# read_graph

Read the entire knowledge graph

Agent View of the PolicyLayer registry record for `read_graph`. HTML page: https://policylayer.com/tools/delorenj-mcp-qdrant-memory/read-graph

## Facts

- Tool: `read_graph`
- Server: MCP Memory Server with Qdrant Persistence (`delorenj/mcp-qdrant-memory`) — https://policylayer.com/tools/delorenj-mcp-qdrant-memory.md
- Homepage: https://github.com/delorenj/mcp-qdrant-memory
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Allowed

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "read_graph",
    "arguments": {}
  }
}
```

## Why read_graph is rated Low

This tool retrieves data without side effects, fitting the 'Read' category. Severity is medium rather than low because reading an 'entire' knowledge graph could expose large volumes of potentially sensitive information to an AI agent, and in a persistent system with HTTPS and file-based storage, the graph likely contains valuable business or personal data.

From the tool's own definition: "Tool name 'read_graph' combined with description 'Read the entire knowledge graph' clearly indicates data retrieval with no modification. However, the word 'entire' suggests bulk access to potentially sensitive structured knowledge."

Risk signals: Bulk/mass operation — affects multiple targets

## Use case

AI agents call read_graph to retrieve information from MCP Memory Server with Qdrant Persistence without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches MCP Memory Server with Qdrant Persistence:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "read_graph": {}
  }
}
```

## Other tools on MCP Memory Server with Qdrant Persistence (7)

- `delete_entities` — Destructive — https://policylayer.com/tools/delorenj-mcp-qdrant-memory/delete-entities.md
- `delete_observations` — Destructive — https://policylayer.com/tools/delorenj-mcp-qdrant-memory/delete-observations.md
- `delete_relations` — Destructive — https://policylayer.com/tools/delorenj-mcp-qdrant-memory/delete-relations.md
- `search_similar` — Read — https://policylayer.com/tools/delorenj-mcp-qdrant-memory/search-similar.md
- `add_observations` — Write — https://policylayer.com/tools/delorenj-mcp-qdrant-memory/add-observations.md
- `create_entities` — Write — https://policylayer.com/tools/delorenj-mcp-qdrant-memory/create-entities.md
- `create_relations` — Write — https://policylayer.com/tools/delorenj-mcp-qdrant-memory/create-relations.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=delorenj-mcp-qdrant-memory · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/delorenj-mcp-qdrant-memory
