gramps-evidence-mcpSAFE
MCP server for evidence-disciplined genealogy: read/write access to a self-hosted Gramps Web tree where every fact carries a citation, plus a read-only reference layer over legacy GEDCOM exports.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/ianderso/gramps-evidence-mcp/actions/workflows/ci.yml) [](https://pypi.org/project/gramps-evidence-mcp/)
An MCP server that gives an AI assistant read/write access to a Gramps genealogy tree, plus a read-only "reference layer" over legacy GEDCOM exports.
96 tools, built around evidence discipline. The premise is that an assistant turned loose on a family tree will happily invent a plausible ancestor, so the write paths here are shaped to make every claim carry its source: facts are created with citations attached, uncite deletes what it orphans, parent-child links are cited independently because one citation object cannot carry two confidences, and an audit set — list_unsourced_facts, get_backlinks, find_duplicates, and server-side queries through query_objects and query_records — exists to find the places where that discipline slipped.
Legacy trees (Ancestry / FamilySearch exports) are consulted through the read-only reference layer as untrusted hints, never a source of truth.
The server is a REST client of [Gramps Web](https://www.grampsweb.org/) (`gramps-webapi`). It never touches the Gramps database files directly — see How it connects.
Living-person privacy filtering is on by default — see Privacy.
This is an independent project. It is not made, endorsed or supported by the Gramps project.
Contents
- How it connects
- Setup
- Configuration
- Client configuration
- Remote access (Claude web / mobile)
- The evidence model & transactions
- [Priva
def4d7370127OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add gramps-evidence-mcp --env GRAMPS_MCP_PASSWORD=${GRAMPS_MCP_PASSWORD} --env GRAMPS_MCP_TRANSKRIBUS_PASSWORD=${GRAMPS_MCP_TRANSKRIBUS_PASSWORD} -- uvx gramps-evidence-mcp==2.2.0Exposed tools (26)
24 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add_citation | write | Create a standalone Citation on a Source (or reuse an existing one). |
db_stats | read | Counts of people, families, events, citations, sources, repositories, |
get_citation | read | Read one citation: page, confidence, date, and its source. |
get_event | read | Get an event: type, date, place handle, description, citation count, and |
get_family | read | Get a family: relationship type, parent handles, child handles, event count. |
get_job | read | Check whether a background job has finished, and whether it worked. |
get_media | read | Read one media object: path, mime type, checksum, description, date. |
get_note | read | Read one note in full, with its type and what it is attached to. |
get_person | read | Get full detail for one person: name, gender, events (with citation counts), |
get_place | read | Read one place: name, title, type, enclosure, coordinates and URLs. |
get_report_options | read | Read one report |
get_repository | read | Get a repository: name, type, URLs, address count, and (if available) |
get_researcher | read | Read the researcher details recorded for this tree. |
get_source | read | Get a source: title, author, publication info, abbreviation, linked |
get_transaction | read | Read one transaction in full, including the objects it changed. |
list_custom_filters | read | List the custom filters already saved on this instance. |
list_event_types | read | List the event type names this tree uses, with their stored integers. |
list_filter_rules | read | List the filter rules Gramps offers in a namespace. |
list_jobs | read | List recent background jobs for this tree, newest first: undo, verify, |
list_object_types | read | The tree |
list_reports | read | List the reports this Gramps instance can generate. |
list_tags | read | List all tags in the tree with their handle, name, and color. |
list_transactions | read | Recent writes to the tree: what changed, when, by which user. |
parse_dna_segments | read | Parse pasted shared-segment data into structured segments and totals. |
reindex_search | read | Rebuild the full-text index behind Gramps Web |
update_citations | write | Re-write many citations |
Trust audit
SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (11)
secret="throwaway-live-test-secret-key-not-for-real-use"
checksum = hashlib.md5(content).hexdigest() # noqa: S324 - matches Gramps' own
@pytest.mark.parametrize("name", ["id_ed25519", ".env", "notes.txt", "tree.ged"])await tools("delete_filter", namespace="people", name=f"../../people/{person['handle']}")assert _seg("../../people/abc") == "..%2F..%2Fpeople%2Fabc"**public HTTPS URL**. A LAN address like `http://192.168.1.50:5000` won't work.
That serves the MCP endpoint at `http://127.0.0.1:8090/mcp`; `GRAMPS_MCP_HOST`
f"GRAMPS_LIVE_URL must be a loopback address such as http://127.0.0.1:5555, "
url="http://127.0.0.1:$port"
return Image.open(io.BytesIO(base64.b64decode(images[0].data)))
assert base64.b64decode(sent["image"]["base64"]) == original
Gates applied: no_behavioural_pass.
def4d7370127full audit observations/trust-audit/mcp-server/ianderso__gramps-evidence-mcp.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | def4d7370127 | SAFE | B | 88 | first audit |
Questions
What is the gramps-evidence-mcp MCP server?
MCP server for evidence-disciplined genealogy: read/write access to a self-hosted Gramps Web tree where every fact carries a citation, plus a read-only reference layer over legacy GEDCOM exports.
What tools does gramps-evidence-mcp expose?
26 in total: 24 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is gramps-evidence-mcp safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does gramps-evidence-mcp need?
It reads GRAMPS_LIVE_PASSWORD, GRAMPS_LIVE_SECRET_KEY, GRAMPS_MCP_PASSWORD and GRAMPS_MCP_TRANSKRIBUS_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does gramps-evidence-mcp run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as gramps-evidence-mcp.
How current is this page?
The grade is for one exact copy of the source (def4d7370127), read on 2026-10-09. The repository is watched and re-audited when it changes.