Atlas / MCP servers / ergut / LogSeq

LogSeqBLOCK

mcp/ergut/logseq-1

MCP server to interact with LogSeq via its Local HTTP API - enabling AI assistants like Claude to seamlessly read, write, and manage your LogSeq graph.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
340
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP server for LogSeq Connect Claude to your LogSeq knowledge base. Read, create, and manage pages — with optional semantic vector search and DB-mode graph support.

✨ What You Can Do

Transform your LogSeq knowledge base into an AI-powered workspace! This MCP server enables Claude to seamlessly interact with your LogSeq graphs.

🎯 Real-World Examples

📊 Intelligent Knowledge Management

"Analyze all my project notes from the past month and create a status summary"
"Find pages mentioning 'machine learning' and create a study roadmap"
"Search for incomplete tasks across all my pages"

📝 Automated Content Creation

"Create a new page called 'Today's Standup' with my meeting notes"
"Add today's progress update to my existing project timeline page"  
"Create a weekly review page from my recent notes"

🔍 Smart Research & Analysis

"Compare my notes on React vs Vue and highlight key differences"
"Find all references to 'customer feedback' and summarize themes"
"Create a knowledge map connecting related topics across pages"

🧠 Semantic Search (optional, requires vector setup)

"Find everything I wrote about burnout, even if I didn't use that word"
"What notes relate to my thoughts on deep work?"
"Search across my Dutch and English notes for ideas about productivity"

🤝 Meeting & Documentation Workflow

"Read my meeting notes and create individual task pages for each action item"
"Get my journal entries from this week and create a summary page"
"Search for 'Q4 planning' and organize all related content into a new overview page"

💡 Key Benefits

  • Zero Context Switching: Claude works directly with your LogSeq data
  • Preserve Your Workflow: No need to export or copy content manually
  • Intelligent Organization: AI-powered page creation, linking, and search
  • **Enhanced Produ
Read from source at commit 6c8d8e488d89OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-logseq --env LOGSEQ_API_TOKEN=${LOGSEQ_API_TOKEN} --env MCP_HTTP_AUTH_TOKEN=${MCP_HTTP_AUTH_TOKEN} -- uvx mcp-logseq
claude-desktop
{
  "mcpServers": {
    "mcp-logseq": {
      "command": "uvx",
      "args": [
        "mcp-logseq"
      ],
      "env": {
        "LOGSEQ_API_TOKEN": "${LOGSEQ_API_TOKEN}",
        "MCP_HTTP_AUTH_TOKEN": "${MCP_HTTP_AUTH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
fake_toolread
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (16)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/mcp_logseq/__init__.py:22
p.add_argument("--insecure", action="store_true",
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/mcp_logseq/__init__.py:51
f"loopback address, or pass --insecure to override (not recommended "
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/integration/test_http_serving.py:38
TOKEN = "journal-profile-token"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:103
LOGSEQ_API_URL = "http://127.0.0.1:12315"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
TESTING.md:193
"http://127.0.0.1:12315/api",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/test_block_id_preservation.py:16
URL = "http://127.0.0.1:12315/api"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/test_db_properties.py:54
responses.POST, "http://127.0.0.1:12315/api",
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/test_db_properties.py:60
responses.POST, "http://127.0.0.1:12315/api",
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
tests/unit/test_cli.py:144
args = parse_args(["--transport", "http", "--host", "0.0.0.0", "--insecure"])
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:266
- **`MCP_HTTP_AUTH_TOKEN`** (required for `--transport http`): Bearer token clients must send as `Authorization: Bearer <token>`. The server refuses to start in HTTP mode without it. See [Serving over
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/SERVING.md:32
HTTP mode **requires** `MCP_HTTP_AUTH_TOKEN`; the server exits if it is missing. Clients authenticate with `Authorization: Bearer <token>` and target the MCP endpoint at **`/mcp`**. (A bare POST to `/
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CHANGELOG.md:101
- Embedding provider API keys can be read from an environment variable via
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
VECTOR_SEARCH.md:103
`api_key_env` names an environment variable to read the API key from at
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/SERVING.md:53
# "personal" — broad read/write, but credentials stay invisible.
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/superpowers/plans/2026-06-14-http-transport-secure-serving.md:407
# "personal" — broad read/write, but credentials stay invisible.
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/superpowers/plans/2026-07-11-embedder-api-key-env.md:253
`api_key_env` names an environment variable to read the API key from at
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 6c8d8e488d89full audit observations/trust-audit/mcp-server/ergut__logseq-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-076c8d8e488d89BLOCKD69first audit
06

Questions

What is the LogSeq MCP server?

MCP server to interact with LogSeq via its Local HTTP API - enabling AI assistants like Claude to seamlessly read, write, and manage your LogSeq graph.

What tools does LogSeq expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is LogSeq safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does LogSeq need?

It reads LOGSEQ_API_TOKEN and MCP_HTTP_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does LogSeq run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp-logseq.

How current is this page?

The grade is for one exact copy of the source (6c8d8e488d89), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement