Hardened VK Ads MCP
vk-ads-mcp
A hardened VK Ads MCP fork: read-only by default, mutations gated by VK_ADS_ENABLE_WRITES, and SSRF protection on file uploads
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- With VK_ADS_ENABLE_WRITES on, it can create, change and delete campaigns and spend ad budget
- File uploads to campaigns reach out to external addresses, even though SSRF protection is in place
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/nikolaymokh-dev-vk-ads-mcpDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
This entry is high risk, so there is no one-click install. Review the code and add the config by hand.
Run in a terminal
claude mcp add --transport stdio --env 'VK_ADS_CLIENT_ID=<your VK_ADS_CLIENT_ID>' --env 'VK_ADS_CLIENT_SECRET=<your VK_ADS_CLIENT_SECRET>' vk-ads -- uvx --from git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0 vk-ads-mcpOr add to the file .mcp.json, in the project
{
"mcpServers": {
"vk-ads": {
"command": "uvx",
"args": [
"--from",
"git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0",
"vk-ads-mcp"
],
"env": {
"VK_ADS_CLIENT_ID": "<your VK_ADS_CLIENT_ID>",
"VK_ADS_CLIENT_SECRET": "<your VK_ADS_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
VK_ADS_CLIENT_IDsecret, required- Client ID for VK Ads API
VK_ADS_CLIENT_SECRETsecret, required- Client secret for VK Ads API
VK_ADS_ACCESS_TOKENsecret, optional- Access token for VK Ads API
VK_ADS_ENABLE_WRITESoptional- Enable mutating operations, set to true to allow writes
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"vk-ads": {
"command": "uvx",
"args": [
"--from",
"git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0",
"vk-ads-mcp"
],
"env": {
"VK_ADS_CLIENT_ID": "<your VK_ADS_CLIENT_ID>",
"VK_ADS_CLIENT_SECRET": "<your VK_ADS_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
VK_ADS_CLIENT_IDsecret, required- Client ID for VK Ads API
VK_ADS_CLIENT_SECRETsecret, required- Client secret for VK Ads API
VK_ADS_ACCESS_TOKENsecret, optional- Access token for VK Ads API
VK_ADS_ENABLE_WRITESoptional- Enable mutating operations, set to true to allow writes
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
code --add-mcp '{"name":"vk-ads","type":"stdio","command":"uvx","args":["--from","git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0","vk-ads-mcp"],"env":{"VK_ADS_CLIENT_ID":"<your VK_ADS_CLIENT_ID>","VK_ADS_CLIENT_SECRET":"<your VK_ADS_CLIENT_SECRET>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"vk-ads": {
"type": "stdio",
"command": "uvx",
"args": [
"--from",
"git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0",
"vk-ads-mcp"
],
"env": {
"VK_ADS_CLIENT_ID": "<your VK_ADS_CLIENT_ID>",
"VK_ADS_CLIENT_SECRET": "<your VK_ADS_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
VK_ADS_CLIENT_IDsecret, required- Client ID for VK Ads API
VK_ADS_CLIENT_SECRETsecret, required- Client secret for VK Ads API
VK_ADS_ACCESS_TOKENsecret, optional- Access token for VK Ads API
VK_ADS_ENABLE_WRITESoptional- Enable mutating operations, set to true to allow writes
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
codex mcp add vk-ads --env 'VK_ADS_CLIENT_ID=<your VK_ADS_CLIENT_ID>' --env 'VK_ADS_CLIENT_SECRET=<your VK_ADS_CLIENT_SECRET>' -- uvx --from git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0 vk-ads-mcpOr add to the file ~/.codex/config.toml, for all projects
[mcp_servers.vk-ads]
command = "uvx"
args = ["--from", "git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0", "vk-ads-mcp"]
env = { VK_ADS_CLIENT_ID = "<your VK_ADS_CLIENT_ID>", VK_ADS_CLIENT_SECRET = "<your VK_ADS_CLIENT_SECRET>" }If the file already exists, append the block to the end.
Keys and settings
VK_ADS_CLIENT_IDsecret, required- Client ID for VK Ads API
VK_ADS_CLIENT_SECRETsecret, required- Client secret for VK Ads API
VK_ADS_ACCESS_TOKENsecret, optional- Access token for VK Ads API
VK_ADS_ENABLE_WRITESoptional- Enable mutating operations, set to true to allow writes
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"vk-ads": {
"command": "uvx",
"args": [
"--from",
"git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0",
"vk-ads-mcp"
],
"env": {
"VK_ADS_CLIENT_ID": "<your VK_ADS_CLIENT_ID>",
"VK_ADS_CLIENT_SECRET": "<your VK_ADS_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
VK_ADS_CLIENT_IDsecret, required- Client ID for VK Ads API
VK_ADS_CLIENT_SECRETsecret, required- Client secret for VK Ads API
VK_ADS_ACCESS_TOKENsecret, optional- Access token for VK Ads API
VK_ADS_ENABLE_WRITESoptional- Enable mutating operations, set to true to allow writes
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"vk-ads": {
"command": "uvx",
"args": [
"--from",
"git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0",
"vk-ads-mcp"
],
"env": {
"VK_ADS_CLIENT_ID": "<your VK_ADS_CLIENT_ID>",
"VK_ADS_CLIENT_SECRET": "<your VK_ADS_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
VK_ADS_CLIENT_IDsecret, required- Client ID for VK Ads API
VK_ADS_CLIENT_SECRETsecret, required- Client secret for VK Ads API
VK_ADS_ACCESS_TOKENsecret, optional- Access token for VK Ads API
VK_ADS_ENABLE_WRITESoptional- Enable mutating operations, set to true to allow writes
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"vk-ads": {
"command": "uvx",
"args": [
"--from",
"git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0",
"vk-ads-mcp"
],
"env": {
"VK_ADS_CLIENT_ID": "<your VK_ADS_CLIENT_ID>",
"VK_ADS_CLIENT_SECRET": "<your VK_ADS_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
VK_ADS_CLIENT_IDsecret, required- Client ID for VK Ads API
VK_ADS_CLIENT_SECRETsecret, required- Client secret for VK Ads API
VK_ADS_ACCESS_TOKENsecret, optional- Access token for VK Ads API
VK_ADS_ENABLE_WRITESoptional- Enable mutating operations, set to true to allow writes
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"vk-ads": {
"command": "uvx",
"args": [
"--from",
"git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0",
"vk-ads-mcp"
],
"env": {
"VK_ADS_CLIENT_ID": "<your VK_ADS_CLIENT_ID>",
"VK_ADS_CLIENT_SECRET": "<your VK_ADS_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
VK_ADS_CLIENT_IDsecret, required- Client ID for VK Ads API
VK_ADS_CLIENT_SECRETsecret, required- Client secret for VK Ads API
VK_ADS_ACCESS_TOKENsecret, optional- Access token for VK Ads API
VK_ADS_ENABLE_WRITESoptional- Enable mutating operations, set to true to allow writes
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"vk-ads": {
"type": "local",
"command": [
"uvx",
"--from",
"git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0",
"vk-ads-mcp"
],
"environment": {
"VK_ADS_CLIENT_ID": "<your VK_ADS_CLIENT_ID>",
"VK_ADS_CLIENT_SECRET": "<your VK_ADS_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
VK_ADS_CLIENT_IDsecret, required- Client ID for VK Ads API
VK_ADS_CLIENT_SECRETsecret, required- Client secret for VK Ads API
VK_ADS_ACCESS_TOKENsecret, optional- Access token for VK Ads API
VK_ADS_ENABLE_WRITESoptional- Enable mutating operations, set to true to allow writes
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"vk-ads": {
"command": "uvx",
"args": [
"--from",
"git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0",
"vk-ads-mcp"
],
"env": {
"VK_ADS_CLIENT_ID": "<your VK_ADS_CLIENT_ID>",
"VK_ADS_CLIENT_SECRET": "<your VK_ADS_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
VK_ADS_CLIENT_IDsecret, required- Client ID for VK Ads API
VK_ADS_CLIENT_SECRETsecret, required- Client secret for VK Ads API
VK_ADS_ACCESS_TOKENsecret, optional- Access token for VK Ads API
VK_ADS_ENABLE_WRITESoptional- Enable mutating operations, set to true to allow writes
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .codeassistant/mcp.json, in the project
{
"mcpServers": {
"vk-ads": {
"command": "uvx",
"args": [
"--from",
"git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0",
"vk-ads-mcp"
],
"env": {
"VK_ADS_CLIENT_ID": "<your VK_ADS_CLIENT_ID>",
"VK_ADS_CLIENT_SECRET": "<your VK_ADS_CLIENT_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
VK_ADS_CLIENT_IDsecret, required- Client ID for VK Ads API
VK_ADS_CLIENT_SECRETsecret, required- Client secret for VK Ads API
VK_ADS_ACCESS_TOKENsecret, optional- Access token for VK Ads API
VK_ADS_ENABLE_WRITESoptional- Enable mutating operations, set to true to allow writes
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add the server with claude mcp add vk-ads --env VK_ADS_CLIENT_ID=<id> --env VK_ADS_CLIENT_SECRET=<secret> -- uvx --from git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0 vk-ads-mcp, and additionally set VK_ADS_ENABLE_WRITES=true for write access.
Other ways from the author
claude mcp add vk-ads --env VK_ADS_CLIENT_ID=<id> --env VK_ADS_CLIENT_SECRET=<secret> -- uvx --from git+https://github.com/nikolaymokh-dev/vk-ads-mcp@v0.1.0 vk-ads-mcpThe install command from the README; read-only by default.
This is third-party code. Review the repository files before installing.
What it does
The server manages VK Ads campaigns (myTarget API v2): 24 tools for reading plans, campaigns, ad groups, banners, statistics, remarketing and dictionaries are always available, while 31 mutating tools for creating, changing and deleting objects, uploading files and spending budget are hidden from the tool list until VK_ADS_ENABLE_WRITES=true is explicitly set. This is a fork of lexamarketolog/vk-ads-mcp that adds a safety layer on top of the original tools: blocking file uploads from non-public addresses and local paths with path-traversal protection, locking the API address to ads.vk.com, and protecting user-supplied values that end up in a URL. It installs via uvx with a pinned version tag and uv.lock.
Who it is for. For marketers and agencies who want to give an agent access to VK Ads, but with a guarantee it cannot spend budget without write access explicitly enabled.
Good fit when
- You need read-only access to VK Ads statistics and campaign structure by default
- You need SSRF and path-traversal protection when uploading images and videos to campaigns
- You need a reproducible install pinned to a version tag rather than the main branch
Not a fit when
- You need full write access right away with no separate enable step: VK_ADS_ENABLE_WRITES=true is required
- You need regular VK.com, not VK Ads: the server has no tools for posts or communities
Example request
Show my VK Ads campaign statistics for the week without changing anything in the accountLimitations
The project is young, at version 0.1.1 with alpha status per its PyPI classifiers. The API terminology uses legacy myTarget names that do not match the new ads.vk.com dashboard interface; the README gives a mapping table. Each partner needs their own VK Ads API keys. The fork adds protection but does not change the behavior of the original lexamarketolog/vk-ads-mcp tools.
How to disable. Remove the server from your MCP client configuration, for example claude mcp remove vk-ads.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| VK_ADS_CLIENT_ID required | The VK Ads application client id. |
| VK_ADS_CLIENT_SECRET required, secret | The VK Ads application client secret. |
| VK_ADS_ENABLE_WRITES | Enables the 31 mutating tools; off by default. |
Security check
- With VK_ADS_ENABLE_WRITES on, it can create, change and delete campaigns and spend ad budget
- File uploads to campaigns reach out to external addresses, even though SSRF protection is in place
README in short
The Russian README explains this is a hardened fork of the original VK Ads server, gives a mapping table from legacy myTarget terms to the new dashboard, install instructions for Claude Code and other MCP clients via uvx pinned to a tag, a separate step to enable mutating tools via VK_ADS_ENABLE_WRITES, and a list of the fork's added safety measures with links to docs/SETUP.md and docs/SECURITY.md.
FAQ
Can the agent change campaigns right away?
No, 31 mutating tools are hidden from the list until the VK_ADS_ENABLE_WRITES=true variable is set.
How is this different from the original lexamarketolog/vk-ads-mcp?
The README lists what was added: read-only by default, SSRF protection on file uploads, an API address lock and path-traversal protection, without changing the tools themselves.
Related
A skill that strips AI writing tells from text using Wikipedia's list, without adding invented facts
Marketing Skills for AI agents
Marketing Skills for AI Agents
About fifty skills for CRO, copywriting, SEO, analytics, ads and launches, built for coding agents
SendPulse MCP server
SendPulse MCP
SendPulse's official remote MCP server: statistics, campaigns and user data through an agent chat
Yandex Direct MCP generated from a machine-readable schema
yandex-direct-mcp
An MCP server and CLI covering all 113 Yandex Direct API v5 methods generated from WSDL, exposing 9 read tools by default and writes only on demand