Atlas / MCP servers / cr7258 / Elasticsearch

ElasticsearchCAUTION

mcp/cr7258/elasticsearch-1

A Model Context Protocol (MCP) server implementation that provides Elasticsearch and OpenSearch interaction.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
24 15r · 4w · 5d
Transport
streamable-http
License
Apache-2.0
Stars
308
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/cr7258-elasticsearch-mcp-server)

[](https://archestra.ai/mcp-catalog/cr7258__elasticsearch-mcp-server)

Overview

A Model Context Protocol (MCP) server implementation that provides Elasticsearch and OpenSearch interaction. This server enables searching documents, analyzing indices, and managing cluster through a set of tools.

Demo

https://github.com/user-attachments/assets/f7409e31-fac4-4321-9c94-b0ff2ea7ff15

Features

General Operations

  • general_api_request: Perform a general HTTP API request. Use this tool for any Elasticsearch/OpenSearch API that does not have a dedicated tool.

Index Operations

  • list_indices: List all indices.
  • get_index: Returns information (mappings, settings, aliases) about one or more indices.
  • create_index: Create a new index.
  • delete_index: Delete an index.
  • create_data_stream: Create a new data stream (requires matching index template).
  • get_data_stream: Get information about one or more data streams.
  • delete_data_stream: Delete one or more data streams and their backing indices.

Document Operations

  • search_documents: Search for documents.
  • index_document: Creates or updates a document in the index.
  • get_document: Get a document by ID.
  • delete_document: Delete a document by ID.
  • delete_by_query: Deletes documents matching the provided query.

Cluster Operations

  • get_cluster_health: Returns basic information about the health of the cluster.
  • get_cluster_stats: Returns high-level overview of cluster statistics.

Alias Operations

  • `l
Read from source at commit e9c188832da3OBSERVED · 2026-10-05
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add elasticsearch-mcp-server --env MCP_API_KEY=${MCP_API_KEY} -- uvx elasticsearch-mcp-server
claude-desktop
{
  "mcpServers": {
    "elasticsearch-mcp-server": {
      "command": "uvx",
      "args": [
        "elasticsearch-mcp-server"
      ],
      "env": {
        "MCP_API_KEY": "${MCP_API_KEY}"
      }
    }
  }
}
03

Exposed tools (24)

15 read · 4 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analyze_textread
create_data_streamwriteCreate a new data stream.
create_indexwrite
delete_aliasdestructive
delete_by_querydestructive
delete_data_streamdestructiveDelete one or more data streams.
delete_documentdestructive
delete_indexdestructive
failing_toolreadraise ValueError(
general_api_requestreadPerform a general HTTP API request.
get_aliasread
get_cluster_healthread
get_cluster_statsread
get_data_streamreadGet information about one or more data streams.
get_documentread
get_indexread
index_documentread
list_aliasesread
list_indicesread
put_aliaswrite
read_operationreadreturn
search_documentsread
succeeding_toolreadreturn
write_operationwritereturn
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (9)

MEDIUMInventory / provenance · inv.binary · CWE-1104
mcp_client/spring-ai/gradle/wrapper/gradle-wrapper.jar
gradle-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_alias, delete_by_query, delete_data_stream, delete_document, delete_index
Why it matters. 5 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:369
# By default, the SSE MCP server will serve on http://127.0.0.1:8000/sse
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:379
# By default, the SSE MCP server will serve on http://127.0.0.1:8000/sse
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:400
# By default, the Streamable HTTP MCP server will serve on http://127.0.0.1:8000/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:410
# By default, the Streamable HTTP MCP server will serve on http://127.0.0.1:8000/mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/e2e/containers/conftest.py:193
base_url = f"http://127.0.0.1:{local_port}"
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
.github/workflows/helm-chart.yaml:22
run: helm plugin install https://github.com/helm-unittest/helm-unittest --version v0.3.2 --verify=false
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
.github/workflows/test.yaml:50
run: helm plugin install https://github.com/helm-unittest/helm-unittest --version v0.3.2 --verify=false
Why it matters. certificate verification is disabled
Fix. leave verification on

Gates applied: no_behavioural_pass.

Audited 2026-10-05 · audit v0.4.1 · source sha e9c188832da3full audit observations/trust-audit/mcp-server/cr7258__elasticsearch-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-05e9c188832da3CAUTIONB89first audit
06

Questions

What is the Elasticsearch MCP server?

A Model Context Protocol (MCP) server implementation that provides Elasticsearch and OpenSearch interaction.

What tools does Elasticsearch expose?

24 in total: 15 read-only, 4 that write, and 5 that can delete or overwrite (delete_alias, delete_by_query, delete_data_stream, delete_document, delete_index). Every one is listed on this page with its risk.

Is Elasticsearch safe to connect to an agent?

With care. The audit graded it B (89/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Elasticsearch need?

It reads MCP_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Elasticsearch run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as elasticsearch-mcp-server.

How current is this page?

The grade is for one exact copy of the source (e9c188832da3), read on 2026-10-05. The repository is watched and re-audited when it changes.

Advertisement