Cube Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Cube Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This is a standalone Model Context Protocol (MCP) server for Cube.js, written in TypeScript using the official @cubejs-client/core SDK.
It provides advanced AI assistants (like Claude, Cursor, etc.) with semantic layer visibility and multi-dimensional querying capabilities over your data.
/meta) and explains the available Cubes, Dimensions, and Measures to the LLM./load) with support for Cube query fields like filters, sorting, time dimensions, pagination, timezone, and result truncation.You can run the published MCP server directly without installing it manually:
npx -y @mob999/cube_mcp npm install npm run buildThis compiles the TypeScript code into the `dist/` directory.
npm testnpm run lintexecute_query supports:
measuresdimensionsfilterstimeDimensionssegmentslimitrowLimitoffsetordertimezonerenewQueryungroupedresponseFormattotalExample:
{
"entity_name": "Components",
"measures": ["Components.count"],
"dimensions": ["Components.id"],
"timeDimensions": [
{
"dimension": "Components.createdAt",
"granularity": "day",
"dateRange": ["2026-01-01", "2026-01-31"]
}
],
"order": [
{ "member": "Components.count", "direction": "desc" },
{ "member": "Components.id", "direction": "asc" }
],
"limit": 100,
"rowLimit": 500,
"offset": 0,
"timezone": "UTC",
"responseFormat": "compact",
"total": true
}By default, the server expects your Cube.js API to be available at http://localhost:4000/cubejs-api/v1.
You can override this by setting the CUBEJS_API_URL environment variable.
To integrate this semantic layer into Cursor or any other MCP-compatible IDE/Agent, configure it as a stdio tool.
Example `mcp.json` / Client Configuration:
{
"mcpServers": {
"CubeSemanticLayer": {
"command": "npx",
"args": ["-y", "@mob999/cube_mcp"],
"env": {
"CUBEJS_API_URL": "http://localhost:4000/cubejs-api/v1"
}
}
}
}Note: The `-y` flag allows `npx` to automatically download and run the package without prompting for confirmation.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.