BoundBench

Google Analytics MCP

Local stdio MCP server exposing read-only Google Analytics Admin and Data API tools (account summaries, property details, core, realtime, funnel and conversions reports).

github.com/googleanalytics/google-analytics-mcp · 2026-10-05 · 75c0e1b

Defense-in-depth score

6.4 / 10

Moderate

A small, read-only server: every tool is a Google Analytics read call, and the credential is requested with the analytics read-only scope only, so a misused session can read analytics data but cannot change anything. It runs no code, loads no workspace files and keeps no memory. Its gaps are around visibility: tools carry no read-only labels for the host, report values that outsiders can write into a property come back unmarked, and the server keeps no record of the calls it makes and sets no limits of its own.

Criteria

C1 Identity & least privilege

Strong 0.75 / 1.00

The server has no credential of its own: it uses the Google Application Default Credentials found in the operator's environment, but it asks for them with only the Google Analytics read-only scope, and all four API clients share that one narrowed credential. Every tool only reads (account lists, property details, reports), so even a misused session can read analytics data but not change any account, property or setting. The read-only scope is a constant in code that no tool or input can change. Access still spans every Google Analytics account and property the signed-in user can see; there is no allowlist of properties.

C2 Approval gates

Moderate 0.53 / 1.00

The MCP host, not this server, decides what to approve, so this rates what the server gives the host. All nine tools only read data, and nothing in the code can create, change or delete anything in Google Analytics, so there is nothing consequential for an approval to miss. However, no tool carries read-only or destructive labels, so a host cannot tell from the tool list that they are safe to auto-approve.

C3 Tool & action scoping

Moderate 0.60 / 1.00

Each tool is narrow and purpose-built (list accounts, get a property, run a report) rather than a general HTTP or query tool. The property ID is checked in code to be a number or 'properties/<number>' before it is used, and the rest of the arguments are converted into typed Google API request objects, but dimension names, filters and row limits are passed through for Google's API to validate. There is no server-side cap on rows per report or allowlist of properties. The default tool set is read-only and cannot be extended at runtime.

C4 Code-execution isolation

N/A · full credit 1.00 / 1.00

The server never interprets model-written text as code: there is no shell, eval, template or script execution. The only process-related code wraps the Google auth library's own gcloud lookup so that it does not inherit the server's stdio; it takes no input from the model.

C5 Untrusted input blast radius

Moderate 0.60 / 1.00

Report results can include text that outsiders control, such as page titles, page paths, campaign names and event names sent to a property by visitors or anyone holding its public measurement ID. The server returns them as structured JSON (headers, rows, metadata) but does not mark any value as untrusted. Its tool descriptions contain usage guidance only. Because the server can only read analytics data and send requests to Google's APIs, a hijacked model can read analytics data through it but cannot use it to send data elsewhere or change anything; leaking or acting would need other tools in the host.

C6 Memory, context & configuration integrity

N/A · full credit 1.00 / 1.00

The server keeps no memory, retrieval store or conversation history, writes no files and loads no .env or instruction files from the working directory. Credentials and project settings come only from the standard Google auth chain in the operator's environment.

C7 Third-party extensions

N/A · full credit 1.00 / 1.00

The server loads no plugins, launches no other MCP servers and downloads no code or models at runtime; its nine tools are fixed in the package.

C8 Secrets & sensitive-data protection

Minimal 0.47 / 1.00

The server never handles a key itself: credentials are loaded by the Google auth library, attached to API calls inside the client libraries, and never placed in tool output. There is no telemetry, and successful calls are not logged. There is also no masking or redaction anywhere; tool errors are passed back to the model and stderr as the raw exception text. The credential in use is narrowed to read-only analytics access, but the ADC file it comes from is a long-lived grant (the README's sample login also adds the cloud-platform scope).

C9 Audit & traceability

Minimal 0.13 / 1.00

The server keeps no record of what it did. Successful tool calls are not logged at all; only failed calls print a single unstructured line with the tool name and error to stderr, which the MCP host may or may not keep. There are no timestamps, arguments, caller identity or durable storage, so an incident could not be reconstructed from this server.

C10 Limits & kill switch

Minimal 0.30 / 1.00

The server sets no timeouts, size caps, rate limits or concurrency limits of its own. Report tools accept an optional row limit chosen by the model, and Google's Analytics APIs enforce their own per-request row maximum and per-property quotas, which bound how much any session can pull. Calls run in worker threads that cannot be cancelled once started, and account listings page through every result.