RedashSAFE
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Model Context Protocol (MCP) server for integrating Redash with AI assistants like Claude.
Features
- Connect to Redash instances via the Redash API
- List available queries and dashboards as resources
- Execute queries and retrieve results
- Execute saved parameterized queries with typed values and saved defaults
- Create and manage queries (create, update, archive)
- Manage query parameters, dashboard parameters, and widget parameter mappings
- Inspect and update dashboard widget layouts and grid positions
- List data sources for query creation
- Get dashboard details and visualizations
- Update chart visualization options with Redash chart-specific settings
Prerequisites
- Node.js (v22.13 or later)
- Corepack (included with Node.js 22; it selects the pnpm version pinned in
package.json) - Access to a Redash instance
- Redash API key
Environment Variables
The server requires the following environment variables:
REDASH_URL: Your Redash instance URL (e.g., https://redash.example.com)REDASH_API_KEY: Your Redash API key
Optional variables:
REDASH_TIMEOUT: Timeout for API requests in milliseconds (default: 30000)REDASH_MAX_RESULTS: Maximum number of results to return (default: 1000)REDASH_EXTRA_HEADERS: Extra HTTP headers to include with every Redash request. Accepts either a JSON object string or a semicolon/comma-separated list ofkey=valuepairs.REDASH_SOCKS_PROXY: SOCKS proxy URL for routing requests through a proxy (e.g.,socks5h://localhost:1080). Usesocks5h://(withh) to delegate DNS resolution to the proxy, which is required for internal hostnames that don't resolve on the local machine.MCP_TRANSPORT: MCP transport to use. Supported values arestdio,http, andstreamable-http(default:stdio).- `MCP
8aeec24b0323OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add redash-mcp --env REDASH_API_KEY=${REDASH_API_KEY} -- npx -y @suthio/[email protected]{
"mcpServers": {
"redash-mcp": {
"command": "npx",
"args": [
"-y",
"@suthio/[email protected]"
],
"env": {
"REDASH_API_KEY": "${REDASH_API_KEY}"
}
}
}
}Exposed tools (5)
5 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Executive | read | Dashboard ID: 22 |
Revenue | read | Monthly revenue |
analytics.events | read | GA4 export |
echo | read | |
fail | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
# OTEL_EXPORTER_OTLP_ENDPOINT=http://127.0.0.1:4318
.tagpr
const { initializeTelemetry, shutdownTelemetry } = await import("../../dist/telemetry.js");const { startHttpServer } = await import("../../dist/httpServer.js");const { TelemetryMcpServer } = await import("../../dist/mcpTelemetry.js");This starts `POST http://127.0.0.1:3000/mcp` by default. CLI flags override environment variables:
| Local MCP client | `http://127.0.0.1:3000/mcp` | `127.0.0.1` | `localhost`, `127.0.0.1`, `[::1]` |
`GET http://127.0.0.1:3000/healthz` returns `200 OK` with the body `ok` for lightweight health checks. It uses the same Host and Origin allowlists as the MCP endpoint and does not contact Redash. If `
| An OpenTelemetry Collector receiving all three signals | `OTEL_EXPORTER_OTLP_ENDPOINT=http://127.0.0.1:4318` | Traces, metrics, and logs at the Collector OTLP/HTTP receiver |
@hono/node-server, @modelcontextprotocol/hono, @modelcontextprotocol/server, @opentelemetry/api, @opentelemetry/api-logs, @opentelemetry/exporter-logs-otlp-grpc, @opentelemetry/exporter-logs-otlp-http
This starts `POST http://127.0.0.1:3000/mcp` by default. CLI flags override environment variables:
HTTP mode is stateless: the server does not issue `Mcp-Session-Id`, does not provide a standalone GET SSE stream, and handles each `POST /mcp` with a fresh MCP server instance. Both current MCP client
Gates applied: no_behavioural_pass.
8aeec24b0323full audit observations/trust-audit/mcp-server/suthio__redash.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 8aeec24b0323 | SAFE | B | 89 | first audit |
Questions
What tools does Redash expose?
5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Redash safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Redash need?
It reads REDASH_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Redash run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @suthio/redash-mcp at 0.0.17.
How current is this page?
The grade is for one exact copy of the source (8aeec24b0323), read on 2026-10-07. The repository is watched and re-audited when it changes.