Dify Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Dify Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Expose Dify knowledge base retrieval capabilities via MCP (Model Context Protocol), for use in Cursor and other MCP-compatible clients.
Connect to a self-hosted or remote Dify instance over HTTP, with optional dataset allowlisting for access control.
POST /datasets/{dataset_id}/retrievedataset_id valuesgit clone https://github.com/your-username/dify-mcp.git
cd dify-mcp
python3.11 -m venv .venv
# Windows
.venv\Scripts\python.exe -m pip install -e .
# macOS / Linux
.venv/bin/python -m pip install -e .Verify import:
# Windows
.venv\Scripts\python.exe -c "import dify_mcp; print('OK')"
# macOS / Linux
.venv/bin/python -c "import dify_mcp; print('OK')"Copy the example env file and edit it:
cp .env.example .envDIFY_API_BASE=http://your-dify-host/v1
DIFY_API_KEY=dataset-your-api-key
DIFY_ALLOWED_DATASETS=dataset-uuid-1,dataset-uuid-2
DIFY_TIMEOUT=30
DIFY_VERIFY_SSL=false| Variable | Description |
|---|---|
DIFY_API_BASE | Dify Knowledge API base URL, e.g. http://192.168.1.100/v1 |
DIFY_API_KEY | Knowledge Base API key |
DIFY_ALLOWED_DATASETS | Comma-separated dataset UUIDs to expose (required) |
DIFY_TIMEOUT | HTTP timeout in seconds (default: 30) |
DIFY_VERIFY_SSL | Verify TLS certificates (default: false for self-signed certs) |
Run the health check:
# Windows
.venv\Scripts\python.exe scripts/health_check.py
# macOS / Linux
.venv/bin/python scripts/health_check.pyYou do not need to start the MCP server manually. Cursor launches it automatically via stdio.
mcpServers in your MCP config file:%USERPROFILE%\.cursor\mcp.json~/.cursor/mcp.jsonSee mcp.json.example for a full example.
Windows example:
{
"mcpServers": {
"dify-knowledge": {
"command": "/absolute/path/to/dify-mcp/.venv/Scripts/python.exe",
"args": ["-m", "dify_mcp.server"],
"cwd": "/absolute/path/to/dify-mcp",
"env": {
"DIFY_API_BASE": "http://your-dify-host/v1",
"DIFY_API_KEY": "dataset-your-api-key",
"DIFY_ALLOWED_DATASETS": "dataset-uuid-1,dataset-uuid-2",
"DIFY_TIMEOUT": "30",
"DIFY_VERIFY_SSL": "false"
}
}
}
}macOS / Linux example:
{
"mcpServers": {
"dify-knowledge": {
"command": "/absolute/path/to/dify-mcp/.venv/bin/python",
"args": ["-m", "dify_mcp.server"],
"cwd": "/absolute/path/to/dify-mcp",
"env": {
"DIFY_API_BASE": "http://your-dify-host/v1",
"DIFY_API_KEY": "dataset-your-api-key",
"DIFY_ALLOWED_DATASETS": "dataset-uuid-1,dataset-uuid-2"
}
}
}
}dify-knowledge shows as enabled| Tool | Description |
|---|---|
list_datasets | List knowledge bases within the allowlist |
get_dataset | Get metadata for one dataset |
search_knowledge | Retrieve relevant chunks (primary retrieval tool) |
list_documents | List documents in a dataset |
list_document_segments | List text segments for a document |
Cursor (MCP client)
│ stdio
▼
dify-mcp (local process)
│ HTTPS / HTTP
▼
Dify Knowledge API (/v1/datasets/...)The MCP server runs locally on your machine and calls the Dify API over the network. Dify does not need to reach your machine.
| Issue | Cause | Fix |
|---|---|---|
No matching distribution found for mcp | Python < 3.11 | Use Python 3.11+ in .venv |
| MCP shows error (red) | Wrong Python path, invalid key, or network issue | Check mcp.json paths and env vars |
401 Unauthorized | Invalid API key | Regenerate key in Dify Service API panel |
Dataset not in allowed list | UUID not in DIFY_ALLOWED_DATASETS | Add the dataset UUID to the allowlist |
| Health check missing env vars | .env not found | Ensure .env exists in the project root |
| Connection timeout | Dify unreachable | Check network / VPN / firewall |
dify-mcp/
├── src/dify_mcp/
│ ├── server.py # MCP entry point
│ ├── config.py # Settings and allowlist
│ ├── dify_client.py # Dify Knowledge API client
│ └── formatters.py # Response formatting
├── scripts/
│ └── health_check.py # Connectivity test
├── mcp.json.example # Cursor MCP config template
├── .env.example # Environment variable template
└── Dify-API.md # Local API path referenceDify-API.md.env or API keys to version controlDIFY_ALLOWED_DATASETS to limit exposuremcp.json env or .env on your machine only~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.