Atlas / MCP servers / pinecone-io / Pinecone Developer

Pinecone DeveloperSAFE

mcp/pinecone-io/pinecone-developer

Connect your Pinecone projects to Cursor, Claude, and other AI assistants

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
71
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@pinecone-database/mcp) [](https://opensource.org/licenses/Apache-2.0) [](https://github.com/pinecone-io/pinecone-mcp/actions/workflows/ci.yml)

The Model Context Protocol (MCP) is a standard that allows coding assistants and other AI tools to interact with platforms like Pinecone. The Pinecone Developer MCP Server allows you to connect these tools with Pinecone projects and documentation.

Once connected, AI tools can:

  • Search Pinecone documentation to answer questions accurately.
  • Help you configure indexes based on your application's needs.
  • Generate code informed by your index configuration and data, as well as Pinecone documentation and examples.
  • Upsert and search for data in indexes, allowing you to test queries and evaluate results within your dev environment.

See the docs for more detailed information.

This MCP server is focused on improving the experience of developers working with Pinecone as part of their technology stack. It is intended for use with coding assistants. Pinecone also offers the Assistant MCP, which is designed to provide AI assistants with relevant context sourced from your knowledge base.

Setup

To configure the MCP server to access your Pinecone project, you will need to generate an API key using the console. Without an API key, your AI tool will still be able to search documentation. However, it will not be able to manage or query your indexes.

The MCP server requires Node.js v20 or later. Ensure that node and

Read from source at commit 0aef6e6263edOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp --env PINECONE_API_KEY=${PINECONE_API_KEY} -- npx -y @pinecone-database/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@pinecone-database/[email protected]"
      ],
      "env": {
        "PINECONE_API_KEY": "${PINECONE_API_KEY}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
search-docsread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/database/cascading-search.test.ts:2
import {createMockPinecone, MockPinecone} from '../../test-utils/mock-pinecone.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/database/cascading-search.test.ts:3
import {createMockServer, MockServer} from '../../test-utils/mock-server.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/database/common/pinecone-client.test.ts:25
vi.mock('../../../constants.js', () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/database/common/pinecone-client.test.ts:32
vi.mock('../../../version.js', () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/database/common/pinecone-client.ts:2
import {PINECONE_API_KEY} from '../../../constants.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @pinecone-database/pinecone, zod, @eslint/js, @types/node, eslint, eslint-config-prettier, prettier
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
README.md:77
To install this as a [Gemini CLI](https://github.com/google-gemini/gemini-cli) extension, run the following command:
Why it matters. remote text is to be obeyed as instructions

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 0aef6e6263edfull audit observations/trust-audit/mcp-server/pinecone-io__pinecone-developer.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-070aef6e6263edSAFEB89first audit
06

Questions

What is the Pinecone Developer MCP server?

Connect your Pinecone projects to Cursor, Claude, and other AI assistants

What tools does Pinecone Developer expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Pinecone Developer safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Pinecone Developer need?

It reads PINECONE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Pinecone Developer run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @pinecone-database/mcp at 0.3.0.

How current is this page?

The grade is for one exact copy of the source (0aef6e6263ed), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement