Atlas / MCP servers / ianderso / gramps-evidence-mcp

gramps-evidence-mcpSAFE

mcp/ianderso/gramps-evidence-mcp

MCP server for evidence-disciplined genealogy: read/write access to a self-hosted Gramps Web tree where every fact carries a citation, plus a read-only reference layer over legacy GEDCOM exports.

Verdict
SAFE
Grade
B
Trust score
88 /100
Exposed tools
26 24r · 2w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
0
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/ianderso/gramps-evidence-mcp/actions/workflows/ci.yml) [](https://pypi.org/project/gramps-evidence-mcp/)

An MCP server that gives an AI assistant read/write access to a Gramps genealogy tree, plus a read-only "reference layer" over legacy GEDCOM exports.

96 tools, built around evidence discipline. The premise is that an assistant turned loose on a family tree will happily invent a plausible ancestor, so the write paths here are shaped to make every claim carry its source: facts are created with citations attached, uncite deletes what it orphans, parent-child links are cited independently because one citation object cannot carry two confidences, and an audit set — list_unsourced_facts, get_backlinks, find_duplicates, and server-side queries through query_objects and query_records — exists to find the places where that discipline slipped.

Legacy trees (Ancestry / FamilySearch exports) are consulted through the read-only reference layer as untrusted hints, never a source of truth.

The server is a REST client of [Gramps Web](https://www.grampsweb.org/) (`gramps-webapi`). It never touches the Gramps database files directly — see How it connects.

Living-person privacy filtering is on by default — see Privacy.

This is an independent project. It is not made, endorsed or supported by the Gramps project.

Contents

  • How it connects
  • Setup
  • Configuration
  • Client configuration
  • Remote access (Claude web / mobile)
  • The evidence model & transactions
  • [Priva
Read from source at commit def4d7370127OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add gramps-evidence-mcp --env GRAMPS_MCP_PASSWORD=${GRAMPS_MCP_PASSWORD} --env GRAMPS_MCP_TRANSKRIBUS_PASSWORD=${GRAMPS_MCP_TRANSKRIBUS_PASSWORD} -- uvx gramps-evidence-mcp==2.2.0
03

Exposed tools (26)

24 read · 2 write · 0 destructive.

ToolRiskDescription
add_citationwriteCreate a standalone Citation on a Source (or reuse an existing one).
db_statsreadCounts of people, families, events, citations, sources, repositories,
get_citationreadRead one citation: page, confidence, date, and its source.
get_eventreadGet an event: type, date, place handle, description, citation count, and
get_familyreadGet a family: relationship type, parent handles, child handles, event count.
get_jobreadCheck whether a background job has finished, and whether it worked.
get_mediareadRead one media object: path, mime type, checksum, description, date.
get_notereadRead one note in full, with its type and what it is attached to.
get_personreadGet full detail for one person: name, gender, events (with citation counts),
get_placereadRead one place: name, title, type, enclosure, coordinates and URLs.
get_report_optionsreadRead one report
get_repositoryreadGet a repository: name, type, URLs, address count, and (if available)
get_researcherreadRead the researcher details recorded for this tree.
get_sourcereadGet a source: title, author, publication info, abbreviation, linked
get_transactionreadRead one transaction in full, including the objects it changed.
list_custom_filtersreadList the custom filters already saved on this instance.
list_event_typesreadList the event type names this tree uses, with their stored integers.
list_filter_rulesreadList the filter rules Gramps offers in a namespace.
list_jobsreadList recent background jobs for this tree, newest first: undo, verify,
list_object_typesreadThe tree
list_reportsreadList the reports this Gramps instance can generate.
list_tagsreadList all tags in the tree with their handle, name, and color.
list_transactionsreadRecent writes to the tree: what changed, when, by which user.
parse_dna_segmentsreadParse pasted shared-segment data into structured segments and totals.
reindex_searchreadRebuild the full-text index behind Gramps Web
update_citationswriteRe-write many citations
04

Trust audit

SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (11)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/live/start_server.sh:46
secret="throwaway-live-test-secret-key-not-for-real-use"
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/gramps_evidence_mcp/service.py:5426
checksum = hashlib.md5(content).hexdigest()  # noqa: S324 - matches Gramps' own
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
tests/test_new_tools.py:841
@pytest.mark.parametrize("name", ["id_ed25519", ".env", "notes.txt", "tree.ged"])
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_tool_behaviour.py:232
await tools("delete_filter", namespace="people", name=f"../../people/{person['handle']}")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_tool_behaviour.py:245
assert _seg("../../people/abc") == "..%2F..%2Fpeople%2Fabc"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:220
**public HTTPS URL**. A LAN address like `http://192.168.1.50:5000` won't work.
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:235
That serves the MCP endpoint at `http://127.0.0.1:8090/mcp`; `GRAMPS_MCP_HOST`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/live/conftest.py:71
f"GRAMPS_LIVE_URL must be a loopback address such as http://127.0.0.1:5555, "
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/live/start_server.sh:66
url="http://127.0.0.1:$port"
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_ocr_router.py:128
return Image.open(io.BytesIO(base64.b64decode(images[0].data)))
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_ocr_router.py:567
assert base64.b64decode(sent["image"]["base64"]) == original

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha def4d7370127full audit observations/trust-audit/mcp-server/ianderso__gramps-evidence-mcp.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09def4d7370127SAFEB88first audit
06

Questions

What is the gramps-evidence-mcp MCP server?

MCP server for evidence-disciplined genealogy: read/write access to a self-hosted Gramps Web tree where every fact carries a citation, plus a read-only reference layer over legacy GEDCOM exports.

What tools does gramps-evidence-mcp expose?

26 in total: 24 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is gramps-evidence-mcp safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does gramps-evidence-mcp need?

It reads GRAMPS_LIVE_PASSWORD, GRAMPS_LIVE_SECRET_KEY, GRAMPS_MCP_PASSWORD and GRAMPS_MCP_TRANSKRIBUS_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does gramps-evidence-mcp run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as gramps-evidence-mcp.

How current is this page?

The grade is for one exact copy of the source (def4d7370127), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement