takeokunn/metabase-mcp (takeokunn/metabase-mcp) is an MCP server listed on the M8ven Trust Index. It scores 44 out of 100, grade D. It declares 429 tools. No publisher has claimed this listing.
A Model Context Protocol server for Metabase that enables AI assistants to interact with Metabase instances, providing 418 tools across 58 categories for database, card, dashboard, collection, user, permissions, and more management.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
takeokunn
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
create_action_public_linkCreate a public sharing link for an action in Metabase (returns UUID)
create_actionCreate a new action in Metabase
delete_action_public_linkDelete a public sharing link from an action in Metabase
delete_actionDelete an action from Metabase
execute_actionExecute an action with parameters in Metabase
get_action_execute_formGet the execute form fields for an action in Metabase
get_actionGet an action by ID from Metabase
list_actionsGet list of actions in Metabase, optionally filtered by model ID
list_public_actionsList all actions with public sharing links in Metabase
update_actionUpdate an existing action in Metabase
add_recent_activityAdd an item to recent activity in Metabase
get_most_recently_viewed_dashboardGet the most recently viewed dashboard in Metabase
list_popular_itemsList popular items in Metabase
list_recent_viewsList recently viewed items in Metabase
list_recentsList recent items in Metabase with optional context filter
delete_alert_subscriptionDelete subscription to an alert in Metabase
get_alertGet details of a specific alert in Metabase
list_alertsList all alerts in Metabase
get_analytics_statsRetrieve anonymous usage statistics from Metabase. Returns aggregated analytics data about how Metabase is being used.
count_api_keysGet the count of all API keys in Metabase
create_api_keyCreate a new API key in Metabase
delete_api_keyDelete an API key from Metabase
list_api_keysList all API keys in Metabase
regenerate_api_keyRegenerate an API key in Metabase
update_api_keyUpdate an existing API key in Metabase
get_xray_database_candidatesGet X-ray dashboard candidates for a database in Metabase
get_xray_entity_cell_compareGet a comparison x-ray automagic dashboard for a specific cell of an entity in Metabase
get_xray_entity_cell_rule_compareGet a comparison x-ray automagic dashboard for a specific cell of an entity with a rule applied in Metabase
get_xray_entity_cell_ruleGet an x-ray automagic dashboard for a specific cell of an entity with a rule applied in Metabase
get_xray_entity_cellGet an x-ray automagic dashboard for a specific cell of an entity in Metabase
get_xray_entity_compareGet a comparison x-ray automagic dashboard for an entity in Metabase
get_xray_entity_query_metadataGet query metadata for an x-ray automagic dashboard entity in Metabase
get_xray_entity_rule_compareGet a comparison x-ray automagic dashboard for an entity with a rule applied in Metabase
get_xray_entity_ruleGet an x-ray automagic dashboard for an entity with a rule applied in Metabase
get_xray_entityGet an x-ray automagic dashboard for any entity in Metabase
get_xray_model_indexGet an x-ray automagic dashboard for a model index by primary key in Metabase
create_bookmarkCreate a new bookmark for a card, dashboard, or collection in Metabase
delete_bookmarkDelete a bookmark for a card, dashboard, or collection from Metabase
list_bookmarksGet list of all bookmarks for the current user in Metabase
reorder_bookmarksReorder bookmarks by providing the new ordering for the current user
get_bug_reporting_detailsGet bug reporting details and diagnostic information from Metabase
get_connection_pool_detailsGet database connection pool details for bug reporting in Metabase
delete_cache_configRemove the query caching configuration in Metabase
get_cache_configGet the current query caching configuration in Metabase
invalidate_cacheInvalidate cached query results in Metabase
update_cache_configSet the query caching configuration in Metabase
copy_cardCopy an existing card (saved question) in Metabase
create_card_public_linkCreate a public sharing link for a card (saved question) in Metabase (returns UUID)
create_cardCreate a new card (saved question) in Metabase
delete_card_public_linkDelete a public sharing link from a card (saved question) in Metabase
delete_cardDelete a card (saved question) from Metabase
execute_card_pivotExecute a card (saved question) as a pivot table query in Metabase
execute_cardExecute a card (saved question) and return the query results
export_card_queryExport a card (saved question) query result in a specified format (csv, json, xlsx, pdf) in Metabase
get_card_dashboardsGet dashboards that contain a specific card in Metabase
get_card_metadataGet query metadata (columns, types, etc.) for a card (saved question)
get_card_param_remappingGet remapping for a parameter of a card in Metabase
get_card_param_valuesGet possible values for a card (saved question) filter parameter in Metabase
get_card_seriesGet related series data for a card (saved question) in Metabase
get_cardGet a single card (saved question) by ID from Metabase
list_cardsGet list of cards (saved questions) in Metabase, optionally filtered by collection
list_embeddable_cardsList all cards (saved questions) available for embedding in Metabase (admin only)
list_public_cardsList all cards (saved questions) with public sharing links in Metabase (admin only)
move_cards_to_collectionMove multiple cards to a collection in Metabase
search_card_param_valuesSearch possible values for a card (saved question) filter parameter in Metabase
update_cardUpdate an existing card (saved question) in Metabase
bulk_move_cardsMove multiple cards to a collection in Metabase
list_cards_in_dashboardsGet dashboards that contain the specified cards in Metabase
create_channelCreate a new notification channel in Metabase
get_channelGet a specific notification channel by ID in Metabase
list_channelsList all notification channels in Metabase
test_channelTest a notification channel configuration in Metabase
update_channelUpdate an existing notification channel in Metabase
cancel_cloud_migrationCancel an in-progress cloud migration in Metabase
get_cloud_migrationGet the current cloud migration status in Metabase
initiate_cloud_migrationInitiate a cloud migration to Metabase Cloud
create_collectionCreate a new collection (folder) in Metabase
delete_collectionArchive (soft-delete) a collection in Metabase
get_collection_dashboard_question_candidatesGet dashboard question candidates from a collection in Metabase
get_collection_itemsGet items (cards, dashboards, etc.) within a collection (supports "root" for root collection)
get_collection_treeGet the hierarchical tree structure of all collections in Metabase
get_collectionGet a single collection by ID from Metabase (supports "root" for root collection)
get_root_collection_itemsGet items (cards, dashboards, etc.) within the root collection in Metabase
get_root_collectionGet the root collection from Metabase
get_root_dashboard_question_candidatesGet dashboard question candidates from the root collection in Metabase
get_trash_collectionGet the trash collection from Metabase
hard_delete_collectionPermanently delete a collection in Metabase (cannot be undone)
list_collectionsGet list of all collections (folders) in Metabase
move_collection_dashboard_question_candidatesMove dashboard question candidates from a collection in Metabase
move_root_dashboard_question_candidatesMove dashboard question candidates from the root collection in Metabase
update_collectionUpdate an existing collection in Metabase
add_comment_reactionAdd an emoji reaction to a comment in Metabase
create_commentCreate a new comment on a Metabase model
delete_commentDelete a comment from Metabase
get_comment_mentionsGet comment mentions for the current user in Metabase
list_commentsList comments in Metabase, optionally filtered by model type and ID
update_commentUpdate an existing comment in Metabase
add_dashboard_cardAdd a card to a dashboard in Metabase (v0.49+)
add_dashboard_tabAdd a new tab to a dashboard in Metabase (v0.49+)
copy_dashboardCopy an existing dashboard in Metabase
329 further tools are not listed here. The complete surface is in the source.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
429/429 tools missing one or more hints — create_action_public_link (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); create_action (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); delete_action_public_link (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +426 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Production dependencies are patched
0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.12.0 (high), @modelcontextprotocol/sdk@1.12.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/takeokunn/metabase-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check