OLSSAFE
A model context protocol (MCP) server for the EBI Ontology Lookup Service (OLS)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Large Language Models are notoriously bad at working with ontologies, often hallucinating terms or their identifiers. This server provides a reliable way to access and query ontologies, ensuring accurate and up-to-date information.
This repository contains a Model Context Protocol (MCP) server providing access to the Ontology Lookup Service (OLS) API. This server enables AI assistants to search for and retrieve ontological terms, concepts, and hierarchies from various biological and medical ontologies.
This server is designed to work seamlessly with AI assistants like Claude Desktop, allowing users to query ontologies using natural language. It supports a wide range of ontologies, including Gene Ontology (GO), Human Phenotype Ontology (HP), and many others.
Without (top part of image below) and with mcp server engaged (bottom of figure below):
Features
The OLS MCP Server provides the following tools:
- 🔍 Search Terms: Search for terms across ontologies with flexible filtering
- 📚 Search Ontologies: Discover available ontologies and their metadata
- i️ Get Ontology Information: Retrieve detailed information about specific ontologies
- 🎯 Get Term Information: Get comprehensive details about specific terms
- 🌳 Get Term Children: Find direct child terms in ontological hierarchies
- 👨👩👧👦 Get Term Ancestors: Retrieve parent terms and ancestors
- 🤖 Find Similar Terms: Discover semantically similar terms using LLM embeddings
Supported Ontologies
The server works with any ontology available through the EBI Ontology Lookup Service, including:
- GO (Gene Ontology)
- EFO (Experimental Factor Ontology)
- HP (Human Phenotype Ontology)
- MONDO (Monarch Disease Ontol
8bfc79d0851fOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add ols-mcp-server -- uvx ols-mcp-server
{
"mcpServers": {
"ols-mcp-server": {
"command": "uvx",
"args": [
"ols-mcp-server"
]
}
}
}Exposed tools (4)
4 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
find_similar_terms | read | Find terms similar to the given term using LLM embeddings. |
get_ontology_info | read | Get detailed information about a specific ontology. |
get_term_ancestors | read | Get ancestor terms (parents) of a specific term. |
get_term_children | read | Get direct children of a specific term. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
images/speak_ontology.png
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass, no_license.
8bfc79d0851ffull audit observations/trust-audit/mcp-server/seandavi__ols.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 8bfc79d0851f | SAFE | B | 89 | first audit |
Questions
What is the OLS MCP server?
A model context protocol (MCP) server for the EBI Ontology Lookup Service (OLS)
What tools does OLS expose?
4 in total: 4 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is OLS safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does OLS need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (8bfc79d0851f), read on 2026-10-09. The repository is watched and re-audited when it changes.