Atlas / MCP servers / shariqriazz / Vertex AI

Vertex AISAFE

mcp/shariqriazz/vertex-ai

MCP server for Vertex AI and Gemini tools, including grounded answers, documentation research, and filesystem workflows.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
16 11r · 5w · 0d
Transport
stdio
License
MIT
Stars
88
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/shariqriazz-vertex-ai-mcp-server)

[](https://smithery.ai/server/@shariqriazz/vertex-ai-mcp-server)

This project implements a Model Context Protocol (MCP) server that provides a comprehensive suite of tools for interacting with Google Cloud's Vertex AI Gemini models, focusing on coding assistance and general query answering.

Security boundary

This server includes filesystem write and terminal-execution tools in addition to model and research tools. Run it with a dedicated low-privilege identity, limit its filesystem and network access, and keep consequential tools behind explicit approval. Do not treat an MCP client confirmation prompt as server-side authorization.

For the implementation tradeoffs this project exposed alongside six other public MCP codebases, see What building seven MCP servers taught me about production MCP. The article uses this repository as public engineering evidence; it does not claim that every production control discussed there is already implemented here.

Features

  • Provides access to Vertex AI Gemini models via numerous MCP tools.
  • Supports web search grounding (answer_query_websearch) and direct knowledge answering (answer_query_direct).
  • Configurable model ID, temperature, streaming behavior, max output tokens, and retry settings via environment variables.
  • Uses streaming API by default for potentially better responsiveness.
  • Includes basic retry logic for transient API errors.
  • Minimal safety
Read from source at commit 2e8a4b29f159OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add vertex-ai-mcp-server --env AI_MAX_OUTPUT_TOKENS=${AI_MAX_OUTPUT_TOKENS} --env GEMINI_API_KEY=${GEMINI_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "vertex-ai-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AI_MAX_OUTPUT_TOKENS": "${AI_MAX_OUTPUT_TOKENS}",
        "GEMINI_API_KEY": "${GEMINI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (16)

11 read · 5 write · 0 destructive.

ToolRiskDescription
answer_query_directreadAnswers a natural language query using only the internal knowledge of the configured Vertex AI model (${modelIdPlaceholder}). Does not use web search. Requires a
answer_query_websearchreadAnswers a natural language query using the configured Vertex AI model (${modelIdPlaceholder}) enhanced with Google Search results for up-to-date information. Requires a
code_analysis_with_docsreadAnalyzes code snippets by comparing them with best practices from official documentation found via web search. Identifies potential bugs, performance issues, and security vulnerabilities. Uses the configured Vertex AI model (${modelIdPlaceholder}) with Google Search. Requires
database_schema_analyzerreadReviews database schemas for normalization, indexing, and performance issues. Suggests improvements based on database-specific best practices. Provides migration strategies for implementing suggested changes. Uses the configured Vertex AI model (${modelIdPlaceholder}) with Google Search. Requires
dependency_vulnerability_scanreadAnalyzes project dependencies for known security vulnerabilities. Provides detailed information about each vulnerability with severity ratings. Suggests mitigation strategies and secure alternatives. Uses the configured Vertex AI model (${modelIdPlaceholder}) with Google Search. Requires
documentation_generatorreadCreates comprehensive documentation for code, APIs, or systems. Follows industry best practices for technical documentation. Includes examples, diagrams, and user guides. Uses the configured Vertex AI model (${modelIdPlaceholder}) with Google Search. Requires
get_doc_snippetsreadProvides precise, authoritative code snippets or concise answers for technical queries by searching official documentation. Focuses on delivering exact solutions without unnecessary explanation. Uses the configured Vertex AI model (${modelIdPlaceholder}) with Google Search. Requires
microservice_design_assistantreadHelps design microservice architectures for specific domains. Provides service boundary recommendations and communication patterns. Includes deployment and orchestration considerations. Uses the configured Vertex AI model (${modelIdPlaceholder}) with Google Search. Requires
regulatory_compliance_advisorreadProvides guidance on regulatory requirements for specific industries (GDPR, HIPAA, etc.). Suggests implementation approaches for compliance. Includes checklists and verification strategies. Uses the configured Vertex AI model (${modelIdPlaceholder}) with Google Search. Requires
save_answer_query_directwriteAnswers a natural language query using only the internal knowledge of the configured Vertex AI model (${modelIdPlaceholder}), does not use web search, and saves the answer to a file. Requires
save_answer_query_websearchwriteAnswers a natural language query using Google Search results and saves the answer to a file. Uses the configured Vertex AI model (${modelIdPlaceholder}). Requires
save_doc_snippetwriteProvides precise code snippets or concise answers for technical queries by searching official documentation and saves the result to a file. Uses the configured Vertex AI model (${modelIdPlaceholder}) with Google Search. Requires
save_generate_project_guidelineswriteGenerates comprehensive project guidelines based on a tech stack using web search and saves the result to a specified file path. Uses the configured Vertex AI model (${modelIdPlaceholder}). Requires
save_topic_explanationwriteProvides a detailed explanation for a query about a specific software topic using official documentation found via web search and saves the result to a file. Uses the configured Vertex AI model (${modelIdPlaceholder}). Requires
security_best_practices_advisorreadProvides security recommendations for specific technologies or scenarios. Includes code examples for implementing secure practices. References industry standards and security guidelines. Uses the configured Vertex AI model (${modelIdPlaceholder}) with Google Search. Requires
testing_strategy_generatorreadCreates comprehensive testing strategies for applications or features. Suggests appropriate testing types (unit, integration, e2e) with coverage goals. Provides example test cases and testing frameworks. Uses the configured Vertex AI model (${modelIdPlaceholder}) with Google Search. Requires
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@google/genai, diff, dotenv, minimatch, zod, zod-to-json-schema, @types/diff, @types/minimatch
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrivilege escalation / persistence · review.unsafe_action · CWE-269, CWE-250
README.md
Minimal safety filters applied (`BLOCK_NONE`) to reduce potential blocking (use with caution).
Why it matters. The server disables content safety filters on the Vertex AI Gemini model by default, which could cause the agent to generate harmful or unsafe content without the user's informed consent.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 2e8a4b29f159full audit observations/trust-audit/mcp-server/shariqriazz__vertex-ai.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-072e8a4b29f159SAFEB89first audit
06

Questions

What is the Vertex AI MCP server?

MCP server for Vertex AI and Gemini tools, including grounded answers, documentation research, and filesystem workflows.

What tools does Vertex AI expose?

16 in total: 11 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Vertex AI safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Vertex AI need?

It reads AI_MAX_OUTPUT_TOKENS and GEMINI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Vertex AI run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as vertex-ai-mcp-server at 0.4.0.

How current is this page?

The grade is for one exact copy of the source (2e8a4b29f159), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement