gephi-mcp
PyPI
v1.11.0
Published by mattartzanthro — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 4 = 96. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −3 | capability blast radius (moderate) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Untrusted-input tools ([gephi_extract_backbone]) co-exist with external-action tools ([gephi_open_project]). A prompt injection could cause unwanted external actions, though no direct sensitive-data leak path was found.
Evidence: untrusted [gephi_extract_backbone] → sinks [gephi_open_project]
Fix: Require confirmation for state-changing/egress actions triggered after processing untrusted content.
Location: flow gephi_extract_backbone → gephi_open_project
In a packaging/dev/install script (shipped, but not the server runtime) (`gephi_mcp_viewer/assets/graphology.umd.min.js:1`): Loading a module chosen at runtime (from a variable) can pull in and run attacker-influenced code paths. This is read from the code itself — not from the tool description — so a poisoned server cannot hide it behind honest-looking metadata.
Evidence: ,n),i=new t(r);return i.import(e),i}}return Ut(xt),Ut(Et),Ut(At),Ut(Lt),Ut(St),Ut(Dt),xt.Graph=xt,xt.DirectedGraph=Et,xt
Fix: Review this call path: confirm it never receives unsanitized tool input, constrain it, or remove it. Treat a server whose code reaches these sinks as high-capability regardless of what its tools claim.
Location: server gephi_mcp_viewer/assets/graphology.umd.min.js
Each tool and what it can reach — statically extracted from the published source.
gephi_extract_backboneingests untrusted inputgephi_open_projectnetwork egressgephi_add_columnno sensitive capabilitygephi_add_edgeno sensitive capabilitygephi_add_edgesno sensitive capabilitygephi_add_nodeno sensitive capabilitygephi_add_nodesno sensitive capabilitygephi_apply_filterno sensitive capabilitygephi_batch_set_node_attributesno sensitive capabilitygephi_batch_set_node_colorsno sensitive capabilitygephi_batch_set_positionsno sensitive capabilitygephi_bulk_remove_nodesno sensitive capabilitygephi_clear_graphno sensitive capabilitygephi_color_by_partitionno sensitive capabilitygephi_color_by_rankingno sensitive capabilitygephi_color_edges_by_partitionno sensitive capabilitygephi_column_value_frequenciesno sensitive capabilitygephi_community_layoutno sensitive capabilitygephi_compare_nodesno sensitive capabilitygephi_compute_avg_path_lengthno sensitive capabilitygephi_compute_betweennessno sensitive capabilitygephi_compute_clustering_coefficientno sensitive capabilitygephi_compute_connected_componentsno sensitive capabilitygephi_compute_degreeno sensitive capabilitygephi_compute_eigenvectorno sensitive capabilitygephi_compute_hitsno sensitive capabilitygephi_compute_modularityno sensitive capabilitygephi_compute_pagerankno sensitive capabilitygephi_create_projectno sensitive capabilitygephi_create_regex_columnno sensitive capabilitygephi_delete_workspaceno sensitive capabilitygephi_detect_duplicatesno sensitive capabilitygephi_duplicate_workspaceno sensitive capabilitygephi_edge_thickness_by_weightno sensitive capabilitygephi_exportno sensitive capabilitygephi_export_csvno sensitive capabilitygephi_export_gexfno sensitive capabilitygephi_export_graphmlno sensitive capabilitygephi_export_pdfno sensitive capabilitygephi_export_pngno sensitive capabilitygephi_export_screenshotno sensitive capabilitygephi_export_svgno sensitive capabilitygephi_extract_ego_networkno sensitive capabilitygephi_extract_giant_componentno sensitive capabilitygephi_filter_by_degreeno sensitive capabilitygephi_filter_by_edge_weightno sensitive capabilitygephi_focus_viewno sensitive capabilitygephi_get_available_layoutsno sensitive capabilitygephi_get_columnsno sensitive capabilitygephi_get_graph_statsno sensitive capabilitygephi_get_graph_typeno sensitive capabilitygephi_get_layout_propertiesno sensitive capabilitygephi_get_layout_statusno sensitive capabilitygephi_get_nodeno sensitive capabilitygephi_get_perspectiveno sensitive capabilitygephi_get_preview_settingsno sensitive capabilitygephi_get_project_infono sensitive capabilitygephi_get_selectionno sensitive capabilitygephi_get_timelineno sensitive capabilitygephi_health_checkno sensitive capabilitygephi_import_csvno sensitive capabilitygephi_import_fileno sensitive capabilitygephi_import_gexfno sensitive capabilitygephi_import_graphmlno sensitive capabilitygephi_label_clustersno sensitive capabilitygephi_list_filtersno sensitive capabilitygephi_list_statisticsno sensitive capabilitygephi_list_workspacesno sensitive capabilitygephi_merge_nodesno sensitive capabilitygephi_new_workspaceno sensitive capabilitygephi_profile_graphno sensitive capabilitygephi_query_edgesno sensitive capabilitygephi_query_nodesno sensitive capabilitygephi_remove_edgeno sensitive capabilitygephi_remove_isolatesno sensitive capabilitygephi_remove_nodeno sensitive capabilitygephi_rename_workspaceno sensitive capabilitygephi_reset_appearanceno sensitive capabilitygephi_reset_filtersno sensitive capabilitygephi_run_layoutno sensitive capabilitygephi_run_statisticno sensitive capabilitygephi_save_projectno sensitive capabilitygephi_set_edge_attributesno sensitive capabilitygephi_set_edge_colorno sensitive capabilitygephi_set_edge_labelno sensitive capabilitygephi_set_edge_weightno sensitive capabilitygephi_set_layout_propertiesno sensitive capabilitygephi_set_node_attributesno sensitive capabilitygephi_set_node_colorno sensitive capabilitygephi_set_node_labelno sensitive capabilitygephi_set_node_positionno sensitive capabilitygephi_set_node_sizeno sensitive capabilitygephi_set_preview_settingsno sensitive capabilitygephi_set_selection_modeno sensitive capabilitygephi_similarity_layoutno sensitive capabilitygephi_size_by_rankingno sensitive capabilitygephi_snapshotno sensitive capabilitygephi_stop_layoutno sensitive capabilitygephi_switch_perspectiveno sensitive capabilitygephi_switch_workspaceno sensitive capabilitygephi_text_to_networkno sensitive capabilitygephi_undono sensitive capabilitygephi_view_graphno sensitive capabilitygephi_visual_qano sensitive capabilitygephi_whatifno sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.11.0 latest |
A 96/100 | 2 | 1.9.0 | 2026-07-23 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan gephi-mcp --online --registry pypi
Security scan results for the Agentmail MCP server.
Security scan results for the Alfahq MCP server.
Security scan results for the Alpine MCP server.
Search the official Astro framework documentation.
Security scan results for the Atag MCP server.
Security scan results for the Aurais Mcp Research Reader MCP server.