Perforce P4BLOCK
[Community Supported] Perforce P4 MCP Server is a Model Context Protocol (MCP) server that integrates with the Perforce P4 version control system.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Perforce P4 MCP Server
Perforce P4 MCP Server is a Model Context Protocol (MCP) server that integrates with the Perforce P4 version control system. It is built on FastMCP with direct P4 Python bindings to expose safe, structured read/write tools for changelists, files, shelves, workspaces, jobs, reviews, and server metadata. It also integrates with P4 DAM through its REST API to manage resources.
Features · Prerequisites · System Requirements · Install · Deployment · Client Configurations · P4 Configurations · Tools
Logging · Troubleshoot · Support · Contributions · License
Features
- Comprehensive P4 integration: Read/write tools across files, changelists, shelves, workspaces, jobs, reviews, streams, and server information.
- Code review workflows: P4 Code Review support for review discovery, voting, state transitions, commenting, and participant management.
- P4 DAM integration: Access P4 DAM assets and metadata through MCP-compatible AI assistants. Search for assets, retrieve metadata, manage reviews, create asset bundles, update as
1e0cddcedbcdOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add p4mcp-server:2026.4.3078076 -- docker run -i --rm ghcr.io/perforce/p4mcp-server:2026.4.3078076:None
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (6 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
logger.info("Swarm SSL verification disabled via P4MCP_SSL_VERIFY=false")* Ensure workspace and depot operations do not bypass safety checks.
CLA.docx
Gates applied: instruction_override, no_behavioural_pass.
1e0cddcedbcdfull audit observations/trust-audit/mcp-server/perforce__perforce-p4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 1e0cddcedbcd | BLOCK | D | 69 | first audit |
Questions
What is the Perforce P4 MCP server?
[Community Supported] Perforce P4 MCP Server is a Model Context Protocol (MCP) server that integrates with the Perforce P4 version control system.
Is Perforce P4 safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Perforce P4 need?
It reads GITHUB_TOKEN and P4DAM_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Perforce P4 run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as p4mcp-server.
How current is this page?
The grade is for one exact copy of the source (1e0cddcedbcd), read on 2026-10-07. The repository is watched and re-audited when it changes.