Atlas / MCP servers / rlabs-inc / Gemini

GeminiCAUTION

mcp/rlabs-inc/gemini-24

MCP Server that enables Claude code to interact with Gemini

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
45 38r · 6w · 1d
Transport
stdio
License
MIT
Stars
219
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for integrating Google's Gemini 3 models with Claude Code, enabling powerful collaboration between both AI systems. Now with a beautiful CLI!

[](https://www.npmjs.com/package/@rlabs-inc/gemini-mcp) [](https://registry.modelcontextprotocol.io)

MCP Registry Support: Now discoverable in the official MCP ecosystem!

Features

Read from source at commit afe42d029b28OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add gemini-mcp --env GEMINI_API_KEY=${GEMINI_API_KEY} -- npx -y @rlabs-inc/[email protected]
03

Exposed tools (45)

38 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
configwriteSet API key and preferences
gemini-analyze-coderead
gemini-analyze-documentread
gemini-analyze-imageread
gemini-analyze-textread
gemini-analyze-urlread
gemini-brainstormread
gemini-check-researchread
gemini-check-videoread
gemini-compare-urlsread
gemini-continue-image-editwrite
gemini-count-tokensread
gemini-create-cachewrite
gemini-deep-researchread
gemini-delete-cachedestructive
gemini-dialogueread
gemini-end-image-editwrite
gemini-extractread
gemini-extract-from-urlread
gemini-extract-tablesread
gemini-generate-imageread
gemini-generate-videoread
gemini-image-promptread
gemini-list-cachesread
gemini-list-image-sessionsread
gemini-list-voicesread
gemini-queryread
gemini-query-cacheread
gemini-research-followupread
gemini-run-codewrite
gemini-searchread
gemini-speakread
gemini-start-image-editwrite
gemini-structuredread
gemini-summarizeread
gemini-summarize-pdfread
gemini-youtuberead
gemini-youtube-summaryread
imagereadGenerate images
queryreadQuery Gemini directly
researchreadDeep research agent
searchreadReal-time web search
speakreadText-to-speech
tokensreadCount tokens in text or files
videoreadGenerate videos
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/tools/token-count.ts:61
logger.info(`Token count: ${totalTokens}`)
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
gemini-delete-cache
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/image.ts:9
import { initGeminiClient, generateImage } from '../../gemini-client.js'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/image.ts:10
import { setupLogger } from '../../utils/logger.js'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/query.ts:9
import { initGeminiClient, generateWithGeminiPro, generateWithGeminiFlash } from '../../gemini-client.js'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/query.ts:10
import { setupLogger } from '../../utils/logger.js'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/commands/research.ts:9
import { initGeminiClient, startDeepResearch, checkDeepResearch } from '../../gemini-client.js'
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CLAUDE.md:122
| `HTTP_PROXY` | No | - | HTTP proxy URL (e.g. `http://127.0.0.1:7890`) for routing traffic through a proxy |
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
CLAUDE.md:140
HTTP_PROXY=http://127.0.0.1:7890 \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:445
"HTTP_PROXY": "http://127.0.0.1:xxxx",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:446
"HTTPS_PROXY": "http://127.0.0.1:xxxx"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@google/genai, undici, @eslint/js, @types/bun, @types/node, eslint, husky, prettier
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha afe42d029b28full audit observations/trust-audit/mcp-server/rlabs-inc__gemini-24.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06afe42d029b28CAUTIONB89first audit
06

Questions

What is the Gemini MCP server?

MCP Server that enables Claude code to interact with Gemini

What tools does Gemini expose?

45 in total: 38 read-only, 6 that write, and 1 that can delete or overwrite (gemini-delete-cache). Every one is listed on this page with its risk.

Is Gemini safe to connect to an agent?

With care. The audit graded it B (89/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Gemini need?

It reads GEMINI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Gemini run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @rlabs-inc/gemini-mcp at 0.8.1.

How current is this page?

The grade is for one exact copy of the source (afe42d029b28), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement