Atlas / MCP servers / graphlit / Graphlit

GraphlitSAFE

mcp/graphlit/graphlit

Model Context Protocol (MCP) Server for Graphlit Platform

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
73 67r · 2w · 4d
Transport
stdio
License
MIT
Stars
379
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://badge.fury.io/js/graphlit-mcp-server) [](https://smithery.ai/server/@graphlit/graphlit-mcp-server)

Overview

The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. This document outlines the setup process and provides a basic example of using the client.

Ingest anything from Slack, Discord, websites, Google Drive, email, Jira, Linear or GitHub into a Graphlit project - and then search and retrieve relevant knowledge within an MCP client like Cursor, Windsurf, Goose or Cline.

Your Graphlit project acts as a searchable, and RAG-ready knowledge base across all your developer and product management tools.

Documents (PDF, DOCX, PPTX, etc.) and HTML web pages will be extracted to Markdown upon ingestion. Audio and video files will be transcribed upon ingestion.

Web crawling and web search are built-in as MCP tools, with no need to integrate other tools like Firecrawl, Exa, etc. separately.

You can read more about the MCP Server use cases and features on our blog.

Watch our latest YouTube video on using the Graphlit MCP Server with the Goose MCP client.

For any questions on using the MCP Server, please join our Discord community and post on the #mcp channel.

Tools

Retrieval

  • Query Contents
  • Query Collections
  • Query Feeds
  • Query Conversations
  • Retrieve Relevant Sources
  • Retrieve Similar Images
  • Visually Describe Image

RAG

  • Prompt LLM Conversation

Extraction

  • Extra
Read from source at commit c045b561e7adOBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add graphlit-mcp-server --env BOX_CLIENT_SECRET=${BOX_CLIENT_SECRET} --env BOX_REFRESH_TOKEN=${BOX_REFRESH_TOKEN} --env DISCORD_BOT_TOKEN=${DISCORD_BOT_TOKEN} --env DROPBOX_APP_KEY=${DROPBOX_APP_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "graphlit-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "BOX_CLIENT_SECRET": "${BOX_CLIENT_SECRET}",
        "BOX_REFRESH_TOKEN": "${BOX_REFRESH_TOKEN}",
        "DISCORD_BOT_TOKEN": "${DISCORD_BOT_TOKEN}",
        "DROPBOX_APP_KEY": "${DROPBOX_APP_KEY}"
      }
    }
  }
}
03

Exposed tools (73)

67 read · 2 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
addContentsToCollectionwriteAdd contents to a collection. Accepts a collection identifier and a list of content identifiers to add to collection. Returns the collection identifier.
askGraphlitread
configureProjectreadConfigures the default content workflow and conversation specification for the Graphlit project. Only needed if user asks to configure the project defaults. *Do not* call unless specifically asked for by the user. To reset the project configuration to
createCollectionwriteCreate a collection. Accepts a collection name, and optional list of content identifiers to add to collection. Returns the collection identifier
deleteCollectiondestructiveDeletes collection from Graphlit knowledge base. Does *not* delete the contents in the collection, only the collection itself. Accepts collection identifier. Returns the collection identifier and collection state, i.e. Deleted.
deleteCollectionsdestructiveDeletes collections from Graphlit knowledge base. Does *not* delete the contents in the collections, only the collections themselves. Accepts optional limit of how many collections to delete, defaults to 100. Returns the collection identifiers and collection state, i.e. Deleted.
deleteContentreadDeletes content from Graphlit knowledge base. Accepts content identifier. Returns the content identifier and content state, i.e. Deleted.
deleteContentsreadDeletes contents from Graphlit knowledge base. Accepts optional content type and file type filters to limit the contents which will be deleted. Also accepts optional limit of how many contents to delete, defaults to 1000. Returns the content identifiers and content state, i.e. Deleted.
deleteConversationreadDeletes conversation from Graphlit knowledge base. Accepts conversation identifier. Returns the conversation identifier and content state, i.e. Deleted.
deleteConversationsreadDeletes conversations from Graphlit knowledge base. Accepts optional limit of how many conversations to delete, defaults to 100. Returns the conversation identifiers and conversation state, i.e. Deleted.
deleteFeeddestructiveDeletes feed from Graphlit knowledge base. *Does* delete the contents in the feed, in addition to the feed itself. Accepts feed identifier. Returns the feed identifier and feed state, i.e. Deleted.
deleteFeedsread
describeImageContentreadPrompts vision LLM and returns description of image content. Accepts content identifier as string, and optional prompt for image description. Returns Markdown text from LLM completion.
describeImageUrlreadPrompts vision LLM and returns completion. Does *not* ingest image into Graphlit knowledge base. Accepts image URL as string. Returns Markdown text from LLM completion.
extractTextreadExtracts JSON data from text using LLM. Accepts text to be extracted, and JSON schema which describes the data which will be extracted. JSON schema needs be of type
ingestBoxFilesreadIngests files from Box into Graphlit knowledge base. Accepts optional Box folder identifier, and an optional read limit for the number of files to ingest. If no folder identifier provided, ingests files from root Box folder (i.e.
ingestDiscordMessagesread
ingestDropboxFilesread
ingestFileread
ingestGitHubFilesreadIngests files from GitHub repository into Graphlit knowledge base. Accepts GitHub repository owner and repository name and an optional read limit for the number of files to ingest. For example, for GitHub repository (https://github.com/openai/tiktoken),
ingestGitHubIssuesreadIngests issues from GitHub repository into Graphlit knowledge base. Accepts GitHub repository owner and repository name and an optional read limit for the number of issues to ingest. For example, for GitHub repository (https://github.com/openai/tiktoken),
ingestGoogleDriveFilesread
ingestGoogleEmailread
ingestJiraIssuesread
ingestLinearIssuesread
ingestMemoryread
ingestMicrosoftEmailread
ingestMicrosoftTeamsMessagesread
ingestNotionPagesread
ingestOneDriveFilesread
ingestRSSread
ingestRedditPostsread
ingestSharePointFilesread
ingestSlackMessagesread
ingestTextread
ingestTwitterPostsread
ingestTwitterSearchread
ingestUrlreadIngests content from URL into Graphlit knowledge base. Can scrape a single web page, and can ingest individual Word documents, PDFs, audio recordings, videos, images, or any other unstructured data. Do *not* use for crawling a web site, which is done with
isContentDonereadCheck if content has completed asynchronous ingestion. Accepts a content identifier which was returned from one of the non-feed ingestion tools, like ingestUrl. Returns whether the content is done or not.
isFeedDonereadCheck if an asynchronous feed has completed ingesting all the available content. Accepts a feed identifier which was returned from one of the ingestion tools, like ingestGoogleDriveFiles. Returns whether the feed is done or not.
listBoxFoldersreadLists available Box folders. Requires environment variables to be configured: BOX_CLIENT_ID, BOX_CLIENT_SECRET, BOX_REFRESH_TOKEN. Returns a list of Box folders that can be used with file ingestion tools.
listDiscordChannelsreadLists available Discord channels in a guild. Requires environment variable to be configured: DISCORD_BOT_TOKEN. Returns a list of Discord channels that can be used with Discord ingestion tools.
listDiscordGuildsreadLists available Discord guilds (servers). Requires environment variable to be configured: DISCORD_BOT_TOKEN. Returns a list of Discord guilds that the bot has access to.
listDropboxFoldersreadLists available Dropbox folders. Requires environment variables to be configured: DROPBOX_APP_KEY, DROPBOX_APP_SECRET, DROPBOX_REFRESH_TOKEN. Returns a list of Dropbox folders that can be used with file ingestion tools.
listGoogleCalendarsreadLists available Google calendars. Requires environment variables to be configured: GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET, GOOGLE_REFRESH_TOKEN. Returns a list of Google calendars that can be used with calendar ingestion tools.
listLinearProjectsreadLists available Linear projects. Requires environment variable to be configured: LINEAR_API_KEY. Returns a list of Linear projects, where the project name can be used with ingestLinearIssues to ingest issues into Graphlit knowledge base.
listMicrosoftCalendarsreadLists available Microsoft calendars. Requires environment variables to be configured: MICROSOFT_CLIENT_ID, MICROSOFT_CLIENT_SECRET, MICROSOFT_REFRESH_TOKEN. Returns a list of Microsoft calendars that can be used with calendar ingestion tools.
listMicrosoftTeamsChannelsread
listMicrosoftTeamsTeamsread
listNotionDatabasesreadLists available Notion databases. Requires environment variable to be configured: NOTION_API_KEY. Returns a list of Notion databases, where the database identifier can be used with ingestNotionPages to ingest pages into Graphlit knowledge base.
listNotionPagesreadLists pages from a Notion database. Requires environment variable to be configured: NOTION_API_KEY. Returns a list of Notion pages in the specified database.
listSharePointFoldersreadLists available SharePoint folders. Requires environment variables to be configured: SHAREPOINT_CLIENT_ID, SHAREPOINT_CLIENT_SECRET, SHAREPOINT_REFRESH_TOKEN. Returns a list of SharePoint folders, which can be used with ingestSharePointFiles to ingest files into Graphlit knowledge base.
listSharePointLibrariesread
listSlackChannelsreadLists available Slack channels. Requires environment variable to be configured: SLACK_BOT_TOKEN. Returns a list of Slack channels, where the channel name can be used with ingestSlackMessages to ingest messages into Graphlit knowledge base.
promptConversationreadPrompts an LLM conversation about your entire Graphlit knowledge base. Uses hybrid vector search based on user prompt for locating relevant content sources. Uses LLM to complete the user prompt with the configured LLM. Maintains conversation history between
publishAudioread
publishImagereadPublishes text as image format, and ingests into Graphlit knowledge base. Accepts a name for the content object. Also, accepts a prompt for image generation. For example,
queryCollectionsreadQuery collections from Graphlit knowledge base. Do *not* use for retrieving collection by collection identifier - retrieve collection resource instead, with URI
queryContentsreadQuery contents from Graphlit knowledge base. Do *not* use for retrieving content by content identifier - retrieve content resource instead, with URI
queryConversationsreadQuery conversations from Graphlit knowledge base. Do *not* use for retrieving conversation by conversation identifier - retrieve conversation resource instead, with URI
queryFeedsreadQuery feeds from Graphlit knowledge base. Do *not* use for retrieving feed by feed identifier - retrieve feed resource instead, with URI
queryProjectUsagereadQueries project usage records. Usage record name describes the operation, i.e.
removeContentsFromCollectiondestructiveRemove contents from collection. Accepts a collection identifier and a list of content identifiers to remove from collection. Returns the collection identifier.
retrieveImagesreadRetrieve images from Graphlit knowledge base. Provides image-specific retrieval when image similarity search is desired. Do *not* use for retrieving content by content identifier - retrieve content resource instead, with URI
retrieveSourcesreadRetrieve relevant content sources from Graphlit knowledge base. Do *not* use for retrieving content by content identifier - retrieve content resource instead, with URI
screenshotPagereadScreenshots web page from URL. Executes *synchronously* and returns the content identifier.
sendEmailNotificationreadSends an email notification to the provided email address(es). Accepts the email subject and a list of email
sendSlackNotificationread
sendTwitterNotificationread
sendWebHookNotificationreadSends a webhook notification to the provided URL. Accepts the webhook URL. Also accepts the text to be sent with the webhook, and an optional text type (Plain, Markdown, Html). Defaults to Markdown text type. Returns true if the notification was successfully sent, or false otherwise.
webCrawlread
webMapreadEnumerates the web pages at or beneath the provided URL using web sitemap. Does *not* ingest web pages into Graphlit knowledge base. Accepts web site URL as string. Returns list of mapped URIs from web site.
webSearchreadPerforms web or podcast search based on search query. Can search for web pages or anything about podcasts (i.e. episodes, topics, guest appearances). Format the search query as what would be entered into a Google search. You can use site filtering in the search query, like
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
deleteCollection, deleteCollections, deleteFeed, removeContentsFromCollection
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, graphlit-client, @types/mime-types, prettier, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-02 · audit v0.4.1 · source sha c045b561e7adfull audit observations/trust-audit/mcp-server/graphlit__graphlit.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-02c045b561e7adSAFEB89first audit
06

Questions

What is the Graphlit MCP server?

Model Context Protocol (MCP) Server for Graphlit Platform

What tools does Graphlit expose?

73 in total: 67 read-only, 2 that write, and 4 that can delete or overwrite (deleteCollection, deleteCollections, deleteFeed, removeContentsFromCollection). Every one is listed on this page with its risk.

Is Graphlit safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Graphlit need?

It reads BOX_CLIENT_SECRET, BOX_REFRESH_TOKEN, DISCORD_BOT_TOKEN, DROPBOX_APP_KEY, DROPBOX_APP_SECRET, DROPBOX_REFRESH_TOKEN, GITHUB_PERSONAL_ACCESS_TOKEN, GOOGLE_CLIENT_SECRET, GOOGLE_DRIVE_CLIENT_SECRET, GOOGLE_DRIVE_REFRESH_TOKEN, GOOGLE_EMAIL_CLIENT_SECRET and GOOGLE_EMAIL_REFRESH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Graphlit run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as graphlit-mcp-server at 1.0.1.

How current is this page?

The grade is for one exact copy of the source (c045b561e7ad), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement