by stape-io
MCP server for Google Tag Manager
# Add to your Claude Code skills
git clone https://github.com/stape-io/google-tag-manager-mcp-serverGuides for using mcp servers skills like google-tag-manager-mcp-server.
Last scanned: 5/30/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@ai-sdk/gateway: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@ai-sdk/provider-utils: @ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@eslint/plugin-kit: @eslint/plugin-kit is vulnerable to Regular Expression Denial of Service attacks through ConfigCommentParser",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@modelcontextprotocol/sdk: Anthropic's MCP TypeScript SDK has a ReDoS vulnerability",
"severity": "high"
},
{
"type": "npm-audit",
"message": "agents: Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ai: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "body-parser: body-parser is vulnerable to denial of service when url encoding is used",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion Regular Expression Denial of Service vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "defu: defu: Prototype pollution via `__proto__` key in defaults argument",
"severity": "high"
},
{
"type": "npm-audit",
"message": "diff: jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch",
"severity": "low"
},
{
"type": "npm-audit",
"message": "eslint: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "flatted: flatted vulnerable to unbounded recursion DoS in parse() revive phase",
"severity": "high"
},
{
"type": "npm-audit",
"message": "gaxios: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "googleapis: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "googleapis-common: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "hono: Hono Improper Authorization vulnerability",
"severity": "high"
},
{
"type": "npm-audit",
"message": "js-yaml: js-yaml has prototype pollution in merge (<<)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "jws: auth0/node-jws Improperly Verifies HMAC Signature",
"severity": "high"
},
{
"type": "npm-audit",
"message": "lodash: Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions",
"severity": "high"
},
{
"type": "npm-audit",
"message": "miniflare: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "path-to-regexp: path-to-regexp vulnerable to Denial of Service via sequential optional groups",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "qs: qs's arrayLimit bypass in comma parsing allows denial of service",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "undici: Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion",
"severity": "high"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "wrangler: Wrangler affected by OS Command Injection in `wrangler pages deploy`",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ws: ws: Uninitialized memory disclosure",
"severity": "medium"
}
],
"status": "WARNING",
"scannedAt": "2026-05-30T15:58:20.815Z",
"npmAuditRan": true,
"pipAuditRan": true
}See how google-tag-manager-mcp-server compares with popular alternatives.
google-tag-manager-mcp-server is an open-source mcp servers skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by stape-io. MCP server for Google Tag Manager. It has 227 GitHub stars.
google-tag-manager-mcp-server returned warnings in SkillsLLM's automated security scan. It has no critical vulnerabilities, but review the flagged issues in the Security Report section before adding it to your workflow.
Clone the repository with "git clone https://github.com/stape-io/google-tag-manager-mcp-server" and add it to your Claude Code skills directory (see the Installation section above).
google-tag-manager-mcp-server is primarily written in TypeScript. It is open-source under stape-io on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other MCP Servers skills you can browse and compare side by side. Open the MCP Servers category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh google-tag-manager-mcp-server against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
See comparison
An interface to the Google Tag Manager API over MCP, in two flavours: a hosted server with Google OAuth built in, and a local CLI that runs on your own credentials.
npm workspace with one app and two published packages:
| Path | Package | What it is |
|---|---|---|
apps/worker |
(private) | The hosted Cloudflare Worker at gtm-mcp.stape.ai: Google OAuth, the approval flow, the public pages, session removal. |
packages/cli |
google-tag-manager-mcp-server |
The npm package: a local MCP server over stdio, authenticating with credentials you supply. |
packages/core |
google-tag-manager-mcp-core |
Every GTM tool and schema, independent of how credentials are obtained. |
Tools reach Google through a GtmAuthProvider (getAccessToken(): Promise<string>) rather than through any particular session, which is what lets the same tool set back both servers — and a private one with your own auth. See the core package README.
This server comes in two flavours: Hosted server and Local CLI. Both give you the same 20 GTM tools; the difference is who handles Google auth.
| Hosted server | Local CLI | |
|---|---|---|
| Auth | Google OAuth in your browser, handled for you | You supply a service account key, refresh token, or access token |
| Data | Passes through gtm-mcp.stape.ai |
Only ever leaves your machine |
| Setup | None | Set one environment variable |
If you're a contributor testing an unreleased change rather than just using the tools, skip everything below and see Test your changes locally instead.
Pick your client below. The hosted server needs the mcp-remote bridge on clients whose MCP support doesn't complete Google's OAuth flow natively; where a client does that itself, it connects straight to https://gtm-mcp.stape.ai/mcp.
Hosted server — Claude Desktop connects to remote HTTP MCP servers natively, no bridge needed. Go to Settings → Connectors → Add custom connector, set the name to gtm-mcp-server and the URL to https://gtm-mcp.stape.ai/mcp, then save. Click the new connector to complete the Google OAuth flow in the browser window that opens.
mcp-remoteis also possible for the hosted server, for anyone who'd rather configure it through the JSON config file (Settings -> Developer -> Edit Config) instead of the Connectors UI — less recommended, but still supported:{ "mcpServers": { "gtm-mcp-server": { "command": "npx", "args": [ "-y", "mcp-remote", "https://gtm-mcp.stape.ai/mcp" ] } } }
Local CLI — no OAuth flow, no data through anyone else's server, you supply a service account key or a refresh token. Open Settings -> Developer -> Edit Config and add:
{
"mcpServers": {
"gtm-mcp-server": {
"command": "npx",
"args": ["-y", "google-tag-manager-mcp-server"],
"env": {
"GOOGLE_SERVICE_ACCOUNT_KEY": "{\"type\":\"service_account\", ... }"
}
}
}
}
See the CLI README for every credential option.
Claude Code speaks HTTP directly, including the OAuth handshake, so the hosted server needs no bridge.
Hosted server:
claude mcp add --transport http gtm-mcp-server https://gtm-mcp.stape.ai/mcp
A browser window opens for the Google OAuth flow the first time a tool is used. Run /mcp inside Claude Code to confirm it connected.
Local CLI:
claude mcp add gtm-mcp-server -e GOOGLE_SERVICE_ACCOUNT_KEY='{"type":"service_account", ... }' -- npx -y google-tag-manager-mcp-server
Both write into .mcp.json / your Claude Code MCP config.
VS Code's MCP client supports HTTP servers and their OAuth flow natively, no mcp-remote needed. Add this to .vscode/mcp.json:
Hosted server:
{
"servers": {
"gtm-mcp-server": {
"type": "http",
"url": "https://gtm-mcp.stape.ai/mcp"
}
}
}
Local CLI:
{
"servers": {
"gtm-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "google-tag-manager-mcp-server"],
"env": {
"GOOGLE_SERVICE_ACCOUNT_KEY": "{\"type\":\"service_account\", ... }"
}
}
}
}
GitHub Copilot Chat in VS Code uses VS Code's own MCP client, so it reads the same .vscode/mcp.json file — see VS Code above. No separate configuration is needed.
Copilot CLI also completes OAuth natively for remote HTTP servers. Add this to ~/.copilot/mcp-config.json:
Hosted server:
{
"mcpServers": {
"gtm-mcp-server": {
"type": "http",
"url": "https://gtm-mcp.stape.ai/mcp"
}
}
}
Local CLI:
{
"mcpServers": {
"gtm-mcp-server": {
"command": "npx",
"args": ["-y", "google-tag-manager-mcp-server"],
"env": {
"GOOGLE_SERVICE_ACCOUNT_KEY": "{\"type\":\"service_account\", ... }"
}
}
}
}
See GitHub's docs for the equivalent copilot mcp add subcommand.
Cursor speaks HTTP directly too, no mcp-remote needed. Add this to .cursor/mcp.json (project-level) or ~/.cursor/mcp.json (global — Settings → MCP → Add new global MCP server):
Hosted server:
{
"mcpServers": {
"gtm-mcp-server": {
"url": "https://gtm-mcp.stape.ai/mcp"
}
}
}
A browser window opens for the Google OAuth flow the first time a tool is used.
Local CLI:
{
"mcpServers": {
"gtm-mcp-server": {
"command": "npx",
"args": ["-y", "google-tag-manager-mcp-server"],
"env": {
"GOOGLE_SERVICE_ACCOUNT_KEY": "{\"type\":\"service_account\", ... }"
}
}
}
}
Antigravity's own OAuth support for remote HTTP servers doesn't reliably reach a token to the server yet (antigravity-cli#25), so use mcp-remote for the hosted server here too. Add this to ~/.gemini/config/mcp_config.json (global) or .agents/mcp_config.json (workspace-local) — accessible from the editor's agent panel via … → MCP Servers → Manage MCP Servers → View raw config:
Hosted server:
{
"mcpServers": {
"gtm-mcp-server": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"https://gtm-mcp.stape.ai/mcp"
]
}
}
}
Local CLI:
{
"mcpServers": {
"gtm-mcp-server": {
"command": "npx",
"args": ["-y", "google-tag-manager-mcp-server"],
"env": {
"GOOGLE_SERVICE_ACCOUNT_KEY": "{\"type\":\"service_account\", ... }"
}
}
}
}
https://gtm-mcp.stape.ai/mcp.ChatGPT only reaches servers over the public internet, it can't spawn a local process — so there's no Local CLI option here, only the hosted server.
Any other MCP-compatible client that expects a stdio-style command/args config can use the same mcp-remote block for the hosted server:
{
"mcpServers": {
"gtm-mcp-server": {
"command": "npx",
"args": [
"-y",
"mcp-remote",
"https://gtm-mcp.stape.ai/mcp"
]
}
}
}
Or the local CLI directly, with your credentials:
{
"mcpServers": {
"gtm-mcp-server": {
"command": "npx",
"args": ["-y", "google-ta