Atlas / MCP servers / galaxyproject / Galaxy

GalaxyCAUTION

mcp/galaxyproject/galaxy

MCP server for Galaxy bioinformatics platform - connect, execute tools, and manage workflows

Verdict
CAUTION
Grade
C
Trust score
79 /100
Exposed tools
44 32r · 11w · 1d
Transport
stdio · streamable-http
License
MIT
Stars
39
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

This project provides a Model Context Protocol (MCP) server for interacting with the Galaxy bioinformatics platform. It enables AI assistants and other clients to connect to Galaxy instances, search and execute tools, manage workflows, and access other features of the Galaxy ecosystem.

Project Overview

The repository holds two independent implementations of the same Galaxy operation set:

  • mcp-server-galaxy-py/ -- the Python MCP server, published to

PyPI as galaxy-mcp. It reaches Galaxy through BioBlend and carries the larger tool surface. See the Python README.

  • galaxy-agent-tools/ -- a TypeScript pnpm workspace offering the

same operations two ways: a galaxy-cli command-line tool and a galaxy-mcp (Node) MCP server, both built on a shared framework-free core. See the galaxy-agent-tools README.

The two are meant to stay in step: an operation keeps its name and its meaning across both. They are still separate codebases with separate release trains, though, so each README lists the operations that surface actually has -- read the one you are using.

ROADMAP.md explains why there are two implementations, how they relate to Galaxy's built-in MCP server, and what comes next. PARITY.md is the generated, CI-checked record of where they differ.

Key Features

  • Galaxy Connection: Connect to any Galaxy instance with a URL and API key
  • OAuth Login (optional): Offer browser-based sign-in that exchanges credentials for temporary Galaxy API keys
  • Server Information: Retrieve comprehensive server details including version, configuration, and capabilities
  • Tools Management: Search the tool catalog, inspect a tool's inputs, and execute Galaxy tools
  • User-Defined Tools: Create, list, run, and deactivate unprivileged user-defined tools
  • Workflow Integration: Find an
Read from source at commit 3bc9043748b6OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add galaxy-mcp --env GALAXY_API_KEY=${GALAXY_API_KEY} -- None galaxy-mcp==1.4.0
03

Exposed tools (44)

32 read · 11 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
BWAreadMap low-divergent sequences
Concatenatereaddatasets tail-to-head
Dividerread
FastQCreadQuality control for FASTQ
TrimmomaticreadTrimming reads
cancel_workflow_invocationread
connectread
create_historywrite
create_user_toolwriteCreate a user-defined tool in Galaxy from a YAML tool definition.
delete_user_tooldestructiveDeactivate a user-defined tool. Deactivated tools are not loaded into the toolbox.
download_datasetread
get_collection_detailsread
get_dataset_detailsread
get_historiesread
get_history_contentsread
get_history_detailsread
get_invocationsread
get_iwc_workflow_detailsread
get_iwc_workflowsread
get_job_detailsread
get_pagereadGet a page and the content of its latest revision.
get_server_inforead
get_tool_citationsread
get_tool_detailsread
get_tool_input_templatereadReturn a ready-to-fill ``inputs`` skeleton for a tool, plus a compact schema.
get_tool_panelread
get_tool_run_exampleswrite
get_userread
get_workflow_detailsread
get_workflow_input_templatewriteReturn a ready-to-fill template plus a run guide for a workflow.
import_workflow_from_iwcwrite
invoke_workflowwrite
list_history_idsread
list_user_toolsreadList user-defined tools belonging to the current user, one page at a time.
list_workflowsread
recommend_iwc_workflowsread
run_toolwrite
run_user_toolwriteRun a user-defined tool via the standard Galaxy tools API.
search_iwc_workflowsread
search_tools_by_keywordsread
search_tools_by_nameread
update_historywrite
upload_filewrite
upload_file_from_urlwrite
04

Trust audit

CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (24)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
galaxy-agent-tools/packages/galaxy-mcp/test/envelope-parity.test.ts:144
const server = buildServer({ baseUrl, apiKey: "envelope-parity-not-a-key" });
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_user_tool
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
galaxy-agent-tools/.dependency-cruiser.cjs
.dependency-cruiser.cjs
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
mcp-server-galaxy-py/.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
galaxy-agent-tools/packages/galaxy-ops/src/mulled.ts:320
* `hashlib.sha1(buffer.encode()).hexdigest()`, refusal included.
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
galaxy-agent-tools/packages/galaxy-ops/src/mulled.ts:333
return createHash("sha1").update(s, "utf8").digest("hex");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
galaxy-agent-tools/packages/galaxy-cli/test/envelope-parity.test.ts:36
"../../../../mcp-server-galaxy-py/tests/testdata/envelopes/",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
galaxy-agent-tools/packages/galaxy-cli/test/envelope-parity.test.ts:193
const { __resetIwcCacheForTest } = await import("../../galaxy-ops/src/iwc-manifest");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
galaxy-agent-tools/packages/galaxy-cli/test/envelope-parity.test.ts:194
const { __clearRecommendationCacheForTest } = await import("../../galaxy-ops/src/mulled");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
galaxy-agent-tools/packages/galaxy-cli/test/envelope-parity.test.ts:327
const { __resetIwcCacheForTest } = await import("../../galaxy-ops/src/iwc-manifest");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
galaxy-agent-tools/packages/galaxy-cli/test/envelope-parity.test.ts:328
const { __clearRecommendationCacheForTest } = await import("../../galaxy-ops/src/mulled");
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
mcp-server-galaxy-py/tests/testdata/envelopes/list_history_ids/budget_boundary.galaxy.json:14
"name": "nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
mcp-server-galaxy-py/tests/testdata/envelopes/list_history_ids/budget_boundary.galaxy.json:18
"name": "nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
mcp-server-galaxy-py/tests/testdata/envelopes/list_history_ids/budget_boundary.json:5
"name": "nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
galaxy-agent-tools/packages/galaxy-ops/test/iwc-manifest.test.ts:126
expect(cleanReadmeSummary("# Title\n\nBody text here.")).toBe(
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
galaxy-agent-tools/packages/galaxy-ops/test/iwc-manifest.test.ts:127
"# Title Body text here.",
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
galaxy-agent-tools/packages/galaxy-ops/test/iwc-manifest.test.ts:140
expect(cleanReadmeSummary("alphabeta gamma")).toBe("alphabeta gamma");
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
galaxy-agent-tools/packages/galaxy-ops/test/laxen.test.ts:117
["", "zero width no-break space -- trim() strips this one, pydantic refuses it"],
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
galaxy-agent-tools/packages/galaxy-ops/test/laxen.test.ts:119
["", "zero width space"],
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
galaxy-agent-tools/package.json
typescript, dependency-cruiser
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
galaxy-agent-tools/packages/galaxy-cli/package.json
commander, yaml, zod, @types/node, execa, tsup, vitest, typescript
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
galaxy-agent-tools/packages/galaxy-mcp/package.json
@modelcontextprotocol/sdk, zod, @types/node, tsup, tsx, vitest, typescript
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
galaxy-agent-tools/packages/galaxy-ops/package.json
@galaxyproject/galaxy-api-client, openapi-fetch, tus-js-client, zod, @types/node, esbuild, tsup, typescript
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
galaxy-agent-tools/packages/galaxy-cli/README.md:20
Set your [Galaxy](https://galaxyproject.org/) connection, then run a command:
Why it matters. remote text is to be obeyed as instructions

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 3bc9043748b6full audit observations/trust-audit/mcp-server/galaxyproject__galaxy.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-083bc9043748b6CAUTIONC79first audit
06

Questions

What is the Galaxy MCP server?

MCP server for Galaxy bioinformatics platform - connect, execute tools, and manage workflows

What tools does Galaxy expose?

44 in total: 32 read-only, 11 that write, and 1 that can delete or overwrite (delete_user_tool). Every one is listed on this page with its risk.

Is Galaxy safe to connect to an agent?

With care. The audit graded it C (79/100) and found 24 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Galaxy need?

It reads GALAXY_API_KEY, GALAXY_MCP_SESSION_SECRET and GALAXY_TEST_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Galaxy run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @galaxyproject/galaxy-ops at 0.3.1.

How current is this page?

The grade is for one exact copy of the source (3bc9043748b6), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement