Back to Browse

Molecare MCP Server

Developer ToolsLow Risk10.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Educational dermatology knowledge and mole tracking. No credentials needed. Not a medical device.

About

Educational dermatology knowledge and mole tracking. No credentials needed. Not a medical device.

Security Report

10.0
Low Risk10.0Low Risk

Valid MCP server (2 strong, 2 medium validity signals). No known CVEs in dependencies. Package registry verified. Imported from the Official MCP Registry.

3 files analyzed · 1 issue found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

database

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

Base URL of a MoleCare-compatible HTTP API. Omit to run in mock mode with synthetic data.Optional

Environment variable: MOLECARE_API_URL

API key for the MoleCare API. Only needed when MOLECARE_API_URL points at a real backend.Required

Environment variable: MOLECARE_API_KEY

MLflow tracking server for experiment and model-run tools. Mocked when unset.Optional

Environment variable: MLFLOW_TRACKING_URI

AWS region for EC2 and CloudWatch operations tools. Credentials come from the standard AWS chain.Optional

Environment variable: AWS_REGION

Logging verbosity (error, warn, info, debug).Optional

Environment variable: LOG_LEVEL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-molecare-molecare-mcp": {
      "env": {
        "LOG_LEVEL": "your-log-level-here",
        "AWS_REGION": "your-aws-region-here",
        "MOLECARE_API_KEY": "your-molecare-api-key-here",
        "MOLECARE_API_URL": "your-molecare-api-url-here",
        "MLFLOW_TRACKING_URI": "your-mlflow-tracking-uri-here"
      },
      "args": [
        "-y",
        "molecare-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

MoleCare MCP Server

npm version npm downloads License Node MCP Contributors

Model Context Protocol (MCP) server that gives Claude and other MCP clients access to:

  1. Dermatology knowledge — ABCDE education, SNOMED CT / ICD-10 helpers, risk-factor prompts
  2. Optional MoleCare API tools — moles, trends, analysis (your backend + API key)
  3. Optional MLOps / ops tools — shipped as a separate binary, molecare-ops-mcp (mock-first)

Not a medical device. Outputs are educational and operational aids only. Do not use for diagnosis or treatment decisions.

Product site: molecare.co.uk · App: iOS · Android


Why this exists

MoleCare helps people track moles over time and prepare for clinician visits. This MCP server lets developers and operators:

  • Query educational skin-health knowledge from Claude Desktop / Cursor
  • Prototype assistant flows against a MoleCare-compatible API
  • Explore MLOps tooling with safe mock data when no credentials are set

Quick start

No credentials, no database, no cloud account. Add this to your MCP client config and restart it:

{
  "mcpServers": {
    "molecare": {
      "command": "npx",
      "args": ["-y", "molecare-mcp"]
    }
  }
}

For Claude Desktop on macOS that file is ~/Library/Application Support/Claude/claude_desktop_config.json.

The dermatology knowledge tools work immediately — they read from a knowledge base bundled in the package. Everything that talks to a backend returns clearly-labelled mock data until you configure it, so you can explore the whole tool surface before deciding whether you want any of it.

To try it without a client at all:

npx -y molecare-mcp

It starts and waits on stdio. No output means it is working.


Connecting a real backend

Only needed if you are running a MoleCare-compatible API:

{
  "mcpServers": {
    "molecare": {
      "command": "npx",
      "args": ["-y", "molecare-mcp"],
      "env": {
        "MOLECARE_API_URL": "http://localhost:8080/api",
        "MOLECARE_API_KEY": "your-local-api-key"
      }
    }
  }
}

Use localhost (or your own deployment). Do not paste production keys into config files that sync to cloud drives.


Environment variables

Every setting is optional. The public server falls back to mock product data without API credentials, and its knowledge tools continue to work offline. For the operations server, use NODE_ENV=development (the .env.example default) to keep integrations in mock mode.

Shared by both binaries

VariablePurposeExample
MOLECARE_API_URLMoleCare-compatible HTTP APIhttp://localhost:8080/api
MOLECARE_API_KEYAPI bearer/key; required with a real MoleCare APIlocal-dev-key
LOG_LEVELLogging verbosity: debug, info, warn, or errorinfo
MCP_HEALTH_PORTPreferred port for the optional HTTP /health endpoint3000
PORTFallback health port, useful for container platforms3000
PRIVACY_GATE_URLOptional local sidecar that checks tool results before egresshttp://localhost:8231
PRIVACY_GATE_TIMEOUT_MSPrivacy-gate request timeout in milliseconds4000

Public server (molecare-mcp)

The public server has no additional settings. Its dermatology knowledge works without configuration; the shared MoleCare API variables enable its optional mole and profile tools.

Operations server (molecare-ops-mcp)

The operations binary also accepts the shared settings above. These additional variables only configure its infrastructure, monitoring, and CI/CD tools:

VariablePurposeExample
NODE_ENVdevelopment forces mock mode; use production only with configured servicesdevelopment
MLFLOW_TRACKING_URIMLflow tracking serverhttp://localhost:5000
MLFLOW_API_KEYOptional MLflow API key—
ML_SERVING_URLModel-serving health endpointhttp://localhost:5000/health
FEAST_SERVER_URLFeast feature serverhttp://localhost:6566
FEAST_PROJECTFeast project namemolecare
WEB_APP_URLMoleCare web applicationhttp://localhost:3000
MOBILE_API_URLMoleCare mobile APIhttp://localhost:8080/api
ADMIN_API_URLMoleCare admin APIhttp://localhost:8080
BACKEND_URLBackend health endpointhttp://localhost:8080
METRICS_API_URLApplication metrics API; leaving it empty keeps app monitoring mocked—
GITHUB_OWNERRepository owner used by CI/CD toolsMoleCare
GITHUB_REPORepository name used by CI/CD toolsMoleCare-ML
GITHUB_TOKENGitHub token used by CI/CD tools—
AWS_REGIONAWS region used by EC2 and CloudWatch toolsus-east-1
AWS_PROFILENamed AWS credential profile—
AWS_ACCESS_KEY_IDAWS SDK credential-chain access key; prefer a role or profile—
EC2_INSTANCE_IDSComma-separated EC2 instance IDs—
DB_HOSTPostgreSQL host used by database health checkslocalhost
DB_PORTPostgreSQL port5432
DB_NAMEPostgreSQL database namemolecare
REDIS_HOSTRedis host and portlocalhost:6379
ES_HOSTElasticsearch host and portlocalhost:9200

See .env.example for the copyable source-of-truth list.


Tools

Dermatology knowledge — no setup required

These are the reason most people install this. They answer from a bundled knowledge base and need no API, no key, and no network.

ToolDescription
search_medical_infoSearch the dermatology knowledge base
lookup_medical_conceptLook up a SNOMED CT concept
search_medical_conceptsSearch conditions by name or description
map_snomed_to_icd10Map a SNOMED CT code to ICD-10
classify_lesion_featuresABCDE-style feature descriptors for a lesion
assess_risk_from_factorsNamed educational risk factors (no score)
get_condition_risk_factorsKnown risk factors for a condition
get_condition_progressionTypical progression stages for a condition
get_malignant_conditionsMalignant skin conditions with codes

Resources: molecare://knowledge/* — ABCDE criteria, Fitzpatrick skin types, prevention, when to see a dermatologist. molecare://ontology/* — SNOMED CT and ICD-10 reference lists, the full snomed-icd10-map mapping table, and risk factors, all with provenance metadata.

Educational prompts

The server also exposes three reusable MCP prompts: walk_through_abcde, prepare_dermatology_appointment, and explain_snomed_code. They help a client organize observations or explain terminology without diagnosing a condition, assigning urgency, or producing a risk score. Every rendered prompt includes the non-diagnostic educational disclaimer; the terminology prompt requires a SNOMED CT code argument.

What the terminology actually covers

Bundled
SNOMED CT concepts7 — melanoma, melanoma in situ, BCC, SCC, actinic keratosis, dysplastic naevus, melanocytic naevus
WHO ICD-10 categories25 — malignant, in situ, benign, precancerous, inflammatory and pigmentation, across Chapters II and XII
SNOMED → ICD-10 mappings9 rows covering all 7 concepts — some concepts have more than one plausible target

Every SNOMED concept the server advertises resolves through lookup_medical_concept and maps through map_snomed_to_icd10. Ask for a code outside the subset and the response carries a coverage block listing what is bundled, rather than an empty result. Browse the whole table with the molecare://ontology/snomed-icd10-map resource.

ICD-10 coverage is deliberately broader than SNOMED coverage. Expanding the bundled SNOMED concept set is on hold pending a redistribution question with SNOMED International: free use in a member country is not the same as free redistribution via npm to non-member territories (#49). WHO licenses ICD-10 more permissively at this level, so that side can grow in the meantime.

Terminology provenance

Bundled SNOMED CT / ICD-10 helpers are an educational subset, not a licensed terminology distribution. Named sources live in src/resources/terminology-provenance.ts and are returned on map_snomed_to_icd10 and the ontology resources:

SystemWhat this package reflects
SNOMED CTInternational Edition concept IDs / FSNs checked against the SNOMED International browser (last checked 2026-09-03). Plain-English search aliases are written for this package and are not SNOMED descriptions
ICD-10WHO ICD-10 category-level codes (e.g. C43, D22), with four-character subcategories only where the category alone would mislead (L57.0, D18.0). Not ICD-10-CM — codes such as C4A are deliberately absent
SNOMED → ICD-10Approximate category-level mappings — not certified one-to-one map rows. Each row carries a rationale

The dataset itself lives in src/resources/terminology-data.ts and is the single source for both the src/api/ontology-client.ts mock paths and the ontology resources. Educational prose without clinical codes lives in src/resources/medical-kb.ts.

MoleCare product data — needs an API

Returns labelled mock data until MOLECARE_API_URL is set.

ToolDescription
get_user_molesList moles for a user id
get_mole_analysisAnalysis payload for a mole
get_mole_changesChange history for a mole
get_user_risk_factorsA user's risk profile
compare_molesCompare two moles

These exist because MoleCare operates this stack from an assistant. They are of little use outside that context, and all of them return mock data unless the matching backend is configured.

They are not part of the molecare-mcp tool list. Loading 39 infrastructure tools that nobody outside MoleCare can use made it measurably harder for a model to pick the right dermatology tool, so they live in their own server:

{
  "mcpServers": {
    "molecare-ops": {
      "command": "npx",
      "args": ["-y", "-p", "molecare-mcp", "molecare-ops-mcp"]
    }
  }
}
AreaTools
Healthget_system_health, check_server_health, get_service_health, clear_cache
MLflowget_mlflow_experiments, get_mlflow_runs, get_registered_models, get_model_version, compare_model_runs, get_training_runs
Feature storeget_feature_views, get_feature_view_details, get_feature_freshness, get_online_features, get_feature_store_stats
CI/CDget_pipeline_runs, get_pipeline_summary, get_deployments, get_deployment_status, get_releases
AWSget_ec2_instances, get_ec2_instance, get_ec2_health, get_ec2_metrics
Appsget_app_status, get_web_app_status, get_mobile_api_status, get_all_apps_status, get_app_metrics, get_app_errors, get_app_versions, get_app_store_status
Databaseget_database_status, get_database_metrics, get_slow_queries, get_table_stats, get_backup_history, get_connection_pools
Kubernetesget_kubernetes_status

The AWS tools need @aws-sdk/client-ec2 and @aws-sdk/client-cloudwatch, which are optional peer dependencies — they are not installed by default, because they add 33 MB that nobody wanting the dermatology tools should have to download. Install them yourself if you want live AWS data:

npm i @aws-sdk/client-ec2 @aws-sdk/client-cloudwatch

Architecture

Claude / Cursor / MCP client
        │ stdio (JSON-RPC)
        ▼
  molecare-mcp                    molecare-ops-mcp
   ├─ medical KB (local)           ├─ MLflow / Feast clients
   ├─ MoleCare API client          ├─ AWS / CI / K8s clients
   └─ ontology client              └─ database / app clients
        │    (14 tools)                 │   (39 tools, internal)
        │                               │
        └───────────┬───────────────────┘
                    └─ optional HTTP GET /health  (Docker / ECS)

Docker

docker build -t molecare-mcp .
docker run --rm -p 3000:3000 molecare-mcp
curl http://localhost:3000/health

Security

  • Never commit .env files or API keys — see SECURITY.md to report a vulnerability
  • Prefer mock mode for demos and screenshots
  • Tools that accept userId can return PHI only if you point them at a real backend with real auth — treat that as production
  • Rate-limit and auth belong on your API, not only on the MCP process

Medical disclaimer

MoleCare MCP provides educational information and developer tooling. It does not diagnose melanoma or any disease. Always consult a qualified clinician for medical concerns.


Development

git clone https://github.com/MoleCare/molecare-mcp.git
cd molecare-mcp
npm install
npm run build
npm run dev      # auto-reload
npm run inspect  # browse tools in MCP Inspector

Contributions are welcome. Read CONTRIBUTING.md first — it covers the mock-first rule, the clinical-safety boundary for anything touching medical content, and how to pick up a good first issue.

Please keep secrets out of examples and prefer localhost defaults.


Related

Environment variables: .env.example is the authoritative list. CI compares it with the variables reachable from both server entrypoints and checks the public/operations grouping above.


Contributors

Thank you to everyone who has helped molecare-mcp.

The list is filled by Contributors from GitHub commits, bots omitted — never hand-maintained, because a stale list is worse than none. Contributor graph · good first issue

License

Apache-2.0 © MoleCare LTD

Reviews

No reviews yet

Be the first to review this server!