PowerPlatformSAFE
PowerPlatform CLI and MCP tools
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server and standalone CLI for querying and configuring PowerPlatform / Dataverse environments. Supports multiple environments, entity metadata, records, plugins, flows, solutions, workflows, business rules, security roles, custom APIs, web resources, and more — including write operations for automated environment setup.
Why MCP + CLI?
MCP integrates directly with AI clients (Claude, Cursor, GitHub Copilot) for interactive, conversational exploration of your environments.
CLI writes results to a file system cache instead of returning them inline. MCP tool responses are bound by the AI client's context window, which can truncate or degrade results when querying environments with hundreds of entities, flows, or plugin steps. The CLI avoids this limitation by persisting full results to disk, making them available for follow-up analysis without context pressure. Both interfaces share the same tools and capabilities.
Installation
Requires Node.js 22+ (< 25).
MCP Server
npm install -g powerplatform-mcp # or npx powerplatform-mcp
CLI
npm install -g powerplatform-cli # or npx powerplatform-cli
Docker
# MCP Server docker pull ghcr.io/michsob/powerplatform-mcp docker run --env-file .env ghcr.io/michsob/powerplatform-mcp # CLI docker pull ghcr.io/michsob/powerplatform-cli docker run --env-file .env ghcr.io/michsob/powerplatform-cli entity-attributes account
Configuration
The tool supports multiple environments. Define them via environment variables:
POWERPLATFORM_ENVIRONMENTS=DEV,UAT,PROD # For each environment, set: POWERPLATFORM_DEV_URL=https://dev-org.crm.dynamics.com POWERPLATFORM_DEV_CLIENT_ID=your-client-id POWERPLATFORM_DEV_CLIENT_SECRET=your-client-secret POWERPLATFORM_DEV_TENANT_ID=your-tenant-id POWERPLATFORM_UAT_URL=https://uat-org.crm.dynamics.com POWERPLATFORM_UAT_CLIENT_ID=... POWERPLATFORM_UAT_CLIE
4baaf4ebca6aOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add powerplatform-mcp -- npx -y [email protected]
{
"mcpServers": {
"powerplatform-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (66)
45 read · 18 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add-security-role-privileges | write | |
add-solution-component | write | |
cancel-flow-run | write | |
check-component-dependencies | read | |
check-delete-eligibility | destructive | |
clone-security-role | read | |
create-custom-api | write | |
create-custom-api-request-parameter | write | |
create-custom-api-response-property | write | |
create-entity-alternate-key | write | |
create-entity-string-attribute | write | |
create-environment-variable | write | |
create-plugin-step | write | |
create-security-role | write | |
create-web-resource | write | |
delete-security-role | destructive | |
export-solution | read | |
get-all-plugin-steps | read | |
get-business-rule | read | |
get-business-rules | read | |
get-connection-references | read | |
get-custom-api | read | |
get-custom-api-request-parameters | read | |
get-custom-api-response-properties | read | |
get-custom-apis | read | |
get-entity-attribute | read | |
get-entity-attributes | read | |
get-entity-keys | read | |
get-entity-metadata | read | |
get-entity-plugin-pipeline | read | |
get-entity-relationships | read | |
get-environment-variables | read | |
get-flow-definition | read | |
get-flow-inventory | read | |
get-flow-run-details | write | |
get-flow-runs | read | |
get-flows | read | |
get-global-option-set | write | |
get-ootb-workflows | read | |
get-plugin-assemblies | read | |
get-plugin-assembly-complete | read | |
get-plugin-trace-logs | read | |
get-plugin-type | read | |
get-publishers | read | |
get-record | read | |
get-sdk-message | read | |
get-security-role-privileges | read | |
get-security-roles | read | |
get-service-endpoints | read | |
get-solution | read | |
get-solution-components | read | |
get-solutions | read | |
get-web-resource | read | |
get-web-resources | read | |
get-workflow-definition | read | |
get-workflows | read | |
list-privileges | read | |
publish-customizations | write | |
query-records | read | |
remove-security-role-privileges | destructive | |
replace-security-role-privileges | read | |
resubmit-flow-run | write | |
scan-flow-health | read | |
search-workflows | read | |
set-environment-variable-value | write | |
update-security-role | write |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (3 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
check-delete-eligibility, delete-security-role, remove-security-role-privileges
import type { EnvironmentRegistry } from '../../environment-config.js';import type { EnvironmentRegistry } from '../../environment-config.js';import type { EnvironmentRegistry } from '../../environment-config.js';import type { EnvironmentRegistry } from '../../environment-config.js';import type { EnvironmentRegistry } from '../../environment-config.js';@azure/msal-node, @modelcontextprotocol/sdk, axios, commander, zod, @types/node, dotenv, dotenv-cli
| `replace-security-role-privileges` | Wipe and replace the full privilege set (`ReplacePrivilegesRole` — destructive, requires `confirm: true`) | `roleId`, `privileges[]`, `confirm` | |
Gates applied: no_behavioural_pass.
4baaf4ebca6afull audit observations/trust-audit/mcp-server/michsob__powerplatform.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 4baaf4ebca6a | SAFE | B | 89 | first audit |
Questions
What is the PowerPlatform MCP server?
PowerPlatform CLI and MCP tools
What tools does PowerPlatform expose?
66 in total: 45 read-only, 18 that write, and 3 that can delete or overwrite (check-delete-eligibility, delete-security-role, remove-security-role-privileges). Every one is listed on this page with its risk.
Is PowerPlatform safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does PowerPlatform need?
No credential environment variables were found in its source, so it appears to need none.
How does PowerPlatform run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as powerplatform-mcp at 2.5.0.
How current is this page?
The grade is for one exact copy of the source (4baaf4ebca6a), read on 2026-10-08. The repository is watched and re-audited when it changes.