GeminiCAUTION
MCP Server that enables Claude code to interact with Gemini
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for integrating Google's Gemini 3 models with Claude Code, enabling powerful collaboration between both AI systems. Now with a beautiful CLI!
[](https://www.npmjs.com/package/@rlabs-inc/gemini-mcp) [](https://registry.modelcontextprotocol.io)
MCP Registry Support: Now discoverable in the official MCP ecosystem!
Features
afe42d029b28OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add gemini-mcp --env GEMINI_API_KEY=${GEMINI_API_KEY} -- npx -y @rlabs-inc/[email protected]Exposed tools (45)
38 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
config | write | Set API key and preferences |
gemini-analyze-code | read | |
gemini-analyze-document | read | |
gemini-analyze-image | read | |
gemini-analyze-text | read | |
gemini-analyze-url | read | |
gemini-brainstorm | read | |
gemini-check-research | read | |
gemini-check-video | read | |
gemini-compare-urls | read | |
gemini-continue-image-edit | write | |
gemini-count-tokens | read | |
gemini-create-cache | write | |
gemini-deep-research | read | |
gemini-delete-cache | destructive | |
gemini-dialogue | read | |
gemini-end-image-edit | write | |
gemini-extract | read | |
gemini-extract-from-url | read | |
gemini-extract-tables | read | |
gemini-generate-image | read | |
gemini-generate-video | read | |
gemini-image-prompt | read | |
gemini-list-caches | read | |
gemini-list-image-sessions | read | |
gemini-list-voices | read | |
gemini-query | read | |
gemini-query-cache | read | |
gemini-research-followup | read | |
gemini-run-code | write | |
gemini-search | read | |
gemini-speak | read | |
gemini-start-image-edit | write | |
gemini-structured | read | |
gemini-summarize | read | |
gemini-summarize-pdf | read | |
gemini-youtube | read | |
gemini-youtube-summary | read | |
image | read | Generate images |
query | read | Query Gemini directly |
research | read | Deep research agent |
search | read | Real-time web search |
speak | read | Text-to-speech |
tokens | read | Count tokens in text or files |
video | read | Generate videos |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (13)
logger.info(`Token count: ${totalTokens}`)gemini-delete-cache
.prettierignore
import { initGeminiClient, generateImage } from '../../gemini-client.js'import { setupLogger } from '../../utils/logger.js'import { initGeminiClient, generateWithGeminiPro, generateWithGeminiFlash } from '../../gemini-client.js'import { setupLogger } from '../../utils/logger.js'import { initGeminiClient, startDeepResearch, checkDeepResearch } from '../../gemini-client.js'| `HTTP_PROXY` | No | - | HTTP proxy URL (e.g. `http://127.0.0.1:7890`) for routing traffic through a proxy |
HTTP_PROXY=http://127.0.0.1:7890 \
"HTTP_PROXY": "http://127.0.0.1:xxxx",
"HTTPS_PROXY": "http://127.0.0.1:xxxx"
@google/genai, undici, @eslint/js, @types/bun, @types/node, eslint, husky, prettier
Gates applied: no_behavioural_pass.
afe42d029b28full audit observations/trust-audit/mcp-server/rlabs-inc__gemini-24.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | afe42d029b28 | CAUTION | B | 89 | first audit |
Questions
What is the Gemini MCP server?
MCP Server that enables Claude code to interact with Gemini
What tools does Gemini expose?
45 in total: 38 read-only, 6 that write, and 1 that can delete or overwrite (gemini-delete-cache). Every one is listed on this page with its risk.
Is Gemini safe to connect to an agent?
With care. The audit graded it B (89/100) and found 13 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Gemini need?
It reads GEMINI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Gemini run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @rlabs-inc/gemini-mcp at 0.8.1.
How current is this page?
The grade is for one exact copy of the source (afe42d029b28), read on 2026-10-06. The repository is watched and re-audited when it changes.