MCP server for Google Search Console, enabling querying search performance, listing properties, and inspecting URL indexing status from MCP-compatible clients.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.GOOGLE_CLIENT_ID— Set and GOOGLE_CLIENT_SECRET before auth (see [Google Cloud setup](#google-cloud-setup)).GOOGLE_CLIENT_SECRET— Set GOOGLE_CLIENT_ID and before auth (see [Google Cloud setup](#google-cloud-setup)).GOOGLE_LOGIN_HINT— No Pre-fill email in the OAuth browser sign-inGSC_TOKEN_PATH— The auth flow opens a browser on port 3336. Tokens are saved to ~/.config/gsc-mcp/tokens.json by default (override with ).[](https://m8ven.ai/mcp/lelantvaris-gsc-mcp-server-1hshvr)