Daniel LightRAGCAUTION
A comprehensive MCP server for LightRAG integration with 22 tools for document management, querying, knowledge graph operations, and system management
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A comprehensive MCP (Model Context Protocol) server that provides 100% functional integration with LightRAG API, offering 22 fully working tools across 4 categories for complete document management, querying, knowledge graph operations, and system management.
🎉 Status: 100% Functional
All 22 tools are working perfectly after comprehensive testing and optimization:
- ✅ Document Management: 6/6 tools working (100%)
- ✅ Query Operations: 2/2 tools working (100%)
- ✅ Knowledge Graph: 6/6 tools working (100%)
- ✅ System Management: 4/4 tools working (100%)
- ✅ Health Check: 1/1 tools working (100%)
Features
- Document Management: 6 tools for inserting, uploading, scanning, retrieving, and managing documents
- Query Operations: 2 tools for text queries with regular and streaming responses
- Knowledge Graph: 6 tools for accessing, checking, updating, and managing entities and relations
- System Management: 4 tools for health checks, status monitoring, and cache management
- Comprehensive Error Handling: Robust error handling with detailed error messages
- Full API Coverage: Complete integration with LightRAG API 0.1.96+
Quick Start
- Install the server:
pip install -e .
- Start LightRAG server (ensure it's running on http://localhost:9621)
- Configure your MCP client (e.g., Claude Desktop):
{
"mcpServers": {
"daniel-lightrag": {
"command": "python",
"args": ["-m", "daniel_lightrag_mcp"]
}
}
}- Test the connection:
Use the get_health tool to verify everything is working.
Installation
# Basic installation pip install -e . # With development dependencies pip install -e ".[dev]"
Usage
Command Line
Start the MCP server:
daniel-lightrag-mcp
Environment Variables
Configure the server with environment variables:
c89a3ad65572OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add daniel-lightrag-mcp --env LIGHTRAG_API_KEY=${LIGHTRAG_API_KEY} -- uvx daniel-lightrag-mcp{
"mcpServers": {
"daniel-lightrag-mcp": {
"command": "uvx",
"args": [
"daniel-lightrag-mcp"
],
"env": {
"LIGHTRAG_API_KEY": "${LIGHTRAG_API_KEY}"
}
}
}
}Exposed tools (21)
13 read · 5 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
check_entity_exists | read | Check if an entity exists in the knowledge graph |
delete_document | destructive | Delete a specific document by ID |
delete_entity | destructive | Delete an entity from the knowledge graph |
delete_relation | destructive | Delete a relation from the knowledge graph |
get_document_status_counts | read | Get document status counts |
get_documents | read | Retrieve all documents from LightRAG |
get_documents_paginated | read | Retrieve documents with pagination. IMPORTANT: page_size must be 10-100 (server enforces minimum for performance). Use page_size=20 for typical browsing. |
get_graph_labels | read | Get labels from the knowledge graph |
get_health | read | Check LightRAG server health |
get_knowledge_graph | read | Retrieve the knowledge graph from LightRAG |
get_pipeline_status | read | Get the pipeline status from LightRAG |
get_track_status | read | Get track status by ID |
hello | read | Say hello |
insert_text | write | Insert text content into LightRAG |
insert_texts | write | Insert multiple text documents into LightRAG |
query_text | read | Query LightRAG with text |
query_text_stream | read | Stream query results from LightRAG |
scan_documents | read | Scan for new documents in LightRAG |
update_entity | write | Update an entity in the knowledge graph |
update_relation | write | Update a relation in the knowledge graph |
upload_document | write | Upload a document file to LightRAG |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
logger.info(f" - api_key: {'***REDACTED***' if api_key else 'None'}")logger.info(f" - Client has API key: {lightrag_client.api_key is not None}")delete_document, delete_entity, delete_relation
print(f"Using API key: {api_key[:10] + '...' if api_key else 'None'}")This MCP server will allow you to interact with your LightRAG instance through any MCP-compatible client, providing full access to document management, querying, and knowledge graph operations.
Gates applied: no_behavioural_pass.
c89a3ad65572full audit observations/trust-audit/mcp-server/desimpkins__daniel-lightrag.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | c89a3ad65572 | CAUTION | B | 89 | first audit |
Questions
What is the Daniel LightRAG MCP server?
A comprehensive MCP server for LightRAG integration with 22 tools for document management, querying, knowledge graph operations, and system management
What tools does Daniel LightRAG expose?
21 in total: 13 read-only, 5 that write, and 3 that can delete or overwrite (delete_document, delete_entity, delete_relation). Every one is listed on this page with its risk.
Is Daniel LightRAG safe to connect to an agent?
With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Daniel LightRAG need?
It reads LIGHTRAG_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Daniel LightRAG run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as daniel-lightrag-mcp.
How current is this page?
The grade is for one exact copy of the source (c89a3ad65572), read on 2026-10-08. The repository is watched and re-audited when it changes.