ElasticsearchCAUTION
A Model Context Protocol (MCP) server implementation that provides Elasticsearch and OpenSearch interaction.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/cr7258-elasticsearch-mcp-server)
[](https://archestra.ai/mcp-catalog/cr7258__elasticsearch-mcp-server)
Overview
A Model Context Protocol (MCP) server implementation that provides Elasticsearch and OpenSearch interaction. This server enables searching documents, analyzing indices, and managing cluster through a set of tools.
Demo
https://github.com/user-attachments/assets/f7409e31-fac4-4321-9c94-b0ff2ea7ff15
Features
General Operations
general_api_request: Perform a general HTTP API request. Use this tool for any Elasticsearch/OpenSearch API that does not have a dedicated tool.
Index Operations
list_indices: List all indices.get_index: Returns information (mappings, settings, aliases) about one or more indices.create_index: Create a new index.delete_index: Delete an index.create_data_stream: Create a new data stream (requires matching index template).get_data_stream: Get information about one or more data streams.delete_data_stream: Delete one or more data streams and their backing indices.
Document Operations
search_documents: Search for documents.index_document: Creates or updates a document in the index.get_document: Get a document by ID.delete_document: Delete a document by ID.delete_by_query: Deletes documents matching the provided query.
Cluster Operations
get_cluster_health: Returns basic information about the health of the cluster.get_cluster_stats: Returns high-level overview of cluster statistics.
Alias Operations
- `l
e9c188832da3OBSERVED · 2026-10-05Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add elasticsearch-mcp-server --env MCP_API_KEY=${MCP_API_KEY} -- uvx elasticsearch-mcp-server{
"mcpServers": {
"elasticsearch-mcp-server": {
"command": "uvx",
"args": [
"elasticsearch-mcp-server"
],
"env": {
"MCP_API_KEY": "${MCP_API_KEY}"
}
}
}
}Exposed tools (24)
15 read · 4 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
analyze_text | read | |
create_data_stream | write | Create a new data stream. |
create_index | write | |
delete_alias | destructive | |
delete_by_query | destructive | |
delete_data_stream | destructive | Delete one or more data streams. |
delete_document | destructive | |
delete_index | destructive | |
failing_tool | read | raise ValueError( |
general_api_request | read | Perform a general HTTP API request. |
get_alias | read | |
get_cluster_health | read | |
get_cluster_stats | read | |
get_data_stream | read | Get information about one or more data streams. |
get_document | read | |
get_index | read | |
index_document | read | |
list_aliases | read | |
list_indices | read | |
put_alias | write | |
read_operation | read | return |
search_documents | read | |
succeeding_tool | read | return |
write_operation | write | return |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (9)
gradle-wrapper.jar
delete_alias, delete_by_query, delete_data_stream, delete_document, delete_index
# By default, the SSE MCP server will serve on http://127.0.0.1:8000/sse
# By default, the SSE MCP server will serve on http://127.0.0.1:8000/sse
# By default, the Streamable HTTP MCP server will serve on http://127.0.0.1:8000/mcp
# By default, the Streamable HTTP MCP server will serve on http://127.0.0.1:8000/mcp
base_url = f"http://127.0.0.1:{local_port}"run: helm plugin install https://github.com/helm-unittest/helm-unittest --version v0.3.2 --verify=false
run: helm plugin install https://github.com/helm-unittest/helm-unittest --version v0.3.2 --verify=false
Gates applied: no_behavioural_pass.
e9c188832da3full audit observations/trust-audit/mcp-server/cr7258__elasticsearch-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-05 | e9c188832da3 | CAUTION | B | 89 | first audit |
Questions
What is the Elasticsearch MCP server?
A Model Context Protocol (MCP) server implementation that provides Elasticsearch and OpenSearch interaction.
What tools does Elasticsearch expose?
24 in total: 15 read-only, 4 that write, and 5 that can delete or overwrite (delete_alias, delete_by_query, delete_data_stream, delete_document, delete_index). Every one is listed on this page with its risk.
Is Elasticsearch safe to connect to an agent?
With care. The audit graded it B (89/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Elasticsearch need?
It reads MCP_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Elasticsearch run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as elasticsearch-mcp-server.
How current is this page?
The grade is for one exact copy of the source (e9c188832da3), read on 2026-10-05. The repository is watched and re-audited when it changes.