Atlas / MCP servers / senolisci / MyKG

MyKGBLOCK

mcp/senolisci/mykg

MyKG Knowledge Graph Engine: Turn raw files into knowledge graphs with induced ontology

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
15 15r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
74
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.python.org/downloads/) [](LICENSE) [](https://github.com/SenolIsci/mykg/actions/workflows/ci.yml) [](https://codecov.io/gh/SenolIsci/mykg) [](#configuration) [](docs/agent-mode.md) [](https://pypi.org/project/mykg/) [](https://pepy.tech/project/mykg) [](https://github.com/SenolIsci/mykg/stargazers) [](https://github.com/SenolIsci/mykg/issues) [](https://github.com/SenolIsci/mykg) [](https://medium.com/@senol.isci) [](https://www.linkedin.com/in/senolisci/)

myKG automatically generates a confidence-scored knowledge graph from a set of mixed documents — Markdown, plain text, PDF, Word, PowerPoint, Excel, HTML, and images — grounded in an induced RDFS/OWL ontology.

Read from source at commit cadf2dc96478OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mykg --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env ANTHROPIC_AUTH_TOKEN=${ANTHROPIC_AUTH_TOKEN} --env GEMINI_API_KEY=${GEMINI_API_KEY} --env GOOGLE_API_KEY=${GOOGLE_API_KEY} -- uvx mykg
claude-desktop
{
  "mcpServers": {
    "mykg": {
      "command": "uvx",
      "args": [
        "mykg"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "ANTHROPIC_AUTH_TOKEN": "${ANTHROPIC_AUTH_TOKEN}",
        "GEMINI_API_KEY": "${GEMINI_API_KEY}",
        "GOOGLE_API_KEY": "${GOOGLE_API_KEY}"
      }
    }
  }
}
03

Exposed tools (15)

15 read · 0 write · 0 destructive.

ToolRiskDescription
mykg_find_pathreadFind the shortest path between two nodes.
mykg_get_neighborsreadGet direct neighbors of a node with edge details.
mykg_get_nodereadGet full details for a node by its stable ID.
mykg_get_schemareadGet the full schema: concept types with hierarchy and relationship properties.
mykg_get_sourcereadGet bounded source-text excerpts for a node, an edge, or both.
mykg_get_statsreadGet summary statistics: node/edge counts, type distribution, density, components, avg degree.
mykg_hub_nodesreadReturn the most connected nodes by degree — the core entities of the graph.
mykg_list_node_typesreadList all concept types with instance counts, sorted descending.
mykg_list_sessionsreadList all available mykg sessions with their status and size.
mykg_orphan_nodesreadFind all orphan nodes — entities with zero connections (no edges).
mykg_query_graphreadSearch the knowledge graph using BFS or DFS traversal from seed nodes.
mykg_query_subgraphreadExtract a filtered subgraph by node IDs, types, and/or minimum confidence.
mykg_read_notereadRead the LLM wiki note for an entity from the Obsidian vault.
mykg_reloadreadReload the in-memory knowledge graph from disk.
mykg_search_nodesreadSearch for entities in the knowledge graph by name, alias, or attribute value.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (19)

CRITICALPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
src/mykg/data/skills/mykg/SKILL.md:3
description: Run mykg knowledge-graph commands inside Claude Code from one slash command `/mykg`. The user describes intent in natural language (extract, append, sync, resume, approve, walkthrough, pa
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
MEDIUMInventory / provenance · inv.binary · CWE-1104
_test_files/projects.xlsx
projects.xlsx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.binary · CWE-1104
docs/examples/domain-separation/.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/examples/domain-separation/.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/mykg/data/_crawl_runner.py:73
digest = hashlib.sha1(parsed.query.encode()).hexdigest()[:8]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/mykg/data/_crawl_runner.py:76
digest = hashlib.sha1(parsed.path.encode()).hexdigest()[:8]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/mykg/data/_crawl_runner.py:91
digest = hashlib.sha1(parsed.query.encode()).hexdigest()[:8]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/mykg/fetch_web.py:247
digest = hashlib.sha1(parsed.query.encode()).hexdigest()[:8]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/mykg/fetch_web.py:252
digest = hashlib.sha1(parsed.path.encode()).hexdigest()[:8]
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_fetch_web.py:196
p = local_path_for_url("https://evil.com/a/../../b", "text/html")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_fetch_web.py:267
row = mod.save_page(tmp_path, "https://evil.com/../../etc/passwd", "text/html", b"x")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_fetch_web.py:514
f"http://127.0.0.1:{port}/",
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/architecture.md:718
| OpenRouter | Access many models via a single API key |
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
.claude/agents/adversarial-architect.md:62
- Can a crafted Markdown file break out of the user content section of the prompt and inject system-level instructions? For example, a file that contains `\n\nSYSTEM: Ignore all previous instructions
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
INFOInventory / provenance · inv.oversize · CWE-1104
docs/diagrams/architecture-sketch.png
docs/diagrams/architecture-sketch.png
Why it matters. 1357039 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/diagrams/mykg_batching_and_chunking.png
docs/diagrams/mykg_batching_and_chunking.png
Why it matters. 1533112 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/mykg_logo_panel.png
docs/mykg_logo_panel.png
Why it matters. 1446407 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/mykg_logo_panel_old.png
docs/mykg_logo_panel_old.png
Why it matters. 1530863 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
pages/assets/architecture-sketch.png
pages/assets/architecture-sketch.png
Why it matters. 1357039 bytes not read

Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.

Audited 2026-10-07 · audit v0.4.1 · source sha cadf2dc96478full audit observations/trust-audit/mcp-server/senolisci__mykg.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07cadf2dc96478BLOCKD69first audit
06

Questions

What is the MyKG MCP server?

MyKG Knowledge Graph Engine: Turn raw files into knowledge graphs with induced ontology

What tools does MyKG expose?

15 in total: 15 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is MyKG safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does MyKG need?

It reads ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN, GEMINI_API_KEY, GOOGLE_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY and OPENROUTER_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does MyKG run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mykg.

How current is this page?

The grade is for one exact copy of the source (cadf2dc96478), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement