How to block unsafe Cypher queries in the Neo4j MCP server
To block unsafe Cypher queries in the Neo4j MCP server, guard the driver passed to create_mcp_server() in mcp-neo4j-cypher. Blocked queries raise GuardError and are never sent.
Install
pip install neo4j-guard mcp-neo4j-cypher
Guard the driver
Save this as server.py. The server's get_neo4j_schema tool calls apoc.meta.schema, so allow it.
import asyncio
from mcp_neo4j_cypher.server import create_mcp_server
from neo4j import AsyncGraphDatabase
from neo4j_guard import guard
async def main() -> None:
driver = guard(
AsyncGraphDatabase.driver("neo4j://localhost:7687", auth=("neo4j", "password")),
allow=["apoc.meta.schema"],
)
await create_mcp_server(driver, read_only=True).run_stdio_async()
asyncio.run(main())
Add the server to the MCP client
Run server.py instead of the mcp-neo4j-cypher command:
{
"mcpServers": {
"neo4j": {
"command": "python",
"args": ["/path/to/server.py"]
}
}
}
Compare with read_only
The server's read_only option removes the write_neo4j_cypher tool and rejects queries that Neo4j classifies as writes. The guarded driver also blocks:
- APOC and other procedures, except entries in
allow. LOAD CSV, which reads files and URLs.- Labels and properties in
disallow, in queries and in returned records.