C1 Identity & least privilege
Strong 0.75 / 1.00
The server has no credential of its own: it uses the Google Application Default Credentials found in the operator's environment, but it asks for them with only the Google Analytics read-only scope, and all four API clients share that one narrowed credential. Every tool only reads (account lists, property details, reports), so even a misused session can read analytics data but not change any account, property or setting. The read-only scope is a constant in code that no tool or input can change. Access still spans every Google Analytics account and property the signed-in user can see; there is no allowlist of properties.
C2 Approval gates
Moderate 0.53 / 1.00
The MCP host, not this server, decides what to approve, so this rates what the server gives the host. All nine tools only read data, and nothing in the code can create, change or delete anything in Google Analytics, so there is nothing consequential for an approval to miss. However, no tool carries read-only or destructive labels, so a host cannot tell from the tool list that they are safe to auto-approve.
C3 Tool & action scoping
Moderate 0.60 / 1.00
Each tool is narrow and purpose-built (list accounts, get a property, run a report) rather than a general HTTP or query tool. The property ID is checked in code to be a number or 'properties/<number>' before it is used, and the rest of the arguments are converted into typed Google API request objects, but dimension names, filters and row limits are passed through for Google's API to validate. There is no server-side cap on rows per report or allowlist of properties. The default tool set is read-only and cannot be extended at runtime.
C4 Code-execution isolation
N/A · full credit 1.00 / 1.00
The server never interprets model-written text as code: there is no shell, eval, template or script execution. The only process-related code wraps the Google auth library's own gcloud lookup so that it does not inherit the server's stdio; it takes no input from the model.
C5 Untrusted input blast radius
Moderate 0.60 / 1.00
Report results can include text that outsiders control, such as page titles, page paths, campaign names and event names sent to a property by visitors or anyone holding its public measurement ID. The server returns them as structured JSON (headers, rows, metadata) but does not mark any value as untrusted. Its tool descriptions contain usage guidance only. Because the server can only read analytics data and send requests to Google's APIs, a hijacked model can read analytics data through it but cannot use it to send data elsewhere or change anything; leaking or acting would need other tools in the host.
C6 Memory, context & configuration integrity
N/A · full credit 1.00 / 1.00
The server keeps no memory, retrieval store or conversation history, writes no files and loads no .env or instruction files from the working directory. Credentials and project settings come only from the standard Google auth chain in the operator's environment.
C7 Third-party extensions
N/A · full credit 1.00 / 1.00
The server loads no plugins, launches no other MCP servers and downloads no code or models at runtime; its nine tools are fixed in the package.
C8 Secrets & sensitive-data protection
Minimal 0.47 / 1.00
The server never handles a key itself: credentials are loaded by the Google auth library, attached to API calls inside the client libraries, and never placed in tool output. There is no telemetry, and successful calls are not logged. There is also no masking or redaction anywhere; tool errors are passed back to the model and stderr as the raw exception text. The credential in use is narrowed to read-only analytics access, but the ADC file it comes from is a long-lived grant (the README's sample login also adds the cloud-platform scope).
C9 Audit & traceability
Minimal 0.13 / 1.00
The server keeps no record of what it did. Successful tool calls are not logged at all; only failed calls print a single unstructured line with the tool name and error to stderr, which the MCP host may or may not keep. There are no timestamps, arguments, caller identity or durable storage, so an incident could not be reconstructed from this server.
C10 Limits & kill switch
Minimal 0.30 / 1.00
The server sets no timeouts, size caps, rate limits or concurrency limits of its own. Report tools accept an optional row limit chosen by the model, and Google's Analytics APIs enforce their own per-request row maximum and per-property quotas, which bound how much any session can pull. Calls run in worker threads that cannot be cancelled once started, and account listings page through every result.