Atlas / MCP servers / merill / Lokka

LokkaCAUTION

mcp/merill/lokka

MCP (Model Context Protocol) for Microsoft 365. Includes support for Microsoft Graph and other services

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
4 2r · 2w · 0d
Transport
stdio
License
MIT
Stars
303
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@merill/lokka) [](https://www.npmjs.com/package/@merill/lokka) [](https://www.npmjs.com/package/@merill/lokka) [](https://github.com/merill/lokka/stargazers) [](https://github.com/merill/lokka/blob/main/LICENSE)

Lokka is a model-context-protocol server for the Microsoft Graph and Azure RM APIs that allows you to query and manage your Azure and Microsoft 365 tenants with AI.

Please see Lokka.dev for how to use Lokka with your favorite AI model and chat client.

Lokka lets you use Claude Desktop, or any MCP Client, to use natural language to accomplish things in your Azure and Microsoft 365 tenant through the Microsoft APIs.

e.g.:

  • Create a new security group called 'Sales and HR' with a dynamic rule based on the department attribute.
  • Find all the conditional access policies that haven't excluded the emergency access account
  • Show me all the Intune device configuration policies assigned to the 'Call center' group
  • What was the most expensive service in Azure last month?

Authentication Methods

Lokka now supports multiple authentication methods to accommodate different deployment scenarios:

Interactive Auth

For user-based authentication with interactive login, you can use the following configur

Read from source at commit 78278eba7a8dOBSERVED · 2026-10-05
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add website --env ACCESS_TOKEN=${ACCESS_TOKEN} --env CERTIFICATE_PASSWORD=${CERTIFICATE_PASSWORD} --env CLIENT_SECRET=${CLIENT_SECRET} --env USE_CLIENT_TOKEN=${USE_CLIENT_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "website": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ACCESS_TOKEN": "${ACCESS_TOKEN}",
        "CERTIFICATE_PASSWORD": "${CERTIFICATE_PASSWORD}",
        "CLIENT_SECRET": "${CLIENT_SECRET}",
        "USE_CLIENT_TOKEN": "${USE_CLIENT_TOKEN}"
      }
    }
  }
}
03

Exposed tools (4)

2 read · 2 write · 0 destructive.

ToolRiskDescription
Lokka-MicrosoftreadA versatile tool to interact with Microsoft APIs including Microsoft Graph (Entra) and Azure Resource Management. IMPORTANT: For Graph API GET requests using advanced query parameters ($filter, $count, $search, $orderby), you are ADVISED to set
add-graph-permissionwriteRequest additional Microsoft Graph permission scopes by performing a fresh interactive sign-in. This tool only works in interactive authentication mode and should be used if any Graph API call returns permissions related errors.
get-auth-statusreadCheck the current authentication status and mode of the MCP Server and also returns the current graph permission scopes of the access token for the current session.
set-access-tokenwriteSet or update the access token for Microsoft Graph authentication. Use this when the MCP Client has obtained a fresh token through interactive authentication.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/mcp/build/main.js:394
logger.info(`Requesting fresh token with scopes: ${scopeString}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/mcp/build/main.js:455
logger.info(`Successfully acquired fresh token with additional scopes: ${scopes.join(', ')}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/mcp/src/main.ts:579
logger.info(`Requesting fresh token with scopes: ${scopeString}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/mcp/src/main.ts:652
logger.info(`Successfully acquired fresh token with additional scopes: ${scopes.join(', ')}`);
LOWInventory / provenance · inv.hidden_file · CWE-1104
website/static/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
src/mcp/package.json
@azure/identity, @microsoft/microsoft-graph-client, @modelcontextprotocol/sdk, @types/jsonwebtoken, isomorphic-fetch, jsonwebtoken, zod, @types/isomorphic-fetch
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
website/package.json
@mdx-js/react, clsx, prism-react-renderer, react, react-dom
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:148
- **`set-access-token`**: Set or update access tokens for Microsoft Graph authentication
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
src/mcp/README.md:144
- **`set-access-token`**: Set or update access tokens for Microsoft Graph authentication
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
website/docs/install-advanced/token-auth.md:50
5. Copy the access token from the **Access token** tab
Why it matters. asks the agent to read credentials
INFOInventory / provenance · inv.oversize · CWE-1104
assets/lokka-demo-1.gif
assets/lokka-demo-1.gif
Why it matters. 28387829 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-05 · audit v0.4.1 · source sha 78278eba7a8dfull audit observations/trust-audit/mcp-server/merill__lokka.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0578278eba7a8dCAUTIONB89first audit
06

Questions

What is the Lokka MCP server?

MCP (Model Context Protocol) for Microsoft 365. Includes support for Microsoft Graph and other services

What tools does Lokka expose?

4 in total: 2 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Lokka safe to connect to an agent?

With care. The audit graded it B (89/100) and found 11 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Lokka need?

It reads ACCESS_TOKEN, CERTIFICATE_PASSWORD, CLIENT_SECRET and USE_CLIENT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Lokka run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as website at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (78278eba7a8d), read on 2026-10-05. The repository is watched and re-audited when it changes.

Advertisement