onec-mcp

Loads a 1C configuration XML export into Neo4j and gives read-only MCP access to metadata, BSL routines and rights via text and full-text search

MCP server

Low risk

We rate an entry low when it mostly gives the agent instructions and reference material.

Why this level

  • MCP only reads the Neo4j graph and never writes back; writing is only possible through the separate load_config process
All reasons and checks
Russian stack

youngpadovan/onec-mcp

Install

Manual install

python scripts/docker/start_docker.py

Brings up Neo4j and the MCP server, waits for Neo4j to be ready, and runs load_config from ONEC_ERP_XML_HOST.

This is third-party code. Review the repository files before installing.

What it does

A Docker stack parses a 1C configuration XML export and builds a Neo4j graph: metadata objects, BSL routines and functions with CALLS edges, and roles and rights from Rights.xml. The agent gets about 25 MCP tools: a list of metadata kinds, objects and their cards, roles by object, an overview with a dossier and routine index, full module or single-procedure text by qualified_name, a call graph to a given depth, a comparison of two roles' grants, and trusted Cypher templates for graph reports. Procedure and metadata search works only by substring and Neo4j full-text index, no vector embeddings.

Who it is for. For 1C analysts and developers who need a local configuration graph for navigating metadata, code and rights without the cloud.

Good fit when

  • You need to find which roles grant access to a metadata object
  • You need to find every caller of a procedure and trace a call chain
  • You want a local knowledge base for the configuration without sending code out

Not a fit when

  • You need a full static call analysis: the CALLS graph is heuristic and does not resolve dynamic Выполнить
  • You need semantic code search: only text and full-text search are available

Example request

Which roles grant access to Справочник.Номенклатура, and who calls the ПроверитьЗаказ procedure

Limitations

The tool only reads the graph, never writes back to Neo4j, and does not run the export from 1C itself. The CALLS call graph is a text-based heuristic, not a full static analysis. One Neo4j instance holds one configuration; a second one needs a separate Compose project. A large ERP export needs tens of gigabytes of RAM.

How to disable. Stop the stack with docker compose -f docker/docker-compose.yml down and remove the server from your MCP client configuration.

MCP

Transport
http
Authentication
not required
Environment variables
Environment variables
ONEC_ERP_XML_HOST
required
Host path to the root of the 1C configuration XML export.
NEO4J_PASSWORD
required, secret
Password for the Neo4j database, set in docker/.env.
ONEC_OPENAI_API_KEY
secret
Key for the optional natural-language-to-Cypher translation feature.

Security check

  • MCP only reads the Neo4j graph and never writes back; writing is only possible through the separate load_config process

README in short

The bilingual README describes the flow from ONEC_ERP_XML_HOST through load_config into Neo4j and MCP on port 8840, a table of the main MCP tools, the principle of trusted Cypher templates instead of free-form write-Cypher, a responsibility split between chat, MCP and load_config, a security section on non-exposed ports and a mandatory Neo4j password, and limitations around the CALLS graph being heuristic.

FAQ

Does procedure search use vector embeddings?

No, search runs only on substring and the Neo4j routine_search full-text index, with no Ollama or vector fields.

Can arbitrary Cypher be written to the database from chat?

No, only dedicated tools and trusted templates from a registry are available; write-Cypher from chat is not supported.

Editors’ pick

A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review

PluginMedium riskNo VPN needed292.5KRepository stars
Editors’ pick

Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture

SkillLow risk271.4KRepository stars
Editors’ pick

GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation

CLIMedium riskNo VPN needed139.3KRepository stars

Reference MCP servers

Model Context Protocol servers

Official

Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything

MCP serverMedium risk90.6KRepository stars
Foxx AIonec-mcp

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.