npm JavaScript analyzed 0.5.3

@google-cloud/gcloud-mcp

v0.5.3
npm

Model Context Protocol (MCP) Server for interacting with GCP APIs

maintainer
google-admin
license
Apache-2.0
first seen
2026-06-09
last seen
2026-08-14
releases · 30d
0
short id

Drift inferred · capture-to-capture

No drift recorded — single capability capture; advisories appear once its surface changes.

capabilities 4 tools
transport stdio counts 4 tools · 0 res · 0 prompts permission surface via README inference

tools

  • backupdr

    list_backup_vaults

  • gcloud

    run_gcloud_command

  • observability

    list_log_entries

  • storage

    list_objects

skills & danger signals npm-tarball
prompt-surface shipped agent-instruction files + hidden-content / dangerous-code findings — quoted from the analyzed source

analyzed v0.5.3 · analyzer v32 · 2h ago

danger signals1

  • dynamic code execution new Function() package/dist/bundle.js :2942 const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);
code evidence v0.5.3 · npm-tarball
evidence-backed findings quoted directly from the published source artifact — not inferred

code files: 1

filesystem 1

  • fs package/dist/bundle.js :26903 import * as fs from "fs";

shell / exec 1

  • shell package/dist/bundle.js :26899 import * as child_process2 from "child_process";

install hooks 1

  • prepare package/package.json :18 npm run build

declared dependencies 20

  • @modelcontextprotocol/sdk@^1.24.0
  • @types/yargs@^17.0.33
  • yargs@^18.0.0
  • zod@^3.25.76
  • typescript@^5.9.2
  • typescript-eslint@^8.39.0
  • @tsconfig/strictest@^2.0.5
  • @types/node@^24.2.1
  • @typescript-eslint/eslint-plugin@^8.39.0
  • @typescript-eslint/parser@^8.39.0
  • @vitest/coverage-v8@^3.2.4
  • esbuild@^0.27.0
  • eslint@^9.32.0
  • eslint-config-prettier@^10.1.8
  • eslint-plugin-import@^2.32.0
  • eslint-plugin-license-header@^0.8.0
  • eslint-plugin-prettier@^5.5.4
  • prettier@^3.6.2
  • turbo@latest
  • vitest@^3.2.4