Atlas / MCP servers / idoru / InfluxDB

InfluxDBSAFE

mcp/idoru/influxdb

An MCP Server for querying InfluxDB

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
4 0r · 4w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
46
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/idoru-influxdb-mcp-server)

[](https://smithery.ai/server/@idoru/influxdb-mcp-server)

[](https://archestra.ai/mcp-catalog/idoru__influxdb-mcp-server)

A Model Context Protocol (MCP) server that exposes access to an InfluxDB v2 instance using the InfluxDB OSS API v2. Mostly built with Claude Code.

Features

This MCP server provides:

  • Resources: Access to organization, bucket, and measurement data
  • Tools: Write data, execute queries, and manage database objects
  • Prompts: Templates for common Flux queries and Line Protocol format

Resources

The server exposes the following resources:

  1. Organizations List: influxdb://orgs
  2. Displays all organizations in the InfluxDB instance
  1. Buckets List: influxdb://buckets
  2. Shows all buckets with their metadata
  1. Bucket Measurements: influxdb://bucket/{bucketName}/measurements
  2. Lists all measurements within a specified bucket
  1. Query Data: influxdb://query/{orgName}/{fluxQuery}
  2. Executes a Flux query and returns results as a resource

Tools

The server provides these tools:

  1. write-data: Write time-series data in line protocol format
  2. Parameters: org, bucket, data, precision (optional)
  1. query-data: Execute Flux queries
  2. Parameters: org, query
  1. create-bucket: Create a new bucket
  2. Parameters: name, orgID, retentionPeriodSeconds (optional)
  1. create-org: Create a new organization
  2. Parameters: name, description (optional)

Prompts

The server offers these prompt templates:

  1. flux-query-examples: Common Flux query examples
  2. line-protocol-guide: Guide to InfluxDB line protocol format

Configuration

The server requires these environment var

Read from source at commit e0583882e755OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add influxdb-mcp-server --env INFLUXDB_TOKEN=${INFLUXDB_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "influxdb-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "INFLUXDB_TOKEN": "${INFLUXDB_TOKEN}"
      }
    }
  }
}
03

Exposed tools (4)

0 read · 4 write · 0 destructive.

ToolRiskDescription
create-bucketwriteProvision a new bucket under an organization so that subsequent write-data calls have a destination.
create-orgwriteCreate a brand-new organization to isolate users or projects before generating buckets and tokens.
query-datawriteExecute a Flux query inside an organization to inspect measurement schemas, run aggregations, or validate recently written data.
write-datawriteStream newline-delimited line protocol records into a bucket. Use this after composing measurements so the LLM can insert real telemetry, optionally controlling timestamp precision.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
tests/integration.test.js:386
console.log("Token created:", tokenData.token ? "success" : "failure");
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, commander, express, node-fetch, zod, @jest/globals, @types/dockerode, @types/jest
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha e0583882e755full audit observations/trust-audit/mcp-server/idoru__influxdb.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08e0583882e755SAFEB89first audit
06

Questions

What is the InfluxDB MCP server?

An MCP Server for querying InfluxDB

What tools does InfluxDB expose?

4 in total: 0 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is InfluxDB safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does InfluxDB need?

It reads INFLUXDB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does InfluxDB run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as influxdb-mcp-server at 0.2.0.

How current is this page?

The grade is for one exact copy of the source (e0583882e755), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement