GraphlitSAFE
Model Context Protocol (MCP) Server for Graphlit Platform
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://badge.fury.io/js/graphlit-mcp-server) [](https://smithery.ai/server/@graphlit/graphlit-mcp-server)
Overview
The Model Context Protocol (MCP) Server enables integration between MCP clients and the Graphlit service. This document outlines the setup process and provides a basic example of using the client.
Ingest anything from Slack, Discord, websites, Google Drive, email, Jira, Linear or GitHub into a Graphlit project - and then search and retrieve relevant knowledge within an MCP client like Cursor, Windsurf, Goose or Cline.
Your Graphlit project acts as a searchable, and RAG-ready knowledge base across all your developer and product management tools.
Documents (PDF, DOCX, PPTX, etc.) and HTML web pages will be extracted to Markdown upon ingestion. Audio and video files will be transcribed upon ingestion.
Web crawling and web search are built-in as MCP tools, with no need to integrate other tools like Firecrawl, Exa, etc. separately.
You can read more about the MCP Server use cases and features on our blog.
Watch our latest YouTube video on using the Graphlit MCP Server with the Goose MCP client.
For any questions on using the MCP Server, please join our Discord community and post on the #mcp channel.
Tools
Retrieval
- Query Contents
- Query Collections
- Query Feeds
- Query Conversations
- Retrieve Relevant Sources
- Retrieve Similar Images
- Visually Describe Image
RAG
- Prompt LLM Conversation
Extraction
- Extra
c045b561e7adOBSERVED · 2026-10-02Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add graphlit-mcp-server --env BOX_CLIENT_SECRET=${BOX_CLIENT_SECRET} --env BOX_REFRESH_TOKEN=${BOX_REFRESH_TOKEN} --env DISCORD_BOT_TOKEN=${DISCORD_BOT_TOKEN} --env DROPBOX_APP_KEY=${DROPBOX_APP_KEY} -- npx -y [email protected]{
"mcpServers": {
"graphlit-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"BOX_CLIENT_SECRET": "${BOX_CLIENT_SECRET}",
"BOX_REFRESH_TOKEN": "${BOX_REFRESH_TOKEN}",
"DISCORD_BOT_TOKEN": "${DISCORD_BOT_TOKEN}",
"DROPBOX_APP_KEY": "${DROPBOX_APP_KEY}"
}
}
}
}Exposed tools (73)
67 read · 2 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
addContentsToCollection | write | Add contents to a collection. Accepts a collection identifier and a list of content identifiers to add to collection. Returns the collection identifier. |
askGraphlit | read | |
configureProject | read | Configures the default content workflow and conversation specification for the Graphlit project. Only needed if user asks to configure the project defaults. *Do not* call unless specifically asked for by the user. To reset the project configuration to |
createCollection | write | Create a collection. Accepts a collection name, and optional list of content identifiers to add to collection. Returns the collection identifier |
deleteCollection | destructive | Deletes collection from Graphlit knowledge base. Does *not* delete the contents in the collection, only the collection itself. Accepts collection identifier. Returns the collection identifier and collection state, i.e. Deleted. |
deleteCollections | destructive | Deletes collections from Graphlit knowledge base. Does *not* delete the contents in the collections, only the collections themselves. Accepts optional limit of how many collections to delete, defaults to 100. Returns the collection identifiers and collection state, i.e. Deleted. |
deleteContent | read | Deletes content from Graphlit knowledge base. Accepts content identifier. Returns the content identifier and content state, i.e. Deleted. |
deleteContents | read | Deletes contents from Graphlit knowledge base. Accepts optional content type and file type filters to limit the contents which will be deleted. Also accepts optional limit of how many contents to delete, defaults to 1000. Returns the content identifiers and content state, i.e. Deleted. |
deleteConversation | read | Deletes conversation from Graphlit knowledge base. Accepts conversation identifier. Returns the conversation identifier and content state, i.e. Deleted. |
deleteConversations | read | Deletes conversations from Graphlit knowledge base. Accepts optional limit of how many conversations to delete, defaults to 100. Returns the conversation identifiers and conversation state, i.e. Deleted. |
deleteFeed | destructive | Deletes feed from Graphlit knowledge base. *Does* delete the contents in the feed, in addition to the feed itself. Accepts feed identifier. Returns the feed identifier and feed state, i.e. Deleted. |
deleteFeeds | read | |
describeImageContent | read | Prompts vision LLM and returns description of image content. Accepts content identifier as string, and optional prompt for image description. Returns Markdown text from LLM completion. |
describeImageUrl | read | Prompts vision LLM and returns completion. Does *not* ingest image into Graphlit knowledge base. Accepts image URL as string. Returns Markdown text from LLM completion. |
extractText | read | Extracts JSON data from text using LLM. Accepts text to be extracted, and JSON schema which describes the data which will be extracted. JSON schema needs be of type |
ingestBoxFiles | read | Ingests files from Box into Graphlit knowledge base. Accepts optional Box folder identifier, and an optional read limit for the number of files to ingest. If no folder identifier provided, ingests files from root Box folder (i.e. |
ingestDiscordMessages | read | |
ingestDropboxFiles | read | |
ingestFile | read | |
ingestGitHubFiles | read | Ingests files from GitHub repository into Graphlit knowledge base. Accepts GitHub repository owner and repository name and an optional read limit for the number of files to ingest. For example, for GitHub repository (https://github.com/openai/tiktoken), |
ingestGitHubIssues | read | Ingests issues from GitHub repository into Graphlit knowledge base. Accepts GitHub repository owner and repository name and an optional read limit for the number of issues to ingest. For example, for GitHub repository (https://github.com/openai/tiktoken), |
ingestGoogleDriveFiles | read | |
ingestGoogleEmail | read | |
ingestJiraIssues | read | |
ingestLinearIssues | read | |
ingestMemory | read | |
ingestMicrosoftEmail | read | |
ingestMicrosoftTeamsMessages | read | |
ingestNotionPages | read | |
ingestOneDriveFiles | read | |
ingestRSS | read | |
ingestRedditPosts | read | |
ingestSharePointFiles | read | |
ingestSlackMessages | read | |
ingestText | read | |
ingestTwitterPosts | read | |
ingestTwitterSearch | read | |
ingestUrl | read | Ingests content from URL into Graphlit knowledge base. Can scrape a single web page, and can ingest individual Word documents, PDFs, audio recordings, videos, images, or any other unstructured data. Do *not* use for crawling a web site, which is done with |
isContentDone | read | Check if content has completed asynchronous ingestion. Accepts a content identifier which was returned from one of the non-feed ingestion tools, like ingestUrl. Returns whether the content is done or not. |
isFeedDone | read | Check if an asynchronous feed has completed ingesting all the available content. Accepts a feed identifier which was returned from one of the ingestion tools, like ingestGoogleDriveFiles. Returns whether the feed is done or not. |
listBoxFolders | read | Lists available Box folders. Requires environment variables to be configured: BOX_CLIENT_ID, BOX_CLIENT_SECRET, BOX_REFRESH_TOKEN. Returns a list of Box folders that can be used with file ingestion tools. |
listDiscordChannels | read | Lists available Discord channels in a guild. Requires environment variable to be configured: DISCORD_BOT_TOKEN. Returns a list of Discord channels that can be used with Discord ingestion tools. |
listDiscordGuilds | read | Lists available Discord guilds (servers). Requires environment variable to be configured: DISCORD_BOT_TOKEN. Returns a list of Discord guilds that the bot has access to. |
listDropboxFolders | read | Lists available Dropbox folders. Requires environment variables to be configured: DROPBOX_APP_KEY, DROPBOX_APP_SECRET, DROPBOX_REFRESH_TOKEN. Returns a list of Dropbox folders that can be used with file ingestion tools. |
listGoogleCalendars | read | Lists available Google calendars. Requires environment variables to be configured: GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET, GOOGLE_REFRESH_TOKEN. Returns a list of Google calendars that can be used with calendar ingestion tools. |
listLinearProjects | read | Lists available Linear projects. Requires environment variable to be configured: LINEAR_API_KEY. Returns a list of Linear projects, where the project name can be used with ingestLinearIssues to ingest issues into Graphlit knowledge base. |
listMicrosoftCalendars | read | Lists available Microsoft calendars. Requires environment variables to be configured: MICROSOFT_CLIENT_ID, MICROSOFT_CLIENT_SECRET, MICROSOFT_REFRESH_TOKEN. Returns a list of Microsoft calendars that can be used with calendar ingestion tools. |
listMicrosoftTeamsChannels | read | |
listMicrosoftTeamsTeams | read | |
listNotionDatabases | read | Lists available Notion databases. Requires environment variable to be configured: NOTION_API_KEY. Returns a list of Notion databases, where the database identifier can be used with ingestNotionPages to ingest pages into Graphlit knowledge base. |
listNotionPages | read | Lists pages from a Notion database. Requires environment variable to be configured: NOTION_API_KEY. Returns a list of Notion pages in the specified database. |
listSharePointFolders | read | Lists available SharePoint folders. Requires environment variables to be configured: SHAREPOINT_CLIENT_ID, SHAREPOINT_CLIENT_SECRET, SHAREPOINT_REFRESH_TOKEN. Returns a list of SharePoint folders, which can be used with ingestSharePointFiles to ingest files into Graphlit knowledge base. |
listSharePointLibraries | read | |
listSlackChannels | read | Lists available Slack channels. Requires environment variable to be configured: SLACK_BOT_TOKEN. Returns a list of Slack channels, where the channel name can be used with ingestSlackMessages to ingest messages into Graphlit knowledge base. |
promptConversation | read | Prompts an LLM conversation about your entire Graphlit knowledge base. Uses hybrid vector search based on user prompt for locating relevant content sources. Uses LLM to complete the user prompt with the configured LLM. Maintains conversation history between |
publishAudio | read | |
publishImage | read | Publishes text as image format, and ingests into Graphlit knowledge base. Accepts a name for the content object. Also, accepts a prompt for image generation. For example, |
queryCollections | read | Query collections from Graphlit knowledge base. Do *not* use for retrieving collection by collection identifier - retrieve collection resource instead, with URI |
queryContents | read | Query contents from Graphlit knowledge base. Do *not* use for retrieving content by content identifier - retrieve content resource instead, with URI |
queryConversations | read | Query conversations from Graphlit knowledge base. Do *not* use for retrieving conversation by conversation identifier - retrieve conversation resource instead, with URI |
queryFeeds | read | Query feeds from Graphlit knowledge base. Do *not* use for retrieving feed by feed identifier - retrieve feed resource instead, with URI |
queryProjectUsage | read | Queries project usage records. Usage record name describes the operation, i.e. |
removeContentsFromCollection | destructive | Remove contents from collection. Accepts a collection identifier and a list of content identifiers to remove from collection. Returns the collection identifier. |
retrieveImages | read | Retrieve images from Graphlit knowledge base. Provides image-specific retrieval when image similarity search is desired. Do *not* use for retrieving content by content identifier - retrieve content resource instead, with URI |
retrieveSources | read | Retrieve relevant content sources from Graphlit knowledge base. Do *not* use for retrieving content by content identifier - retrieve content resource instead, with URI |
screenshotPage | read | Screenshots web page from URL. Executes *synchronously* and returns the content identifier. |
sendEmailNotification | read | Sends an email notification to the provided email address(es). Accepts the email subject and a list of email |
sendSlackNotification | read | |
sendTwitterNotification | read | |
sendWebHookNotification | read | Sends a webhook notification to the provided URL. Accepts the webhook URL. Also accepts the text to be sent with the webhook, and an optional text type (Plain, Markdown, Html). Defaults to Markdown text type. Returns true if the notification was successfully sent, or false otherwise. |
webCrawl | read | |
webMap | read | Enumerates the web pages at or beneath the provided URL using web sitemap. Does *not* ingest web pages into Graphlit knowledge base. Accepts web site URL as string. Returns list of mapped URIs from web site. |
webSearch | read | Performs web or podcast search based on search query. Can search for web pages or anything about podcasts (i.e. episodes, topics, guest appearances). Format the search query as what would be entered into a Google search. You can use site filtering in the search query, like |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
deleteCollection, deleteCollections, deleteFeed, removeContentsFromCollection
.prettierignore
@modelcontextprotocol/sdk, graphlit-client, @types/mime-types, prettier, typescript
Gates applied: no_behavioural_pass.
c045b561e7adfull audit observations/trust-audit/mcp-server/graphlit__graphlit.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | c045b561e7ad | SAFE | B | 89 | first audit |
Questions
What is the Graphlit MCP server?
Model Context Protocol (MCP) Server for Graphlit Platform
What tools does Graphlit expose?
73 in total: 67 read-only, 2 that write, and 4 that can delete or overwrite (deleteCollection, deleteCollections, deleteFeed, removeContentsFromCollection). Every one is listed on this page with its risk.
Is Graphlit safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Graphlit need?
It reads BOX_CLIENT_SECRET, BOX_REFRESH_TOKEN, DISCORD_BOT_TOKEN, DROPBOX_APP_KEY, DROPBOX_APP_SECRET, DROPBOX_REFRESH_TOKEN, GITHUB_PERSONAL_ACCESS_TOKEN, GOOGLE_CLIENT_SECRET, GOOGLE_DRIVE_CLIENT_SECRET, GOOGLE_DRIVE_REFRESH_TOKEN, GOOGLE_EMAIL_CLIENT_SECRET and GOOGLE_EMAIL_REFRESH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Graphlit run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as graphlit-mcp-server at 1.0.1.
How current is this page?
The grade is for one exact copy of the source (c045b561e7ad), read on 2026-10-02. The repository is watched and re-audited when it changes.