Atlas / MCP servers / blurrah / GraphQL

GraphQLSAFE

mcp/blurrah/graphql

Model Context Protocol server for GraphQL

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio
License
MIT
Stars
407
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/mcp-graphql)

A Model Context Protocol server that enables LLMs to interact with GraphQL APIs. This implementation provides schema introspection and query execution capabilities, allowing models to discover and use GraphQL APIs dynamically.

Usage

Run mcp-graphql with the correct endpoint, it will automatically try to introspect your queries.

Environment Variables (Breaking change in 1.0.0)

Note: As of version 1.0.0, command line arguments have been replaced with environment variables.

Examples

# Basic usage with a local GraphQL server
ENDPOINT=http://localhost:3000/graphql npx mcp-graphql

# Using with custom headers
ENDPOINT=https://api.example.com/graphql HEADERS='{"Authorization":"Bearer token123"}' npx mcp-graphql

# Enable mutation operations
ENDPOINT=http://localhost:3000/graphql ALLOW_MUTATIONS=true npx mcp-graphql

# Using a local schema file instead of introspection
ENDPOINT=http://localhost:3000/graphql SCHEMA=./schema.graphql npx mcp-graphql

# Using a schema file hosted at a URL
ENDPOINT=http://localhost:3000/graphql SCHEMA=https://example.com/schema.graphql npx mcp-graphql

Resources

  • graphql-schema: The server exposes the GraphQL schema as a resource that clients can access. This is either the local schema file, a sc
Read from source at commit 5d4522339e76OBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-graphql -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-graphql": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
introspect-schemareadIntrospect the GraphQL schema, use this tool before doing a query to get the schema information if you do not have it available as a resource already.
query-graphqlreadQuery a GraphQL endpoint with the given query and variables
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/helpers/package.ts:10
readFileSync(join(__dirname, "../../package.json"), "utf-8"),
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
graphql, @graphql-tools/schema, @types/bun, biome, graphql-yoga
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha 5d4522339e76full audit observations/trust-audit/mcp-server/blurrah__graphql.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-015d4522339e76SAFEB89first audit
06

Questions

What is the GraphQL MCP server?

Model Context Protocol server for GraphQL

What tools does GraphQL expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is GraphQL safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does GraphQL need?

No credential environment variables were found in its source, so it appears to need none.

How does GraphQL run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-graphql at 2.0.4.

How current is this page?

The grade is for one exact copy of the source (5d4522339e76), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement