No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by blurrah · MCP Server · ★ 407
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is mcp-graphql safe to install? View the security audit →
mcp-graphql A Model Context Protocol server that enables LLMs to interact with GraphQL APIs. This implementation provides schema introspection and query execution capabilities, allowing models to discover and use GraphQL APIs dynamically. Usage Run with the correct endpoint, it will automatically try to introspect your queries. Environment Variables (Breaking change in 1.0.0) Note: As of version 1.0.0, command line arguments have been replaced with environment variables. Examples bash Basic usage with a local GraphQL server ENDPOINT=http://localhost:3000/graphql npx mcp-graphql Using with custom headers ENDPOINT=https://api.example.com/graphql HEADERS='{"Authorization":"Bearer token123"}' npx mcp-graphql Enable mutation operations ENDPO
| Stars | 407 |
| Forks | 61 |
| Language | TypeScript |
| Category | MCP Server |
| License | MIT |
| Quality Score | 76.1223174185047/100 |
| Open Issues | 14 |
| Last Updated | 2025-09-08 |
| Created | 2024-12-21 |
| Platforms | mcp, node |
| Est. Tokens | ~19k |
These tools work well together with mcp-graphql for enhanced workflows:
Looking for a mcp-graphql alternative? If you're comparing mcp-graphql with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
The python library for research and development in NLP, multimodal LLMs, Agents, ML, Knowledge Graphs, and mor
A curated collection of top-tier penetration testing tools and productivity utilities across multiple domains.
A Model Context Protocol (MCP) server that enables secure interaction with MySQL databases
A security scanner for your LLM agentic workflows
📦️ A fast, secure MCP server that extends its capabilities through WebAssembly plugins.
Flow-Like: Strongly Typed Enterprise Scale Workflows. Built for scalability, speed, seamless AI integration an
Explore other popular mcp server tools:
mcp-graphql is Model Context Protocol server for GraphQL. It is categorized as a MCP Server with 407 GitHub stars.
mcp-graphql is primarily written in TypeScript. It covers topics such as ai, llm, mcp.
You can find installation instructions and usage details in the mcp-graphql GitHub repository at github.com/blurrah/mcp-graphql. The project has 407 stars and 61 forks, indicating an active community.
mcp-graphql is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to mcp-graphql on Agent Skills Hub include npcpy, awesome-hacking-lists, mysql_mcp_server. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: