Atlas / MCP servers / meilisearch / Meilisearch

MeilisearchCAUTION

mcp/meilisearch/meilisearch-2

A Model Context Protocol (MCP) server for interacting with Meilisearch through LLM interfaces.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
22 15r · 5w · 2d
Transport
stdio
License
MIT
Stars
195
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Meilisearch MCP Server

Meilisearch | Meilisearch Cloud | Documentation | Discord

⚡ Connect any LLM to Meilisearch and supercharge your AI with lightning-fast search capabilities! 🔍

🤔 What is this?

The Meilisearch MCP Server is a Model Context Protocol server that enables any MCP-compatible client (including Claude, OpenAI agents, and other LLMs) to interact with Meilisearch. This stdio-based server allows AI assistants to manage search indices, perform searches, and handle your data through natural conversation.

Why use this?

  • 🤖 Universal Compatibility - Works with any MCP client, not just Claude
  • 🗣️ Natural Language Control - Manage Meilisearch through conversation with any LLM
  • 🚀
Read from source at commit 71ab62101abfOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add meilisearch-mcp --env MEILI_MASTER_KEY=${MEILI_MASTER_KEY} -- uvx meilisearch-mcp
claude-desktop
{
  "mcpServers": {
    "meilisearch-mcp": {
      "command": "uvx",
      "args": [
        "meilisearch-mcp"
      ],
      "env": {
        "MEILI_MASTER_KEY": "${MEILI_MASTER_KEY}"
      }
    }
  }
}
03

Exposed tools (22)

15 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add-documentswriteAdd documents to an index
cancel-tasksreadCancel tasks based on filters
create-indexwriteCreate a new Meilisearch index
create-keywriteCreate a new API key
delete-indexdestructiveDelete a Meilisearch index
delete-keydestructiveDelete an API key
get-chat-workspace-settingsreadGet settings for a specific chat workspace
get-connection-settingsreadGet current Meilisearch connection settings
get-documentsreadGet documents from an index
get-health-statusreadGet comprehensive health status of Meilisearch
get-index-metricsreadGet detailed metrics for an index
get-keysreadGet list of API keys
get-settingsreadGet current settings for an index
get-statsreadGet database statistics
get-system-inforeadGet system-level information
get-taskreadGet information about a specific task
get-versionreadGet Meilisearch version information
health-checkreadCheck Meilisearch server health
list-indexesreadList all Meilisearch indexes
searchreadSearch through Meilisearch indices. If indexUid is not provided, it will search across all indices.
update-connection-settingswriteUpdate Meilisearch connection settings
update-settingswriteUpdate settings for an index
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
UNDECLARED (3 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
Dockerfile:10
rm -rf /var/lib/apt/lists/*
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete-index, delete-key
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements-dev.txt
pytest, pytest-asyncio, black, mcp
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 71ab62101abffull audit observations/trust-audit/mcp-server/meilisearch__meilisearch-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0671ab62101abfCAUTIONB89first audit
06

Questions

What is the Meilisearch MCP server?

A Model Context Protocol (MCP) server for interacting with Meilisearch through LLM interfaces.

What tools does Meilisearch expose?

22 in total: 15 read-only, 5 that write, and 2 that can delete or overwrite (delete-index, delete-key). Every one is listed on this page with its risk.

Is Meilisearch safe to connect to an agent?

With care. The audit graded it B (89/100) and found 3 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Meilisearch need?

It reads MEILI_MASTER_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Meilisearch run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as meilisearch-mcp.

How current is this page?

The grade is for one exact copy of the source (71ab62101abf), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement