Atlas / MCP servers / sprawz / GTM Editor

GTM EditorCAUTION

mcp/sprawz/gtm-editor

An MCP server for Google Tag Manager. Connect it to your LLM, authenticate once, and start managing GTM through natural language.

Verdict
CAUTION
Grade
B
Trust score
85 /100
Exposed tools
—
Transport
streamable-http
License
BSD-3-Clause
Stars
169
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](LICENSE) [](https://go.dev/) [](https://modelcontextprotocol.io/) [](https://github.com/paolobietolini/gtm-mcp-server/actions/workflows/security.yml) [](https://github.com/paolobietolini/gtm-mcp-server/releases)

GTM MCP Server connects MCP clients to the Google Tag Manager API. It can inspect containers, create and update workspace entities, create versions, and publish a selected version after explicit confirmation.

Use the hosted server at:

https://mcp.gtmeditor.com

The server supports browser-based Google OAuth for individual users and service-account authentication for self-hosted automation.

Project status

The agreed API parity scope is complete. The project implements 101 methods from Google's 106-method GTM v2 discovery surface. The five accounts.user_permissions methods are intentionally excluded because granting and revoking GTM access needs a separate privilege-management design.

Tool count and API-method count are different. Some tools provide local guidance, while some helpers cover more than one Google API call.

Connect an MCP client

Add the hosted URL as a remote HTTP MCP serve

Read from source at commit 4821c7d68747OBSERVED · 2026-10-07
02

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (15)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
auth/middleware_test.go:499
const token = "sekrit-bearer-token-value"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
auth/middleware_test.go:529
const token = "zqx-stale-bearer-value"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.goreleaser.yaml
.goreleaser.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
auth/cimd_test.go:181
{"169.254.169.254:80", true}, // cloud metadata service
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
auth/cimd_test.go:193
{"[64:ff9b::a9fe:a9fe]:80", true}, // NAT64 of 169.254.169.254
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
auth/cimd_test.go:205
{"[::a9fe:a9fe]:80", true}, // 169.254.169.254
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
auth/cimd_test.go:107
"https://127.0.0.1/client.json",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
auth/cimd_test.go:109
"https://10.0.0.5/client.json",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
auth/cimd_test.go:110
"https://192.168.1.1/client.json",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
auth/cimd_test.go:149
req := httptest.NewRequest(http.MethodGet, "https://127.0.0.1/latest/meta-data/", nil)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
auth/cimd_test.go:394
fmt.Fprintf(w, `{"client_id": %q, "client_name": "Claude Code", "redirect_uris": ["http://localhost/callback", "http://127.0.0.1/callback"]}`, metadataURL)
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
skills/gtm-mcp/gtm-mcp.md:8
You are connected to the GTM MCP Server, which gives you full access to manage Google Tag Manager through the MCP protocol. This skill teaches you how to use it effectively.
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:446
cat > .env <<'EOF'
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 4821c7d68747full audit observations/trust-audit/mcp-server/sprawz__gtm-editor.json · Report an issue / request a re-scan
03

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-074821c7d68747CAUTIONB85first audit
04

Questions

What is the GTM Editor MCP server?

An MCP server for Google Tag Manager. Connect it to your LLM, authenticate once, and start managing GTM through natural language.

Is GTM Editor safe to connect to an agent?

With care. The audit graded it B (85/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does GTM Editor need?

It reads MCP_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does GTM Editor run?

It speaks streamable-http, so it runs as a service you connect to over the network.

How current is this page?

The grade is for one exact copy of the source (4821c7d68747), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement