PrometheusCAUTION
MCP server for LLMs to interact with Prometheus
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/tjhop/prometheus-mcp-server/blob/master/LICENSE) [](https://goreportcard.com/report/github.com/tjhop/prometheus-mcp-server) [](https://github.com/tjhop/prometheus-mcp-server/actions/workflows/golangci-lint.yml) [](https://github.com/tjhop/prometheus-mcp-server/releases/latest) [](https://github.com/tjhop/prometheus-mcp-server/releases/latest)
About
This is an MCP server to allow LLMs to interact with a running Prometheus instance via the API to do things like generate and execute promql queries, list and analyze metrics, etc.
Demos and Examples
Asking Claude to Investigate Slow Queries
The prompt used was:
querying my metrics is slow, can you help me figure out why?
[](https://asciinema.org/a/8KxZgJxrXXX2zjwwDRSP4UtqL)
Investigate metrics produced by the MCP server itself and suggest recording rules for SLOs
The prompt used was:
use the tools from the prometheus mcp server to investigate the metrics from the mcp server and suggest prometheus recording rules for SLOs
[](https://asciinema.org/a/av3WhfD122A1HHOq2d4SEZgMn)
Summarize Prometheus metric/label naming best practices
The prom
9e60aa18b3c2OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add prometheus-mcp:v${VERSION} -- docker run -i --rm docker.io/prom/prometheus-mcp:v${VERSION}:NoneTrust audit
CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (18)
assets
).Default("http://127.0.0.1:9090").String().envrc
.golangci.yml
.promu.yml
.yamllint
.helmignore
"docs/../../../etc/passwd": "malicious",
_, err = fs.ReadFile(memFS, "../../../etc/passwd")
--prometheus.url="http://127.0.0.1:9090"
PrometheusURL: "http://127.0.0.1:9090",
PrometheusURL: "http://127.0.0.1:9090",
- stdio, the in-memory `mcptest` harness, and the HTTP handler all negotiate the new revision by default; legacy clients that send `initialize` are still served on every transport. HTTP is stateless o
images/demo-usage-with-prometheus-demo-server.gif
images/gemini_docs_search.gif
images/gemini_slo.gif
images/logo.png
Gates applied: no_behavioural_pass.
9e60aa18b3c2full audit observations/trust-audit/mcp-server/tjhop__prometheus-6.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 9e60aa18b3c2 | CAUTION | B | 88 | first audit |
Questions
What is the Prometheus MCP server?
MCP server for LLMs to interact with Prometheus
Is Prometheus safe to connect to an agent?
With care. The audit graded it B (88/100) and found 18 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Prometheus need?
No credential environment variables were found in its source, so it appears to need none.
How does Prometheus run?
It speaks stdio and streamable-http, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (9e60aa18b3c2), read on 2026-10-08. The repository is watched and re-audited when it changes.