Atlas / MCP servers / sailingcoder / Grafana

GrafanaSAFE

mcp/sailingcoder/grafana-2

让AI助手直接分析你的Grafana监控数据 - A Model Context Protocol server for Grafana data analysis

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
6 6r · 0w · 0d
Transport
stdio
License
MIT
Stars
46
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

让 AI 直接读懂你的监控数据,成为你的专属智能运维助手!

English | 中文文档

✨ 项目简介

想象一下这样的场景:

  • 您问AI:"我的服务器现在怎么样?"
  • AI直接查看您的Grafana监控,回答:"CPU使用率偏高,建议检查这几个进程..."

繁杂的监控图表,AI 辅助你一键解读。你无需再逐图筛查,真正实现从 图表到洞察 的闭环分析体验!

🚀 核心特性

Grafana MCP Analyzer 基于 MCP (Model Context Protocol) 协议,赋能Claude、ChatGPT等AI助手具备以下超能力:

  • 自然语言查询 - 轻松访问监控数据,AI 一键输出专业分析
  • 多轮对话支持 - 支持复杂的多轮对话分析,能够基于上下文进行深入分析
  • curl支持 - 直接使用浏览器 copy 的 curl 合成查询
  • 全数据源支持 - Prometheus、MySQL、ES 等通通支持
  • 专业 DevOps 建议 - 不只是展示数据,更提供可执行的优化方案,提升DevOps效率
💡 架构新模式:会话缓存 → 逐步获取数据 → 渐进式深入分析 → 缓存复用,让AI分析更准确、更高效。

🛠️ 快速开始

第一步:极速安装(30秒)

npm install -g grafana-mcp-analyzer
环境要求:Node.js 18+ | 安装指南

第二步:AI 助手集成(30秒)

Cursor设置 → “MCP” → 服务配置(以Cursor为例):

{
"mcpServers": {
"grafana": {
"command": "grafana-mcp-analyzer",
"env": {
"CONFIG_PATH": "https://raw.githubusercontent.com/SailingCoder/grafana-mcp-analyzer/main/config/grafana-config-play.js",
"MAX_CHUNK_SIZE": "100"
}
}
}
}

注:CONFIG_PATH支持绝对路径、远程路径,推荐使用远程路径快速体验。

第三步:编写配置文件(1分钟)

如需连接自有数据,可在 CONFIG_PATH 路径下创建配置文件:(grafana-config-play.js 示例 👉 点此查看 )

如果你只想快速体验示例,可跳过此步骤,直接执行第四步。

点击展开查看示例

/**
* 基于Grafana Play演示实例的配置文件
* 以下配置文件内容来源:https://raw.githubusercontent.com/SailingCoder/grafana-mcp-analyzer/main/config/grafana-config-play.js
* Request 配置方式:支持 http api 和 curl
*/
const config = {
// Grafana服务器地址
baseUrl: 'https://play.grafa
Read from source at commit fef7ffb40ca3OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add grafana-mcp-analyzer -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "grafana-mcp-analyzer": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (6)

6 read · 0 write · 0 destructive.

ToolRiskDescription
analyze_existing_dataread
analyze_queryread
check_healthread
chunk_workflowread
list_queriesread
manage_cacheread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/services/config-manager.ts:129
hash = crypto.createHash('md5').update(configPath).digest('hex');
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/services/config-manager.ts:133
hash = crypto.createHash('md5').update(absolutePath).digest('hex');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, zod, @types/node, esbuild, rimraf, ts-node, typescript
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha fef7ffb40ca3full audit observations/trust-audit/mcp-server/sailingcoder__grafana-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08fef7ffb40ca3SAFEB89first audit
06

Questions

What is the Grafana MCP server?

让AI助手直接分析你的Grafana监控数据 - A Model Context Protocol server for Grafana data analysis

What tools does Grafana expose?

6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Grafana safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Grafana need?

No credential environment variables were found in its source, so it appears to need none.

How does Grafana run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as grafana-mcp-analyzer at 2.1.0.

How current is this page?

The grade is for one exact copy of the source (fef7ffb40ca3), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement