
Security News
Lovable’s OJ Rewrites Vite’s Dev Server in Rust as AI Lowers the Cost of Forking Open Source
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.
@dockndevai/mcp-grafana
Advanced tools
Model Context Protocol server for Grafana — search & edit dashboards, query datasources (Prometheus/Loki/SQL), inspect alerts & annotations, with safe-by-default access modes and guards.
A safe-by-default Model Context Protocol server for Grafana. It lets an agent explore and operate Grafana — search dashboards, read the dashboard JSON model, list and query datasources (Prometheus / Loki / SQL), inspect alert rules and annotations, and (in higher modes) create/update dashboards and folders, write annotations, and delete.
Part of the dockndevai MCP server suite — one governance model across all of them.

The server starts read-only (see Safe by default); higher-capability tools are only registered when you raise the mode.
| Tool | For | Needs mode |
|---|---|---|
get_health | check the instance is up, version | read-only |
search | find dashboards & folders by name/tag (get UIDs) | read-only |
list_dashboards / list_folders | enumerate dashboards / folders | read-only |
get_dashboard | the full dashboard JSON model + meta | read-only |
list_datasources / get_datasource | datasources (secrets redacted) | read-only |
query_datasource | run PromQL / LogQL / SQL via the unified query API | read-only |
list_alert_rules | Grafana-managed alert rules | read-only |
list_annotations | events overlaid on graphs | read-only |
create_or_update_dashboard | upsert a dashboard (versioned, reversible) | read-write |
create_folder | create a folder | read-write |
create_annotation | mark a deploy/incident on graphs | read-write |
delete_dashboard / delete_folder / delete_annotation | delete (irreversible) | admin + GRAFANA_ALLOW_DELETE |
npx -y @dockndevai/mcp-grafana
You need a Grafana service account token (Administration → Service accounts → Add service account → Add token). Give it the least role that works — Viewer for read-only use, Editor to create/update, Admin only if you must delete.
{
"mcpServers": {
"grafana": {
"command": "npx",
"args": ["-y", "@dockndevai/mcp-grafana"],
"env": {
"GRAFANA_URL": "http://localhost:3000",
"GRAFANA_TOKEN": "glsa_...",
"GRAFANA_MODE": "read-only"
}
}
}
}
See docs/CLIENTS.md for Claude Code / Cursor / Codex / VS Code / Windsurf snippets, and .env.example for every supported variable.
The access model is enforced by src/security.ts — defence in depth on top of the service-account token's own role:
GRAFANA_MODE — read-only (default) → read-write → admin. A tool is registered only if the mode allows its capability. Read-only exposes the 11 read tools; edits need read-write; deletes need admin.GRAFANA_ALLOW_DELETE — deletes are irreversible, so on top of admin mode they also require this flag.GRAFANA_FOLDER_ALLOWLIST / GRAFANA_PROTECTED_FOLDERS — confine which folders can be written to; mark folders (e.g. production) that may be read but never modified or deleted.GRAFANA_DATASOURCE_ALLOWLIST — restrict which datasources query_datasource may hit.GRAFANA_DRY_RUN — validate and log writes without executing them.GRAFANA_AUDIT_LOG — a JSON audit line per guarded operation, on stderr (default on).GRAFANA_ALLOW_DELETE gate.secureJsonData, passwords and tokens are stripped from every response.
See SECURITY.md.
Conventions for the dashboard JSON model, panel/target shapes, PromQL/LogQL/SQL query patterns, folder organisation and safe editing live in the bundled skill: .claude/skills/grafana-dashboards-and-queries/SKILL.md. Agents that load it can build and edit dashboards to a consistent standard without being re-taught each time.
npm install
npm run build
GRAFANA_URL=http://localhost:3000 GRAFANA_TOKEN=glsa_… node dist/index.js
# introspect without a live Grafana:
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | GRAFANA_TOKEN=x node dist/index.js
MIT
FAQs
Model Context Protocol server for Grafana — search & edit dashboards, query datasources (Prometheus/Loki/SQL), inspect alerts & annotations, with safe-by-default access modes and guards.
The npm package @dockndevai/mcp-grafana receives a total of 65 weekly downloads. As such, @dockndevai/mcp-grafana popularity was classified as not popular.
We found that @dockndevai/mcp-grafana demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Lovable’s OJ rewrites Vite’s dev server in Rust, reducing memory use and preview times as AI lowers the cost of open source reimplementation.

Security News
It has been one year since Shai-Hulud made its first appearance on npm.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.