MCPLow riskUnclaimed
Cost Guard MCP
Pre-flight query cost and result-size guardrails for AI agents on BigQuery, Snowflake, Databricks
mcpsmithsmcpsmiths/cost-guard-mcp
server.json
{
"$schema": "https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json",
"name": "io.github.mcpsmiths/cost-guard-mcp",
"description": "Pre-flight query cost and result-size guardrails for AI agents on BigQuery, Snowflake, Databricks",
"title": "Cost Guard MCP",
"repository": {
"url": "https://github.com/mcpsmiths/cost-guard-mcp",
"source": "github"
},
"version": "0.3.2",
"packages": [
{
"registryType": "pypi",
"identifier": "cost-guard-mcp",
"version": "0.3.2",
"transport": {
"type": "stdio"
},
"environmentVariables": [
{
"description": "BigQuery: path to a service-account key file (Application Default Credentials). Required to use the bigquery engine.",
"isSecret": true,
"name": "GOOGLE_APPLICATION_CREDENTIALS"
},
{
"description": "Snowflake: account identifier. Required to use the snowflake engine.",
"name": "SNOWFLAKE_ACCOUNT"
},
{
"description": "Snowflake: username. Required to use the snowflake engine.",
"name": "SNOWFLAKE_USER"
},
{
"description": "Snowflake: role to assume. Required to use the snowflake engine; has no default and must never be ACCOUNTADMIN.",
"name": "SNOWFLAKE_ROLE"
},
{
"description": "Snowflake: path to an RSA private key file for key-pair auth (preferred over SNOWFLAKE_PASSWORD). Either this or SNOWFLAKE_PASSWORD is required to use the snowflake engine.",
"isSecret": true,
"name": "SNOWFLAKE_PRIVATE_KEY_PATH"
},
{
"description": "Snowflake: passphrase for an encrypted SNOWFLAKE_PRIVATE_KEY_PATH key file, if the key is encrypted.",
"isSecret": true,
"name": "SNOWFLAKE_PRIVATE_KEY_PASSPHRASE"
},
{
"description": "Snowflake: password (discouraged; prefer SNOWFLAKE_PRIVATE_KEY_PATH). Either this or SNOWFLAKE_PRIVATE_KEY_PATH is required to use the snowflake engine.",
"isSecret": true,
"name": "SNOWFLAKE_PASSWORD"
},
{
"description": "Databricks: SQL warehouse server hostname (e.g. my-workspace.cloud.databricks.com, no scheme, no trailing slash). Required to use the databricks engine.",
"name": "DATABRICKS_SERVER_HOSTNAME"
},
{
"description": "Databricks: SQL warehouse HTTP path (from the warehouse's Connection Details tab, e.g. /sql/1.0/warehouses/<warehouse-id>). Required to use the databricks engine.",
"name": "DATABRICKS_HTTP_PATH"
},
{
"description": "Databricks: personal access token (simplest auth option). Either this or DATABRICKS_CLIENT_ID + DATABRICKS_CLIENT_SECRET is required to use the databricks engine.",
"isSecret": true,
"name": "DATABRICKS_TOKEN"
},
{
"description": "Databricks: OAuth machine-to-machine service-principal client ID (preferred for automated use). Requires DATABRICKS_CLIENT_SECRET as well.",
"name": "DATABRICKS_CLIENT_ID"
},
{
"description": "Databricks: OAuth machine-to-machine service-principal client secret. Requires DATABRICKS_CLIENT_ID as well.",
"isSecret": true,
"name": "DATABRICKS_CLIENT_SECRET"
}
]
}
]
}Permissions
DeclaredDetected
Runs code—
pythonInstalls—
pypi:cost-guard-mcp@0.3.2Runs install scripts—None
NetworkNoneNone
Needs credentials
DATABRICKS_CLIENT_SECRETDATABRICKS_TOKENGOOGLE_APPLICATION_CREDENTIALSSNOWFLAKE_PASSWORDSNOWFLAKE_PRIVATE_KEY_PASSPHRASESNOWFLAKE_PRIVATE_KEY_PATHDATABRICKS_CLIENT_SECRETDATABRICKS_TOKENGOOGLE_APPLICATION_CREDENTIALSSNOWFLAKE_PASSWORDSNOWFLAKE_PRIVATE_KEY_PASSPHRASESNOWFLAKE_PRIVATE_KEY_PATHOutside the workspace—None
Agent tools—None
Checks
Low risk · Nothing worth a warning was found.
Not reviewed by a person · Checked by rules; the model review is not switched on yet.
Versions
- #10.3.2latestOct 7, 2026
Cost Guard MCPOpen in Codeg