takeokunn/metabase-mcp (takeokunn/metabase-mcp) is an MCP server listed on the M8ven Trust Index. It scores 44 out of 100, grade D. It declares 429 tools. No publisher has claimed this listing.

D
Caution
44/100

takeokunn/metabase-mcp

A Model Context Protocol server for Metabase that enables AI assistants to interact with Metabase instances, providing 418 tools across 58 categories for database, card, dashboard, collection, user, permissions, and more management.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

takeokunn

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Known vulnerabilities in dependencies: 3 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
// tools this server exposes429 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

create_action_public_link

Create a public sharing link for an action in Metabase (returns UUID)

create_action

Create a new action in Metabase

delete_action_public_link

Delete a public sharing link from an action in Metabase

delete_action

Delete an action from Metabase

execute_action

Execute an action with parameters in Metabase

get_action_execute_form

Get the execute form fields for an action in Metabase

get_action

Get an action by ID from Metabase

list_actions

Get list of actions in Metabase, optionally filtered by model ID

list_public_actions

List all actions with public sharing links in Metabase

update_action

Update an existing action in Metabase

add_recent_activity

Add an item to recent activity in Metabase

get_most_recently_viewed_dashboard

Get the most recently viewed dashboard in Metabase

list_popular_items

List popular items in Metabase

list_recent_views

List recently viewed items in Metabase

list_recents

List recent items in Metabase with optional context filter

delete_alert_subscription

Delete subscription to an alert in Metabase

get_alert

Get details of a specific alert in Metabase

list_alerts

List all alerts in Metabase

get_analytics_stats

Retrieve anonymous usage statistics from Metabase. Returns aggregated analytics data about how Metabase is being used.

count_api_keys

Get the count of all API keys in Metabase

create_api_key

Create a new API key in Metabase

delete_api_key

Delete an API key from Metabase

list_api_keys

List all API keys in Metabase

regenerate_api_key

Regenerate an API key in Metabase

update_api_key

Update an existing API key in Metabase

get_xray_database_candidates

Get X-ray dashboard candidates for a database in Metabase

get_xray_entity_cell_compare

Get a comparison x-ray automagic dashboard for a specific cell of an entity in Metabase

get_xray_entity_cell_rule_compare

Get a comparison x-ray automagic dashboard for a specific cell of an entity with a rule applied in Metabase

get_xray_entity_cell_rule

Get an x-ray automagic dashboard for a specific cell of an entity with a rule applied in Metabase

get_xray_entity_cell

Get an x-ray automagic dashboard for a specific cell of an entity in Metabase

get_xray_entity_compare

Get a comparison x-ray automagic dashboard for an entity in Metabase

get_xray_entity_query_metadata

Get query metadata for an x-ray automagic dashboard entity in Metabase

get_xray_entity_rule_compare

Get a comparison x-ray automagic dashboard for an entity with a rule applied in Metabase

get_xray_entity_rule

Get an x-ray automagic dashboard for an entity with a rule applied in Metabase

get_xray_entity

Get an x-ray automagic dashboard for any entity in Metabase

get_xray_model_index

Get an x-ray automagic dashboard for a model index by primary key in Metabase

create_bookmark

Create a new bookmark for a card, dashboard, or collection in Metabase

delete_bookmark

Delete a bookmark for a card, dashboard, or collection from Metabase

list_bookmarks

Get list of all bookmarks for the current user in Metabase

reorder_bookmarks

Reorder bookmarks by providing the new ordering for the current user

get_bug_reporting_details

Get bug reporting details and diagnostic information from Metabase

get_connection_pool_details

Get database connection pool details for bug reporting in Metabase

delete_cache_config

Remove the query caching configuration in Metabase

get_cache_config

Get the current query caching configuration in Metabase

invalidate_cache

Invalidate cached query results in Metabase

update_cache_config

Set the query caching configuration in Metabase

copy_card

Copy an existing card (saved question) in Metabase

create_card_public_link

Create a public sharing link for a card (saved question) in Metabase (returns UUID)

create_card

Create a new card (saved question) in Metabase

delete_card_public_link

Delete a public sharing link from a card (saved question) in Metabase

delete_card

Delete a card (saved question) from Metabase

execute_card_pivot

Execute a card (saved question) as a pivot table query in Metabase

execute_card

Execute a card (saved question) and return the query results

export_card_query

Export a card (saved question) query result in a specified format (csv, json, xlsx, pdf) in Metabase

get_card_dashboards

Get dashboards that contain a specific card in Metabase

get_card_metadata

Get query metadata (columns, types, etc.) for a card (saved question)

get_card_param_remapping

Get remapping for a parameter of a card in Metabase

get_card_param_values

Get possible values for a card (saved question) filter parameter in Metabase

get_card_series

Get related series data for a card (saved question) in Metabase

get_card

Get a single card (saved question) by ID from Metabase

list_cards

Get list of cards (saved questions) in Metabase, optionally filtered by collection

list_embeddable_cards

List all cards (saved questions) available for embedding in Metabase (admin only)

list_public_cards

List all cards (saved questions) with public sharing links in Metabase (admin only)

move_cards_to_collection

Move multiple cards to a collection in Metabase

search_card_param_values

Search possible values for a card (saved question) filter parameter in Metabase

update_card

Update an existing card (saved question) in Metabase

bulk_move_cards

Move multiple cards to a collection in Metabase

list_cards_in_dashboards

Get dashboards that contain the specified cards in Metabase

create_channel

Create a new notification channel in Metabase

get_channel

Get a specific notification channel by ID in Metabase

list_channels

List all notification channels in Metabase

test_channel

Test a notification channel configuration in Metabase

update_channel

Update an existing notification channel in Metabase

cancel_cloud_migration

Cancel an in-progress cloud migration in Metabase

get_cloud_migration

Get the current cloud migration status in Metabase

initiate_cloud_migration

Initiate a cloud migration to Metabase Cloud

create_collection

Create a new collection (folder) in Metabase

delete_collection

Archive (soft-delete) a collection in Metabase

get_collection_dashboard_question_candidates

Get dashboard question candidates from a collection in Metabase

get_collection_items

Get items (cards, dashboards, etc.) within a collection (supports "root" for root collection)

get_collection_tree

Get the hierarchical tree structure of all collections in Metabase

get_collection

Get a single collection by ID from Metabase (supports "root" for root collection)

get_root_collection_items

Get items (cards, dashboards, etc.) within the root collection in Metabase

get_root_collection

Get the root collection from Metabase

get_root_dashboard_question_candidates

Get dashboard question candidates from the root collection in Metabase

get_trash_collection

Get the trash collection from Metabase

hard_delete_collection

Permanently delete a collection in Metabase (cannot be undone)

list_collections

Get list of all collections (folders) in Metabase

move_collection_dashboard_question_candidates

Move dashboard question candidates from a collection in Metabase

move_root_dashboard_question_candidates

Move dashboard question candidates from the root collection in Metabase

update_collection

Update an existing collection in Metabase

add_comment_reaction

Add an emoji reaction to a comment in Metabase

create_comment

Create a new comment on a Metabase model

delete_comment

Delete a comment from Metabase

get_comment_mentions

Get comment mentions for the current user in Metabase

list_comments

List comments in Metabase, optionally filtered by model type and ID

update_comment

Update an existing comment in Metabase

add_dashboard_card

Add a card to a dashboard in Metabase (v0.49+)

add_dashboard_tab

Add a new tab to a dashboard in Metabase (v0.49+)

copy_dashboard

Copy an existing dashboard in Metabase

329 further tools are not listed here. The complete surface is in the source.

// known CVEs in dependencies3 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.12.0GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.12.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.12.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

429/429 tools missing one or more hints — create_action_public_link (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); create_action (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); delete_action_public_link (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +426 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Production dependencies are patched

0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.0 (high), @modelcontextprotocol/sdk@1.12.0 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/takeokunn/metabase-mcp?variant=verified)](https://m8ven.ai/mcp/takeokunn/metabase-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: 472bf1b49b7187dd36f675fb88ecb3bfdfd9b53c
code hash: f3aecceef8b7e89448d8a797cb541fd7818de0e453d3a28fe9a8333d9dc5081a
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client