Neo4J Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Neo4J Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
MCP server for Neo4j graph database operations.
Version: 0.1.3 Status: Internal Bodai integration component
Crackerjack is the standard quality-control and CI/CD gate for Neo4j MCP changes. Local verification should mirror the Crackerjack workflow used across the Bodai ecosystem.
______________________________________________________________________
Neo4j MCP exposes graph database workflows through a FastMCP server. It gives agents a typed interface for Cypher execution, node and relationship management, path discovery, and schema inspection while preserving a narrow database client boundary.
Use this server when an agent needs to query or mutate graph data directly. Keep domain-specific graph policies in the calling system or a higher-level service layer rather than embedding them in generic Neo4j tools.
Implemented tool surface:
/health and /healthz for MCP client and process supervision checksgit clone https://github.com/lesleslie/neo4j-mcp.git
cd neo4j-mcp
uv sync --group devexport NEO4J_MCP_MOCK_MODE=true
uv run neo4j-mcp start
uv run neo4j-mcp healthexport NEO4J_MCP_URI="bolt://localhost:7687"
export NEO4J_MCP_USER="neo4j"
export NEO4J_MCP_PASSWORD="your-password"
export NEO4J_MCP_DATABASE="neo4j"
uv run neo4j-mcp startThe default HTTP bind is 127.0.0.1:3045.
The CLI is built with mcp-common and provides the standard lifecycle command surface used by Bodai MCP servers.
uv run neo4j-mcp start # Start the HTTP MCP server
uv run neo4j-mcp stop # Stop the managed server process
uv run neo4j-mcp restart # Restart the managed server process
uv run neo4j-mcp status # Show process status
uv run neo4j-mcp health # Run the local health probeAdd the server to an MCP client configuration:
{
"mcpServers": {
"neo4j": {
"command": "uv",
"args": ["run", "neo4j-mcp", "start"],
"cwd": "/Users/les/Projects/neo4j-mcp",
"env": {
"NEO4J_MCP_URI": "bolt://localhost:7687",
"NEO4J_MCP_USER": "neo4j",
"NEO4J_MCP_PASSWORD": "your-password",
"NEO4J_MCP_DATABASE": "neo4j"
}
}
}
}For tests or local client wiring, replace live connection values with NEO4J_MCP_MOCK_MODE=true.
curl http://127.0.0.1:3045/health
curl http://127.0.0.1:3045/healthz| Tool | Purpose | Required Inputs |
|---|---|---|
run_cypher | Execute a Cypher query | query |
create_node | Create a node with labels and properties | labels |
get_node | Retrieve a node by ID | node_id |
delete_node | Delete a node by ID | node_id |
find_nodes | Search nodes by labels and properties | none |
create_relationship | Create a typed relationship between nodes | type, start_node_id, end_node_id |
delete_relationship | Delete a relationship by ID | relationship_id |
find_paths | Find paths between two nodes | start_node_id, end_node_id |
get_schema | Retrieve database schema details | none |
Tool responses follow a consistent ToolResponse shape:
{
"success": true,
"message": "Query returned 3 records",
"data": {},
"error": null,
"next_steps": []
}Committed defaults live in settings/neo4j.yaml. Runtime overrides should come from environment variables or a local .env file that is not committed.
| Setting | Environment Variable | Default |
|---|---|---|
| Neo4j URI | NEO4J_MCP_URI | bolt://localhost:7687 |
| User | NEO4J_MCP_USER | neo4j |
| Password | NEO4J_MCP_PASSWORD | empty |
| Database | NEO4J_MCP_DATABASE | neo4j |
| Max connection lifetime | NEO4J_MCP_MAX_CONNECTION_LIFETIME | 3600 |
| Max pool size | NEO4J_MCP_MAX_CONNECTION_POOL_SIZE | 50 |
| Connection timeout | NEO4J_MCP_CONNECTION_TIMEOUT | 30.0 |
| Mock mode | NEO4J_MCP_MOCK_MODE | false |
| HTTP host | NEO4J_MCP_HTTP_HOST | 127.0.0.1 |
| HTTP port | NEO4J_MCP_HTTP_PORT | 3045 |
| Log level | NEO4J_MCP_LOG_LEVEL | INFO |
| JSON logs | NEO4J_MCP_LOG_JSON | true |
neo4j_mcp/
cli.py # mcp-common lifecycle CLI
client.py # Neo4j driver boundary
config.py # Pydantic settings and logging
models.py # Typed graph request and response models
server.py # FastMCP application factory
tools/graph_tools.py # Registered MCP tools
settings/
neo4j.yaml # Committed defaults
tests/uv sync --group dev
uv run pytest
uv run ruff check neo4j_mcp tests
uv run ruff format neo4j_mcp tests
uv run mypy neo4j_mcpUse targeted tests when isolating graph behavior:
uv run pytest tests -k graph -vparams when passing user-controlled values.run_cypher as a privileged tool because it can mutate data.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.