Atlas / MCP servers / stape-io / Google Tag Manager

Google Tag ManagerBLOCK

mcp/stape-io/google-tag-manager

MCP server for Google Tag Manager

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
21 20r · 1w · 0d
Transport
stdio · streamable-http
License
Apache-2.0
Stars
226
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://archestra.ai/mcp-catalog/stape-io__google-tag-manager-mcp-server)

An interface to the Google Tag Manager API over MCP, in two flavours: a hosted server with Google OAuth built in, and a local CLI that runs on your own credentials.

Table of Contents

  • MCP Server for Google Tag Manager
  • Table of Contents
  • Repository layout
  • Installation
  • Claude Desktop
  • Claude Code
  • VS Code
  • GitHub Copilot
  • Copilot CLI
  • Cursor
  • Antigravity
  • ChatGPT
  • Other MCP clients
  • Troubleshooting
  • Test your changes locally
  • Changes to packages/core or packages/cli
  • Changes to apps/worker
  • 1. Set up a Google Cloud OAuth client
  • 2. Configure local environment variables
  • 3. Start the server
  • 4. Point your MCP client at the local server
  • Releasing
  • Development
  • Useful resources
  • Open Source

Repository layout

npm workspace with one app and two published packages:

Read from source at commit 5e97b0d78c4eOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add google-tag-manager-mcp-core -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "google-tag-manager-mcp-core": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (21)

20 read · 1 write · 0 destructive.

ToolRiskDescription
STAPE.AIread
gtag_destinationread
gtm_accountread
gtm_auth_statusread
gtm_built_in_variableread
gtm_clientread
gtm_containerread
gtm_environmentread
gtm_folderread
gtm_gtag_configread
gtm_guideread
gtm_tagread
gtm_templateread
gtm_transformationread
gtm_triggerwrite
gtm_user_permissionread
gtm_variableread
gtm_versionread
gtm_version_headerread
gtm_workspaceread
gtm_zoneread
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (14)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
apps/worker/worker-configuration.d.ts:2212
exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
apps/worker/worker-configuration.d.ts:4647
exec(query: string): Promise<D1ExecResult>;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
apps/worker/.dev.vars.example
.dev.vars.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
apps/worker/src/test/auth.test.ts:187
redirectTo: "http://127.0.0.1:4305/oauth/callback?code=c",
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
apps/worker/src/utils/apisHandler.ts:96
atob(c.req.query("state") as string),
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
apps/worker/src/utils/workersOAuthUtils.ts:18
const jsonString = atob(encoded);
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
apps/worker/src/utils/workersOAuthUtils.ts:123
const payload = atob(base64Payload); // Assuming payload is base64 encoded JSON string
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
apps/worker/worker-configuration.d.ts:197
atob(data: string): string;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
apps/worker/worker-configuration.d.ts:283
declare function atob(data: string): string;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/worker/package.json
@cloudflare/workers-oauth-provider, agents, google-tag-manager-mcp-core, hono, zod, @types/node, typescript, vitest
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@changesets/cli, @eslint/js, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, eslint-config-prettier, eslint-plugin-prettier, prettier
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/cli/package.json
@modelcontextprotocol/server, google-tag-manager-mcp-core, zod, @types/node, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/core/package.json
@googleapis/tagmanager, @modelcontextprotocol/client, @modelcontextprotocol/server, @types/node, typescript, vitest, zod
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 5e97b0d78c4efull audit observations/trust-audit/mcp-server/stape-io__google-tag-manager.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-065e97b0d78c4eBLOCKD69first audit
06

Questions

What is the Google Tag Manager MCP server?

MCP server for Google Tag Manager

What tools does Google Tag Manager expose?

21 in total: 20 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Google Tag Manager safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Google Tag Manager need?

No credential environment variables were found in its source, so it appears to need none.

How does Google Tag Manager run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as google-tag-manager-mcp-core at 3.0.0.

How current is this page?

The grade is for one exact copy of the source (5e97b0d78c4e), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement