MCP Server for GCP environment for interacting with various Observability APIs.
Drift inferred · capture-to-capture
No drift recorded — single capability capture; advisories appear once its surface changes.
transport stdio counts 4 tools · 0 res
· 0 prompts
permission surface via README inference
tools
-
backupdr
list_backup_vaults
-
gcloud
run_gcloud_command
-
observability
list_log_entries
-
storage
list_objects
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed v0.2.3 · analyzer v32 · 7h ago
danger signals2
- dynamic code execution new Function() package/dist/bundle.js :2942
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode); - over-broad OAuth scope https://www.googleapis.com/auth/cloud-platform
expected for this server's purpose
package/dist/bundle.js :26580
scopes: "https://www.googleapis.com/auth/cloud-platform"
evidence-backed
findings quoted directly from the published source artifact — not inferred
code files: 1
filesystem 1
- fs package/dist/bundle.js :28153
import { readdirSync, statSync } from "fs";
shell / exec 1
- shell package/dist/bundle.js :28139
return String(string3).normalize().replaceAll("\r\n", "\n").split("\n").map((line) => exec(line, columns, options)).join("\n");
install hooks 1
- prepare package/package.json :19
npm run build
declared dependencies 24
- @modelcontextprotocol/sdk@^1.26.0
- google-auth-library@^10.1.0
- googleapis@^171.0.0
- @types/yargs@^17.0.33
- yargs@^18.0.0
- zod@^3.25.76
- typescript@^5.9.2
- typescript-eslint@^8.39.0
- @tsconfig/strictest@^2.0.5
- @types/node@^24.2.1
- @typescript-eslint/eslint-plugin@^8.39.0
- @typescript-eslint/parser@^8.39.0
- @vitest/coverage-v8@^3.2.4
- esbuild@^0.27.0
- eslint@^9.32.0
- eslint-config-prettier@^10.1.8
- eslint-plugin-import@^2.32.0
- eslint-plugin-license-header@^0.8.0
- eslint-plugin-prettier@^5.5.4
- prettier@^3.6.2
- turbo@latest
- vitest@^3.2.4
- memfs@^4.36.0
- ts-node@^10.9.2