MCP server for a PII graph on Neo4j
DataLens MCP Server
A FastMCP server for compliance queries against a PII graph in Neo4j, unrelated to the Yandex DataLens service
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- The server reads a graph containing personal data about people, though it does not modify it itself
Install
Manual install
pip install -r requirements.txtThen configure .env with your Neo4j parameters and run python server.py.
Security check
How we reviewMedium riskWe rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
- The server reads a graph containing personal data about people, though it does not modify it itself
This is third-party code. Review the repository files before installing.
What it does
The Python and FastMCP server connects to a Neo4j graph database and exposes a handful of compliance tools: finding where a specific PII type is stored, such as passport data or email, tracing a table's data lineage upstream and downstream, and listing data processing activities by status. The server does not build the graph itself: it expects tables, columns, files and their relationships to already be modeled in Neo4j under a specific schema, and it just queries them. The DataLens name here belongs only to this tool and has no connection to the Yandex service.
Who it is for. For data protection teams that already have a metadata graph in Neo4j and want agent access to it for compliance questions.
Good fit when
- You already have a graph of tables, columns and files with PII tagging in Neo4j
- You want quick answers to questions like "where is passport data stored" through an agent
Not a fit when
- You are looking for the Yandex DataLens BI dashboard service: this is a different, unrelated product
- You do not yet have a Neo4j metadata graph: the server only reads one, it does not build it
Example request
Find which tables and files store email-type data, based on the Neo4j graphMCP
- Transport
- stdio
- Authentication
- not required
Environment variables
NEO4J_URIrequired- The Neo4j connection URI, defaulting to neo4j://localhost:7687
NEO4J_USERrequired- The Neo4j username
NEO4J_PASSWORDrequired, secret- The Neo4j password
Limitations
The project is very small, a single file, maintained by one author with no stars. It has no connection to the Yandex DataLens service. It only works on top of an already-built Neo4j graph with a specific Table, Column, File, PII and ProcessingActivity node schema, and it has no tools for populating that graph.
How to disable. Stop the python server.py process and remove the server from your MCP client config.
FAQ
Will the server build the PII graph itself?
No, it only reads an already-existing graph in Neo4j under its schema; populating the graph is a separate task.
Related
MCP serversA code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents
README in short
The English README describes the server as a component for a DataLens compliance application, requiring Python 3.10 and a local Neo4j, gives setup steps via venv and pip, a development run via fastmcp dev for the tool inspector, and a stdio run for MCP client integration.