GalaxyCAUTION
MCP server for Galaxy bioinformatics platform - connect, execute tools, and manage workflows
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This project provides a Model Context Protocol (MCP) server for interacting with the Galaxy bioinformatics platform. It enables AI assistants and other clients to connect to Galaxy instances, search and execute tools, manage workflows, and access other features of the Galaxy ecosystem.
Project Overview
The repository holds two independent implementations of the same Galaxy operation set:
mcp-server-galaxy-py/-- the Python MCP server, published to
PyPI as galaxy-mcp. It reaches Galaxy through BioBlend and carries the larger tool surface. See the Python README.
galaxy-agent-tools/-- a TypeScript pnpm workspace offering the
same operations two ways: a galaxy-cli command-line tool and a galaxy-mcp (Node) MCP server, both built on a shared framework-free core. See the galaxy-agent-tools README.
The two are meant to stay in step: an operation keeps its name and its meaning across both. They are still separate codebases with separate release trains, though, so each README lists the operations that surface actually has -- read the one you are using.
ROADMAP.md explains why there are two implementations, how they relate to Galaxy's built-in MCP server, and what comes next. PARITY.md is the generated, CI-checked record of where they differ.
Key Features
- Galaxy Connection: Connect to any Galaxy instance with a URL and API key
- OAuth Login (optional): Offer browser-based sign-in that exchanges credentials for temporary Galaxy API keys
- Server Information: Retrieve comprehensive server details including version, configuration, and capabilities
- Tools Management: Search the tool catalog, inspect a tool's inputs, and execute Galaxy tools
- User-Defined Tools: Create, list, run, and deactivate unprivileged user-defined tools
- Workflow Integration: Find an
3bc9043748b6OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add galaxy-mcp --env GALAXY_API_KEY=${GALAXY_API_KEY} -- None galaxy-mcp==1.4.0Exposed tools (44)
32 read · 11 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
BWA | read | Map low-divergent sequences |
Concatenate | read | datasets tail-to-head |
Divider | read | |
FastQC | read | Quality control for FASTQ |
Trimmomatic | read | Trimming reads |
cancel_workflow_invocation | read | |
connect | read | |
create_history | write | |
create_user_tool | write | Create a user-defined tool in Galaxy from a YAML tool definition. |
delete_user_tool | destructive | Deactivate a user-defined tool. Deactivated tools are not loaded into the toolbox. |
download_dataset | read | |
get_collection_details | read | |
get_dataset_details | read | |
get_histories | read | |
get_history_contents | read | |
get_history_details | read | |
get_invocations | read | |
get_iwc_workflow_details | read | |
get_iwc_workflows | read | |
get_job_details | read | |
get_page | read | Get a page and the content of its latest revision. |
get_server_info | read | |
get_tool_citations | read | |
get_tool_details | read | |
get_tool_input_template | read | Return a ready-to-fill ``inputs`` skeleton for a tool, plus a compact schema. |
get_tool_panel | read | |
get_tool_run_examples | write | |
get_user | read | |
get_workflow_details | read | |
get_workflow_input_template | write | Return a ready-to-fill template plus a run guide for a workflow. |
import_workflow_from_iwc | write | |
invoke_workflow | write | |
list_history_ids | read | |
list_user_tools | read | List user-defined tools belonging to the current user, one page at a time. |
list_workflows | read | |
recommend_iwc_workflows | read | |
run_tool | write | |
run_user_tool | write | Run a user-defined tool via the standard Galaxy tools API. |
search_iwc_workflows | read | |
search_tools_by_keywords | read | |
search_tools_by_name | read | |
update_history | write | |
upload_file | write | |
upload_file_from_url | write |
Trust audit
CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (24)
const server = buildServer({ baseUrl, apiKey: "envelope-parity-not-a-key" });delete_user_tool
.dependency-cruiser.cjs
.pre-commit-config.yaml
* `hashlib.sha1(buffer.encode()).hexdigest()`, refusal included.
return createHash("sha1").update(s, "utf8").digest("hex");"../../../../mcp-server-galaxy-py/tests/testdata/envelopes/",
const { __resetIwcCacheForTest } = await import("../../galaxy-ops/src/iwc-manifest");const { __clearRecommendationCacheForTest } = await import("../../galaxy-ops/src/mulled");const { __resetIwcCacheForTest } = await import("../../galaxy-ops/src/iwc-manifest");const { __clearRecommendationCacheForTest } = await import("../../galaxy-ops/src/mulled");"name": "nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
"name": "nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
"name": "nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn
expect(cleanReadmeSummary("# Title\n\nBody text here.")).toBe("# Title Body text here.",
expect(cleanReadmeSummary("alphabeta gamma")).toBe("alphabeta gamma");["", "zero width no-break space -- trim() strips this one, pydantic refuses it"],
["", "zero width space"],
typescript, dependency-cruiser
commander, yaml, zod, @types/node, execa, tsup, vitest, typescript
@modelcontextprotocol/sdk, zod, @types/node, tsup, tsx, vitest, typescript
@galaxyproject/galaxy-api-client, openapi-fetch, tus-js-client, zod, @types/node, esbuild, tsup, typescript
Set your [Galaxy](https://galaxyproject.org/) connection, then run a command:
Gates applied: no_behavioural_pass.
3bc9043748b6full audit observations/trust-audit/mcp-server/galaxyproject__galaxy.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 3bc9043748b6 | CAUTION | C | 79 | first audit |
Questions
What is the Galaxy MCP server?
MCP server for Galaxy bioinformatics platform - connect, execute tools, and manage workflows
What tools does Galaxy expose?
44 in total: 32 read-only, 11 that write, and 1 that can delete or overwrite (delete_user_tool). Every one is listed on this page with its risk.
Is Galaxy safe to connect to an agent?
With care. The audit graded it C (79/100) and found 24 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Galaxy need?
It reads GALAXY_API_KEY, GALAXY_MCP_SESSION_SECRET and GALAXY_TEST_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Galaxy run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @galaxyproject/galaxy-ops at 0.3.1.
How current is this page?
The grade is for one exact copy of the source (3bc9043748b6), read on 2026-10-08. The repository is watched and re-audited when it changes.