Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/neo4j-contrib/mcp-neo4jWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/neo4j-contrib/mcp-neo4j/gemini-extension)<a href="https://agentmods.dev/plugins/neo4j-contrib/mcp-neo4j/gemini-extension"><img src="https://agentmods.dev/badge/plugins/neo4j-contrib/mcp-neo4j/gemini-extension/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/plugins/neo4j-contrib/mcp-neo4j/gemini-extension"><img src="https://agentmods.dev/badge/plugins/neo4j-contrib/mcp-neo4j/gemini-extension.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
mcp-neo4j scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "mcp-neo4j",
"version": "1.0.1",
"mcpServers": {
"mcp-neo4j-cloud-aura-api": {
"command": "uvx",
"args": [ "mcp-neo4j-aura-manager" ]
},
"mcp-neo4j-cypher": {
"command": "uvx",
"args": [ "mcp-neo4j-cypher" ]
},
"mcp-neo4j-data-modeling": {
"command": "uvx",
"args": [ "mcp-neo4j-data-modeling" ]
},
"mcp-neo4j-memory": {
"command": "uvx",
"args": [ "mcp-neo4j-memory" ]
}
},
"settings": [
{
"name": "NEO4J_URI",
"description": "Neo4j connection URI (e.g., bolt://localhost:7687 or neo4j+s://xxxx.databases.neo4j.io)",
"envVar": "NEO4J_URI"
},
{
"name": "NEO4J_USERNAME",
"description": "Neo4j username",
"envVar": "NEO4J_USERNAME"
},
{
"name": "NEO4J_PASSWORD",
"description": "Neo4j password",
"envVar": "NEO4J_PASSWORD",
"sensitive": true
},
{
"name": "NEO4J_DATABASE",
"description": "Neo4j database name (default: neo4j)",
"envVar": "NEO4J_DATABASE"
},
{
"name": "NEO4J_AURA_CLIENT_ID",
"description": "Neo4j Aura API Client ID",
"envVar": "NEO4J_AURA_CLIENT_ID"
},
{
"name": "NEO4J_AURA_CLIENT_SECRET",
"description": "Neo4j Aura API Client Secret",
"envVar": "NEO4J_AURA_CLIENT_SECRET",
"sensitive": true
},
{
"name": "NEO4J_NAMESPACE",
"description": "Namespace prefix for tool names",
"envVar": "NEO4J_NAMESPACE"
}
]
}What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 61 lines scan A 0a54ce73fc69
mcp-neo4j is a plugin published in the GitHub repository neo4j-contrib/mcp-neo4j (980 stars, last pushed 4d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-09.
Other plugins, from other repositories
nlqdb-memory
Persistent, queryable memory for your agent: a real Postgres it asks in plain English over MCP, so it can GROUP BY / JOIN / aggregate over what it remembered instead of recalling the nearest few rows. Bundles the hosted MCP server plus two skills that teach the agent when to use it.
hypermnesia-mcp
Cortex — persistent memory for Claude Code that remembers across sessions automatically. Install and forget. Scientific retrieval backed by 97 published references. (Renamed from the 'cortex' plugin to match the PyPI/MCP-registry identity.).
cortex
Persistent local-first memory MCP server: remember/recall with thermodynamic heat and decay, knowledge graph, autonomous wiki, local SQLite store by default. Requires uv (uvx) on PATH; hooks-based auto-capture is Claude Code-only — on Gemini CLI memory is manual-tool-driven.
toonify-mcp
Local context compression for Claude Code workflows, including structured data and debug-heavy output.
mnemo-mcp
Persistent AI memory — store, search, and recall knowledge across sessions.
xmemo
Connect Cursor to XMemo's hosted, user-owned memory layer for durable project context, coding preferences, decisions, and reusable agent knowledge.