SPARQL-LLMCAUTION
🦜✨ Chat system, MCP server, and reusable components to improve LLMs capabilities when generating SPARQL queries
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://pypi.org/project/sparql-llm/) [](https://pypi.org/project/sparql-llm/) [](https://github.com/sib-swiss/sparql-llm/actions/workflows/test.yml)
This project provides tools to enhance the capabilities of Large Language Models (LLMs) in generating SPARQL queries for specific endpoints:
- a complete chat web service available at [expasy.org/chat](https://expasy.org/chat)
- a MCP server exposing tools at [chat.expasy.org/mcp](https://chat.expasy.org/mcp)
- reusable components published as the [`sparql-llm`](https://pypi.org/project/sparql-llm/) pip package
The system integrates Retrieval-Augmented Generation (RAG) and SPARQL query validation through endpoint schemas, to ensure more accurate and relevant query generation on large scale knowledge graphs.
The components are designed to work either independently or as part of a full chat-based system that can be deployed for a set of SPARQL endpoints. It requires endpoints to include metadata such as SPARQL query examples and endpoint descriptions using the Vocabulary of Interlinked Datasets (VoID), which can be automatically generated using the void-generator.
💥 News
🥇 We won the first place at the Text2SPARQL Challenge, co-located with ESWC 2026. Some highlights from our evaluation:
- 🎯 up to 59% higher F1 score*
- 🚀 up to 27× faster*
- 💸 no more than $0.01 per question
- 🌍
679e27b073c4OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add sparql-llm -- None sparql-llm==0.1.2
Exposed tools (5)
4 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
access_sib_biodata_sparql | read | Assist users in writing SPARQL queries to access SIB biodata resources by retrieving relevant examples and docs. |
execute_sparql_query | write | Execute a SPARQL query against a SPARQL endpoint. |
get_classes_schema | read | Search for specific classes and their schema in the SPARQL endpoints. |
get_resources_info | read | Get information about the SPARQL endpoints indexed by this MCP server. |
search_sparql_docs | read | relevant_docs: list[ScoredPoint] = [] |
Trust audit
CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (9 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (14)
# - VECTORDB_URL=http://10.89.1.2:6334/
# - DBPEDIA_URL=http://141.57.8.18:9081/sparql
# - CORPORATE_URL=http://141.57.8.18:9080/sparql
return "http://127.0.0.1:8000"
}`;function qi(s){var e={keyword:"base|10 prefix|10 @base|10 @prefix|10",literal:"true|0 false|0",built_in:"a|0"},t={className:"literal",relevance:1,begin:/</,end:/>/,illegal:/[^\x00-\x20<>"{}|^`]/},napi-key="public_apikey_used_by_frontend_to_prevent_abuse_from_robots"
api-key="public_apikey_used_by_frontend_to_prevent_abuse_from_robots"
.pre-commit-config.yaml
outDir: "../../src/sparql_llm/agent/webapp",
@langchain/core, @langchain/langgraph, @langchain/langgraph-sdk, dompurify, highlight.js, marked, solid-element, solid-js
@edc4it/reveal.js-clipcode, @types/node, reveal.js, vite
tests/text2sparql/queries.csv
tests/void_uniprot.ttl
uv.lock
Gates applied: no_behavioural_pass.
679e27b073c4full audit observations/trust-audit/mcp-server/sib-swiss__sparql-llm.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 679e27b073c4 | CAUTION | B | 83 | first audit |
Questions
What is the SPARQL-LLM MCP server?
🦜✨ Chat system, MCP server, and reusable components to improve LLMs capabilities when generating SPARQL queries
What tools does SPARQL-LLM expose?
5 in total: 4 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is SPARQL-LLM safe to connect to an agent?
With care. The audit graded it B (83/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does SPARQL-LLM need?
It reads OPENROUTER_API_KEY and TOKENIZERS_PARALLELISM from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does SPARQL-LLM run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as tuto-sparql-agent at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (679e27b073c4), read on 2026-10-07. The repository is watched and re-audited when it changes.