graphjin — security grade SAFE, quality 68/100

Security audit verdict: SAFE · quality 68/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by dosco · MCP Server · ★ 3.2k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is graphjin safe to install? View the security audit →

About graphjin

GraphJin — One Governed Graph for Your AI Agents GraphJin is a compiler and runtime that gives AI agents one governed graph over the systems a real company already has: databases, warehouses, files, source code, workflows, metadata, and security policy. Instead of handing an agent raw credentials and hoping it guesses correctly, GraphJin exposes that graph through GraphQL + MCP: the agent discovers before acting, validates queries, runs approved work, observes runtime status — and every answer is checked against an execution ledger before it leaves the server. It is not only for agents. GraphJin is still a high-performance GraphQL-to-databa

agentic-aiai-agentscloud-nativecockroachdbdatabasegraphqlllmmariadbmcpmongodb

Quick Facts

Stars3,167
Forks195
LanguageGo
CategoryMCP Server
LicenseApache-2.0
Quality Score68.1833786165692/100
Open Issues22
Last Updated2026-09-11
Created2019-03-24
Platformsgo, mcp
Est. Tokens~25k

Compatible Skills

These tools work well together with graphjin for enhanced workflows:

  • mariadb-operator — semantic(0.33)+complementary+rare_topics+same_lang+similar_pop+shared_platform (66%)
  • mcp-toolbox — semantic(0.38)+rare_topics+same_lang+similar_pop+shared_platform (62%)
  • cloudpods — semantic(0.19)+complementary+same_lang+similar_pop+shared_platform (57%)
  • dbhub — semantic(0.42)+rare_topics+similar_pop+shared_platform (49%)

graphjin alternative? Top 6 similar tools

Looking for a graphjin alternative? If you're comparing graphjin with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • dbhub by bytebase · ⭐ 3.5k

    Token conscious database MCP server for Postgres, MySQL, SQL Server, MariaDB, SQLite.

  • tabularis by TabularisDB · ⭐ 4.9k

    Open-source desktop SQL workspace for PostgreSQL, MySQL/MariaDB, SQLite and 15+ more databases like DuckDB, Cl

  • anyquery by julien040 · ⭐ 1.7k

    One SQL interface for 60+ tools (e.g., GitHub, Notion, Airtable). Plug into any LLM through MCP.

  • nocturne_memory by Dataojitori · ⭐ 1.3k

    A lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Say goodbye to Vector RAG and

  • tabularis by debba · ⭐ 1.2k

    A lightweight, cross-platform database client for developers. Supports MySQL, PostgreSQL and SQLite. Hackable

  • mariadb-operator by mariadb-operator · ⭐ 1.0k

    🦭 Run and operate MariaDB in a cloud native way

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Go Agent Tools

Frequently Asked Questions

What is graphjin?

graphjin is One governed graph for AI agents — GraphQL + MCP over your databases, files, APIs, and code. It is categorized as a MCP Server with 3.2k GitHub stars.

What programming language is graphjin written in?

graphjin is primarily written in Go. It covers topics such as agentic-ai, ai-agents, cloud-native.

How do I install or use graphjin?

You can find installation instructions and usage details in the graphjin GitHub repository at github.com/dosco/graphjin. The project has 3.2k stars and 195 forks, indicating an active community.

What license does graphjin use?

graphjin is released under the Apache-2.0 license, making it free to use and modify according to the license terms.

What are the best alternatives to graphjin?

The top alternatives to graphjin on Agent Skills Hub include dbhub, tabularis, anyquery. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools