Back to Home
UnitVectorY-Labs icon

mcp-graphql-forge

by UnitVectorY-Labs

Overview

A modular MCP server that converts GraphQL API endpoints into discoverable and configurable tools for agents.

Installation

Run Command
FORGE_CONFIG=mcp-graphql-forge/example mcp-graphql-forge

Environment Variables

  • FORGE_CONFIG

Security Notes

The server's `token_command` configuration allows execution of arbitrary shell commands to obtain an authentication token. This introduces a severe Remote Code Execution (RCE) vulnerability if the `forge.yaml` configuration file is compromised or configured with an untrusted command. Additionally, `env_passthrough: true` could expose sensitive environment variables to the token command process. No hardcoded secrets or obfuscation were found.

Similar Servers

Stats

Interest Score34
Security Score3
Cost ClassMedium
Avg Tokens750
Stars4
Forks2
Last Update2026-01-17

Tags

GraphQLAPI IntegrationMCPGoTooling