Atlas / MCP servers / desimpkins / Daniel LightRAG

Daniel LightRAGCAUTION

mcp/desimpkins/daniel-lightrag

A comprehensive MCP server for LightRAG integration with 22 tools for document management, querying, knowledge graph operations, and system management

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
21 13r · 5w · 3d
Transport
stdio
License
MIT
Stars
37
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A comprehensive MCP (Model Context Protocol) server that provides 100% functional integration with LightRAG API, offering 22 fully working tools across 4 categories for complete document management, querying, knowledge graph operations, and system management.

🎉 Status: 100% Functional

All 22 tools are working perfectly after comprehensive testing and optimization:

  • ✅ Document Management: 6/6 tools working (100%)
  • ✅ Query Operations: 2/2 tools working (100%)
  • ✅ Knowledge Graph: 6/6 tools working (100%)
  • ✅ System Management: 4/4 tools working (100%)
  • ✅ Health Check: 1/1 tools working (100%)

Features

  • Document Management: 6 tools for inserting, uploading, scanning, retrieving, and managing documents
  • Query Operations: 2 tools for text queries with regular and streaming responses
  • Knowledge Graph: 6 tools for accessing, checking, updating, and managing entities and relations
  • System Management: 4 tools for health checks, status monitoring, and cache management
  • Comprehensive Error Handling: Robust error handling with detailed error messages
  • Full API Coverage: Complete integration with LightRAG API 0.1.96+

Quick Start

  1. Install the server:
pip install -e .
  1. Start LightRAG server (ensure it's running on http://localhost:9621)
  1. Configure your MCP client (e.g., Claude Desktop):
{
"mcpServers": {
"daniel-lightrag": {
"command": "python",
"args": ["-m", "daniel_lightrag_mcp"]
}
}
}
  1. Test the connection:

Use the get_health tool to verify everything is working.

Installation

# Basic installation
pip install -e .

# With development dependencies
pip install -e ".[dev]"

Usage

Command Line

Start the MCP server:

daniel-lightrag-mcp

Environment Variables

Configure the server with environment variables:

Read from source at commit c89a3ad65572OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add daniel-lightrag-mcp --env LIGHTRAG_API_KEY=${LIGHTRAG_API_KEY} -- uvx daniel-lightrag-mcp
claude-desktop
{
  "mcpServers": {
    "daniel-lightrag-mcp": {
      "command": "uvx",
      "args": [
        "daniel-lightrag-mcp"
      ],
      "env": {
        "LIGHTRAG_API_KEY": "${LIGHTRAG_API_KEY}"
      }
    }
  }
}
03

Exposed tools (21)

13 read · 5 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
check_entity_existsreadCheck if an entity exists in the knowledge graph
delete_documentdestructiveDelete a specific document by ID
delete_entitydestructiveDelete an entity from the knowledge graph
delete_relationdestructiveDelete a relation from the knowledge graph
get_document_status_countsreadGet document status counts
get_documentsreadRetrieve all documents from LightRAG
get_documents_paginatedreadRetrieve documents with pagination. IMPORTANT: page_size must be 10-100 (server enforces minimum for performance). Use page_size=20 for typical browsing.
get_graph_labelsreadGet labels from the knowledge graph
get_healthreadCheck LightRAG server health
get_knowledge_graphreadRetrieve the knowledge graph from LightRAG
get_pipeline_statusreadGet the pipeline status from LightRAG
get_track_statusreadGet track status by ID
helloreadSay hello
insert_textwriteInsert text content into LightRAG
insert_textswriteInsert multiple text documents into LightRAG
query_textreadQuery LightRAG with text
query_text_streamreadStream query results from LightRAG
scan_documentsreadScan for new documents in LightRAG
update_entitywriteUpdate an entity in the knowledge graph
update_relationwriteUpdate a relation in the knowledge graph
upload_documentwriteUpload a document file to LightRAG
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (5)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/daniel_lightrag_mcp/server.py:863
logger.info(f"  - api_key: {'***REDACTED***' if api_key else 'None'}")
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/daniel_lightrag_mcp/server.py:874
logger.info(f"  - Client has API key: {lightrag_client.api_key is not None}")
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_document, delete_entity, delete_relation
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
archive/testing_scripts/test_lightrag_connection.py:22
print(f"Using API key: {api_key[:10] + '...' if api_key else 'None'}")
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
archive/development_docs/implementation_plan.md:65
This MCP server will allow you to interact with your LightRAG instance through any MCP-compatible client, providing full access to document management, querying, and knowledge graph operations.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha c89a3ad65572full audit observations/trust-audit/mcp-server/desimpkins__daniel-lightrag.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08c89a3ad65572CAUTIONB89first audit
06

Questions

What is the Daniel LightRAG MCP server?

A comprehensive MCP server for LightRAG integration with 22 tools for document management, querying, knowledge graph operations, and system management

What tools does Daniel LightRAG expose?

21 in total: 13 read-only, 5 that write, and 3 that can delete or overwrite (delete_document, delete_entity, delete_relation). Every one is listed on this page with its risk.

Is Daniel LightRAG safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Daniel LightRAG need?

It reads LIGHTRAG_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Daniel LightRAG run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as daniel-lightrag-mcp.

How current is this page?

The grade is for one exact copy of the source (c89a3ad65572), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement