Atlas / MCP servers / stevereiner / Flexible GraphRAG

Flexible GraphRAGBLOCK

mcp/stevereiner/flexible-graphrag

Python, LlamaIndex, LangChain, 15 Property Graph, 4 RDF , 10 Vector, OpenSearch, Elasticsearch DBs. 14 data sources, 10 auto sync: Alfresco, Nuxeo, etc. KG auto-building, Ontologies, LLMs, Docling, LlamaParse, LiteParse, GraphRAG, RAG, Hybrid Search, AI Chat. TypeScript React, Vue, Angular frontends

Verdict
BLOCK
Grade
F
Trust score
35 /100
Exposed tools
9 9r · 0w · 0d
Transport
—
License
Apache-2.0
Stars
188
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pypi.org/project/flexible-graphrag/) [](https://pepy.tech/project/flexible-graphrag) [](https://pypi.org/project/flexible-graphrag-mcp/) [](https://pepy.tech/project/flexible-graphrag-mcp) [](https://opensource.org/licenses/Apache-2.0) [](https://www.python.org/) [](https://react.dev/) [](https://angular.dev/) [](https://vuejs.org/) [](https://hub.docker.com/u/integratedsemantics) [](https://deepwiki.com/stevereiner/flexible-graphrag) [](https://stevereiner.github.io/flexible-graphrag/) [](https://integratedsemantics.org)

Read from source at commit c3215a5ba72cOBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add flexible-graphrag-vue --env AGE_PASSWORD=${AGE_PASSWORD} --env ALFRESCO_AUTH_METHOD=${ALFRESCO_AUTH_METHOD} --env ALFRESCO_OAUTH2_ACCESS_TOKEN=${ALFRESCO_OAUTH2_ACCESS_TOKEN} --env ALFRESCO_OAUTH2_CLIENT_ID=${ALFRESCO_OAUTH2_CLIENT_ID} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "flexible-graphrag-vue": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "AGE_PASSWORD": "${AGE_PASSWORD}",
        "ALFRESCO_AUTH_METHOD": "${ALFRESCO_AUTH_METHOD}",
        "ALFRESCO_OAUTH2_ACCESS_TOKEN": "${ALFRESCO_OAUTH2_ACCESS_TOKEN}",
        "ALFRESCO_OAUTH2_CLIENT_ID": "${ALFRESCO_OAUTH2_CLIENT_ID}"
      }
    }
  }
}
03

Exposed tools (9)

9 read · 0 write · 0 destructive.

ToolRiskDescription
check_processing_statusread
get_python_inforeadGet information about the Python environment of the backend
get_system_statusreadGet the current status of the flexible-graphrag system
health_checkreadCheck if the backend is healthy and responsive
ingest_documentsread
ingest_textread
query_documentsread
search_documentsread
test_with_samplereadTest the system with sample text for quick verification
04

Trust audit

BLOCKgrade F · trust 35/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (10 observation(s))
Network
declared (18 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
flexible-graphrag/llamaindex/llm/embedding_factory.py:36
"embedding_factory: OPENAI_VERIFY_SSL=false — creating httpx.Client(verify=False)"
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
flexible-graphrag/llamaindex/llm/embedding_factory.py:38
return httpx.Client(verify=False)
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
scripts/create_opensearch_pipeline.py:31
session.verify = False
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
scripts/nuxeo/nuxeo_oauth2_headless.py:35
with httpx.Client(follow_redirects=False, verify=False, timeout=30) as c:
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/CONFIGURATION/CONFIG-RDF-STORES.md:1
# Configure RDF Graph Databases
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMInventory / provenance · inv.binary · CWE-1104
sample-docs/excel-2plus2.xlsx
excel-2plus2.xlsx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
sample-docs/word-hello-world.docx
word-hello-world.docx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
flexible-graphrag/cocoindex_integration/_compat.py:234
_m = importlib.import_module(_mod_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
flexible-graphrag/cocoindex_integration/bridge.py:1457
importlib.import_module(mod_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
flexible-graphrag/cocoindex_integration/connectors/cocoindex/sources/__init__.py:110
importlib.import_module(coco_module)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
flexible-graphrag/cocoindex_integration/connectors/flexible/_sources/_lazy.py:149
mod = importlib.import_module(mod_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
flexible-graphrag/cocoindex_integration/functions/kg_extractors.py:294
importlib.import_module(mod)
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
scripts/nuxeo/nuxeo_oauth2_headless.py:58
print("access_token :", token.get("access_token"))
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
scripts/nuxeo/nuxeo_oauth2_headless.py:59
print("refresh_token:", token.get("refresh_token"))
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
scripts/nuxeo/nuxeo_oauth2_headless.py:60
print("expires_in   :", token.get("expires_in"))
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
scripts/nuxeo/nuxeo_oauth2_token.py:84
print("access_token :", token.get("access_token"))
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
scripts/nuxeo/nuxeo_oauth2_token.py:85
print("refresh_token:", token.get("refresh_token"))
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/nuxeo/nuxeo_oauth2_headless.py:53
callback_url = loc if loc.startswith("http") else (REDIR + loc[loc.find("?"):])
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/nuxeo/nuxeo_oauth2_headless.py:54
print("\nCALLBACK:", callback_url)
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
scripts/nuxeo/nuxeo_oauth2_headless.py:56
token = auth.request_token(code_verifier=verifier, authorization_response=callback_url, state=state)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
docker/includes/milvus.yaml:12
command: etcd -advertise-client-urls=http://127.0.0.1:2379 -listen-client-urls http://0.0.0.0:2379 --data-dir /etcd
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
CHANGELOG.md:431
- **`docker/docker.env`** — Added `ONTOLOGY_DIR=schemas/` override (resolves against container `/app` cwd) so `USE_ONTOLOGY=true` works in full-stack Docker without changing `.env`. Added `POSTGRES_IN
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
README.md:231
POSTGRES_INCREMENTAL_URL=postgresql://postgres:password@localhost:5433/postgres
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docker/DOCKER-ENV-SETUP.md:265
`POSTGRES_INCREMENTAL_URL=postgresql://postgres:password@postgres-pgvector:5432/flexible_graphrag_incremental`
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docker/docker-env-sample.txt:150
POSTGRES_INCREMENTAL_URL=postgresql://postgres:[email protected]:5433/flexible_graphrag_incremental

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha c3215a5ba72cfull audit observations/trust-audit/mcp-server/stevereiner__flexible-graphrag.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06c3215a5ba72cBLOCKF35first audit
06

Questions

What is the Flexible GraphRAG MCP server?

Python, LlamaIndex, LangChain, 15 Property Graph, 4 RDF , 10 Vector, OpenSearch, Elasticsearch DBs. 14 data sources, 10 auto sync: Alfresco, Nuxeo, etc. KG auto-building, Ontologies, LLMs, Docling, LlamaParse, LiteParse, GraphRAG, RAG, Hybrid Search, AI Chat. TypeScript React, Vue, Angular frontends

What tools does Flexible GraphRAG expose?

9 in total: 9 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Flexible GraphRAG safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (35/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Flexible GraphRAG need?

It reads AGE_PASSWORD, ALFRESCO_AUTH_METHOD, ALFRESCO_OAUTH2_ACCESS_TOKEN, ALFRESCO_OAUTH2_CLIENT_ID, ALFRESCO_OAUTH2_CLIENT_SECRET, ALFRESCO_OAUTH2_GRANT_TYPE, ALFRESCO_OAUTH2_REFRESH_TOKEN, ALFRESCO_OAUTH2_SCOPE, ALFRESCO_OAUTH2_TOKEN_ENDPOINT, ALFRESCO_PASSWORD, ALFRESCO_SYNC_PASSWORD and ANTHROPIC_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (c3215a5ba72c), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement