VictoriaLogsBLOCK
The implementation of Model Context Protocol (MCP) server for VictoriaLogs.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/VictoriaMetrics/mcp-victorialogs/releases)
The implementation of Model Context Protocol (MCP) server for VictoriaLogs.
This provides access to your VictoriaLogs instance and seamless integration with VictoriaLogs APIs and documentation. It can give you a comprehensive interface for logs, observability, and debugging tasks related to your VictoriaLogs instances, enable advanced automation and interaction capabilities for engineers and tools.
Features
This MCP server allows you to use almost all read-only APIs of VictoriaLogs, i.e. all functions available in Web UI:
- Querying logs and exploring logs data
- Showing parameters of your VictoriaLogs instance
- Listing available streams, fields, field values
- Query statistics for the logs as
3eca3d7b4ee3OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-victorialogs:${VERSION} --env VL_INSTANCE_BEARER_TOKEN=${VL_INSTANCE_BEARER_TOKEN} -- docker run -i --rm ghcr.io/victoriametrics/mcp-victorialogs:${VERSION}:NoneTrust audit
BLOCKgrade F · trust 43/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (8 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
func (d *DFA) eval(bytes []uint8) Distance {func Exec(argv0 string, argv []string, envv []string) error {func Exec(argv0 string, argv []string, envv []string) error {{257, "EDC5257I", "Function cannot be called in the child process of a fork() from a multithreaded process until exec() is called."},Time zone GMT (UTC)
editions_defaults.binpb
BPX4PTR = 320 // ptrace
$2 ~ /^(O|F|[ES]?FD|NAME|S|PTRACE|PT|PIOD|TFD)_/ ||
func ptrace(request int, pid int, addr uintptr, data uintptr) error {func ptrace(request int, pid int, addr uintptr, data uintptr) (err error) {func PtraceAttach(pid int) (err error) { return ptrace(PT_ATTACH, pid, 0, 0) }".,;%+-E׉∞NaN:\u00a0\u200e%\u200e\u200e+\u200e-ليس\u00a0رقمًا٪NDТерхьаш" +
"იZMdMсан\u00a0емес¤¤¤сан\u00a0эмесບໍ່\u200bແມ່ນ\u200bໂຕ\u200bເລກNSဂဏန်" +
"းမဟုတ်သောННне\u00a0числочыыһыла\u00a0буотах·10^epilohosan\u00a0dälTFЕs" +
"on\u00a0emasҳақиқий\u00a0сон\u00a0эмас非數值非数值٫٬؛٪\u061c\u061c+\u061c-اس؉ل" +
.golangci.yml
.goreleaser.yaml
.wwhrd.yml
.drone.yml
.gitmodules
curl http://0.0.0.0:9428/debug/pprof/heap > mem.pprof
curl http://0.0.0.0:9428/debug/pprof/profile > cpu.pprof
curl http://0.0.0.0:9429/debug/pprof/heap > mem.pprof
curl http://0.0.0.0:9429/debug/pprof/profile > cpu.pprof
Datasource address supporting log stats APIs, which can be a single VictoriaLogs node or a proxy in front of VictoriaLogs. Supports an address in the form of an IP address with a port (e.g., http://12
Gates applied: no_behavioural_pass.
3eca3d7b4ee3full audit observations/trust-audit/mcp-server/victoriametrics-community__victorialogs.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 3eca3d7b4ee3 | BLOCK | F | 43 | first audit |
Questions
What is the VictoriaLogs MCP server?
The implementation of Model Context Protocol (MCP) server for VictoriaLogs.
Is VictoriaLogs safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (43/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does VictoriaLogs need?
It reads VL_INSTANCE_BEARER_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does VictoriaLogs run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as mcp-victorialogs-web at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (3eca3d7b4ee3), read on 2026-10-08. The repository is watched and re-audited when it changes.