onec-mcp
Loads a 1C configuration XML export into Neo4j and gives read-only MCP access to metadata, BSL routines and rights via text and full-text search
Low risk
We rate an entry low when it mostly gives the agent instructions and reference material.
Why this level
- MCP only reads the Neo4j graph and never writes back; writing is only possible through the separate load_config process
Install
Manual install
python scripts/docker/start_docker.pyBrings up Neo4j and the MCP server, waits for Neo4j to be ready, and runs load_config from ONEC_ERP_XML_HOST.
This is third-party code. Review the repository files before installing.
What it does
A Docker stack parses a 1C configuration XML export and builds a Neo4j graph: metadata objects, BSL routines and functions with CALLS edges, and roles and rights from Rights.xml. The agent gets about 25 MCP tools: a list of metadata kinds, objects and their cards, roles by object, an overview with a dossier and routine index, full module or single-procedure text by qualified_name, a call graph to a given depth, a comparison of two roles' grants, and trusted Cypher templates for graph reports. Procedure and metadata search works only by substring and Neo4j full-text index, no vector embeddings.
Who it is for. For 1C analysts and developers who need a local configuration graph for navigating metadata, code and rights without the cloud.
Good fit when
- You need to find which roles grant access to a metadata object
- You need to find every caller of a procedure and trace a call chain
- You want a local knowledge base for the configuration without sending code out
Not a fit when
- You need a full static call analysis: the CALLS graph is heuristic and does not resolve dynamic Выполнить
- You need semantic code search: only text and full-text search are available
Example request
Which roles grant access to Справочник.Номенклатура, and who calls the ПроверитьЗаказ procedureLimitations
The tool only reads the graph, never writes back to Neo4j, and does not run the export from 1C itself. The CALLS call graph is a text-based heuristic, not a full static analysis. One Neo4j instance holds one configuration; a second one needs a separate Compose project. A large ERP export needs tens of gigabytes of RAM.
How to disable. Stop the stack with docker compose -f docker/docker-compose.yml down and remove the server from your MCP client configuration.
MCP
- Transport
- http
- Authentication
- not required
| Environment variables | |
|---|---|
| ONEC_ERP_XML_HOST required | Host path to the root of the 1C configuration XML export. |
| NEO4J_PASSWORD required, secret | Password for the Neo4j database, set in docker/.env. |
| ONEC_OPENAI_API_KEY secret | Key for the optional natural-language-to-Cypher translation feature. |
Security check
- MCP only reads the Neo4j graph and never writes back; writing is only possible through the separate load_config process
README in short
The bilingual README describes the flow from ONEC_ERP_XML_HOST through load_config into Neo4j and MCP on port 8840, a table of the main MCP tools, the principle of trusted Cypher templates instead of free-form write-Cypher, a responsibility split between chat, MCP and load_config, a security section on non-exposed ports and a mandatory Neo4j password, and limitations around the CALLS graph being heuristic.
FAQ
Does procedure search use vector embeddings?
No, search runs only on substring and the Neo4j routine_search full-text index, with no Ollama or vector fields.
Can arbitrary Cypher be written to the database from chat?
No, only dedicated tools and trusted templates from a registry are available; write-Cypher from chat is not supported.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything