-flow-inventoryread
get-flow-run-detailswrite
get-flow-runsread
get-flowsread
get-global-option-setwrite
get-ootb-workflowsread
get-plugin-assembliesread
get-plugin-assembly-completeread
get-plugin-trace-logsread
get-plugin-typeread
get-publishersread
get-recordread
get-sdk-messageread
get-security-role-privilegesread
get-security-rolesread
get-service-endpointsread
get-solutionread
get-solution-componentsread
get-solutionsread
get-web-resourceread
get-web-resourcesread
get-workflow-definitionread
get-workflowsread
list-privilegesread
publish-customizationswrite
query-recordsread
remove-security-role-privilegesdestructive
replace-security-role-privilegesread
resubmit-flow-runwrite
scan-flow-healthread
search-workflowsread
set-environment-variable-valuewrite
update-security-rolewrite
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (3 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
check-delete-eligibility, delete-security-role, remove-security-role-privileges
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/businessrule-commands.ts:2
import type { EnvironmentRegistry } from '../../environment-config.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/configuration-commands.ts:2
import type { EnvironmentRegistry } from '../../environment-config.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/customapi-commands.ts:2
import type { EnvironmentRegistry } from '../../environment-config.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/dependency-commands.ts:2
import type { EnvironmentRegistry } from '../../environment-config.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/entity-commands.ts:2
import type { EnvironmentRegistry } from '../../environment-config.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@azure/msal-node, @modelcontextprotocol/sdk, axios, commander, zod, @types/node, dotenv, dotenv-cli
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:193
| `replace-security-role-privileges` | Wipe and replace the full privilege set (`ReplacePrivilegesRole` — destructive, requires `confirm: true`) | `roleId`, `privileges[]`, `confirm` | |

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4baaf4ebca6afull audit observations/trust-audit/mcp-server/michsob__powerplatform.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-084baaf4ebca6aSAFEB89first audit
06

Questions

What is the PowerPlatform MCP server?

PowerPlatform CLI and MCP tools

What tools does PowerPlatform expose?

66 in total: 45 read-only, 18 that write, and 3 that can delete or overwrite (check-delete-eligibility, delete-security-role, remove-security-role-privileges). Every one is listed on this page with its risk.

Is PowerPlatform safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does PowerPlatform need?

No credential environment variables were found in its source, so it appears to need none.

How does PowerPlatform run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as powerplatform-mcp at 2.5.0.

How current is this page?

The grade is for one exact copy of the source (4baaf4ebca6a), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement