cost-guard-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| SNOWFLAKE_ROLE | No | Snowflake role (required, no default, never ACCOUNTADMIN). | |
| SNOWFLAKE_USER | No | Snowflake user name. | |
| SNOWFLAKE_ACCOUNT | No | Snowflake account identifier. | |
| SNOWFLAKE_PASSWORD | No | Snowflake password (discouraged; use SNOWFLAKE_PRIVATE_KEY_PATH instead). | |
| SNOWFLAKE_PRIVATE_KEY_PATH | No | Path to Snowflake private key file (preferred over password). | |
| GOOGLE_APPLICATION_CREDENTIALS | No | Path to a service-account key file for BigQuery. Alternatively, run `gcloud auth application-default login`. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| check_credentialsA | Verify credentials/connectivity for an engine without running any real query or dry-run estimate. Call this once after configuring a new engine (or when a real tool call fails) to get a fast, clear yes/no signal instead of debugging via trial queries. |
| describe_engine_capabilitiesA | Declare which cost signals are exact vs. approximate for the given warehouse engine. |
| estimate_query_costA | Estimate the cost of a SQL query before running it. ALWAYS call this before running an expensive-looking query. The response's accuracy_tier tells you how much to trust the number: PRECISE (exact), UPPER_BOUND (real cap, may overstate), HEURISTIC (rough). |
| run_query_boundedA | Run a query only if its pre-flight cost estimate is within your given bounds; refuses otherwise (check result.status — "refused" means it did NOT run and result.hint explains why). NOTE: unlike estimate_query_cost, a successful call here has a real monetary/quota side effect — don't call this repeatedly without inspecting the result of each call. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 4 tools
Each tool targets a distinct stage: credential verification, capability/accuracy disclosure, cost estimation, and guarded execution. The overlap between estimate_query_cost and run_query_bounded is explicitly clarified by the side-effect warning.
All tool names use a consistent snake_case verb_noun pattern: check_, describe_, estimate_, run_. The slight grammatical extension in run_query_bounded does not break the overall naming consistency.
Four tools is well-scoped for a cost-guard MCP server. Each tool serves a necessary and non-redundant role in the pre-flight cost-protection workflow.
The core lifecycle is covered: verify connectivity, understand estimate reliability, estimate cost, and run only within bounds. A post-run actual-cost tracking or persistent budget management tool would be a minor enhancement, but agents can work around its absence for the stated use case.