Cedar Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Cedar Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol (MCP) server for interacting with the CEDAR (Center for Expanded Data Annotation and Retrieval) metadata repository.
Before using this MCP server, you'll need API keys from:
Set your API keys as environment variables:
export CEDAR_API_KEY="your-cedar-key"
export BIOPORTAL_API_KEY="your-bioportal-key"Run directly without installation using uvx:
uvx cedar-mcpInstall from PyPI and run:
pip install cedar-mcp
cedar-mcpNote: The--cedar-api-keyand--bioportal-api-keyCLI flags are deprecated and will be removed in a future release. Use environment variables instead.
By default, the server uses stdio transport. You can also run it as an HTTP server using SSE or streamable-http transports:
# SSE transport on default host/port (127.0.0.1:8000)
cedar-mcp --transport sse
# Streamable HTTP on custom host/port
cedar-mcp --transport streamable-http --host 0.0.0.0 --port 9000| Flag | Choices | Default | Description |
|---|---|---|---|
--transport | stdio, sse, streamable-http | stdio | Transport protocol |
--host | — | 127.0.0.1 | Host to bind to (HTTP transports only) |
--port | — | 8000 | Port to bind to (HTTP transports only) |
Add the CEDAR MCP server to Claude Code:
claude mcp add cedar-mcp --uvx -e CEDAR_API_KEY=your-cedar-key -e BIOPORTAL_API_KEY=your-bioportal-keyTo use with Claude Desktop app:
claude_desktop_config.json:{
"mcpServers": {
"cedar-mcp": {
"command": "uvx",
"args": [
"cedar-mcp"
],
"env": {
"CEDAR_API_KEY": "your-cedar-key",
"BIOPORTAL_API_KEY": "your-bioportal-key",
"CEDAR_MCP_CACHE_TTL_SECONDS": "86400",
"CEDAR_MCP_CACHE_DIR": "/path/to/custom/location"
}
}
}
}Or if you have it installed locally:
{
"mcpServers": {
"cedar-mcp": {
"command": "cedar-mcp",
"env": {
"CEDAR_API_KEY": "your-cedar-key",
"BIOPORTAL_API_KEY": "your-bioportal-key",
"CEDAR_MCP_CACHE_TTL_SECONDS": "86400",
"CEDAR_MCP_CACHE_DIR": "/path/to/custom/location"
}
}
}
}The CEDAR_MCP_CACHE_TTL_SECONDS and CEDAR_MCP_CACHE_DIR environment variables are optional. When set under the "env" key, Claude Desktop injects them into the server process environment before it starts, so the cache picks them up automatically. If omitted, the defaults apply (24-hour TTL and a platform-specific cache directory — see Cache Configuration).
Here is the list of CEDAR tools with a short description
get_cedar_template: Fetches a template from the CEDAR repository.get_instances_based_on_template: Gets template instances that belong to a specific template with pagination support.term_search_from_branch: Searches BioPortal for standardized ontology terms within a specific branch.term_search_from_ontology: Searches BioPortal for standardized ontology terms within an entire ontology.get_branch_children: Fetches all immediate children terms for a given branch in an ontology.get_ontology_class_tree: Fetches the hierarchical tree structure for a given class in an ontology.remove_stale_cache_entries: Removes expired entries from the BioPortal search cache.clear_bioportal_cache: Clears all entries from the BioPortal search cache.BioPortal search results are cached locally using SQLite to reduce latency and API load. The cache persists across server restarts.
| Variable | Default | Description |
|---|---|---|
CEDAR_MCP_CACHE_TTL_SECONDS | 86400 (24 hours) | Time-to-live for cached BioPortal responses |
CEDAR_MCP_CACHE_DIR | Platform-specific (see below) | Override the cache directory location |
Default cache locations:
~/Library/Caches/cedar-mcp$XDG_CACHE_HOME/cedar-mcp or ~/.cache/cedar-mcp%LOCALAPPDATA%/cedar-mcp/cachepip install -r requirements-dev.txtThis project includes comprehensive integration tests that validate real API interactions with both CEDAR and BioPortal APIs.
For detailed testing information, see test/README.md.
Contributions are welcome! Please ensure all tests pass before submitting a Pull Request:
python run_tests.py --integrationThis project is licensed under the MIT License — see the LICENSE file for details.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.