THRONE
See report Verify server

registry / record

@elastic/mcp-server-elasticsearch

npm / sealed 2026-06-16 / No. ee03bef8

Does @elastic/mcp-server-elasticsearch MCP work in Claude Code and Cursor? Throne executed @elastic/mcp-server-elasticsearch mcp in a single-use Firecracker microVM and replayed both recorded client behaviours. Compatibility verdict: needs launch arguments. Is @elastic/mcp-server-elasticsearch mcp safe? Static security scan: 2 finding(s) to review under security ruleset v1. The full per-step results, security findings, scan date, and evidence hash are below.

> throne registry @elastic/mcp-server-elasticsearch sealed
Upstream notice: the maintainer has deprecated this packageThis package is deprecated. Please see the README at https://github.com/elastic/mcp-server-elasticsearch for details on how to run v0.4.0 or later.
This server needs launch argumentsthe server requires command-line arguments (for example a database URL) that a bare launch does not pass, Server error: [ { "code": "too_small", "minimum": 1, "type": "string", "inclusive": true, "exact": false, "message": "Elasticsearch URL cannot be empty", "path": [ "url" ] }, { "validation": "url", "code": "invalid_string", "message": "Invalid Elasticsearch URL format", "path": [ "url" ] } ]
receiptsealed evidence
scan id
ee03bef8cac34aafa46bd780ace2d921
target
@elastic/mcp-server-elasticsearch
sealed at
2026-06-16 17:31:37Z
evidence hash
sha256:d2ee8d96fd3128be02a21560146e72cf7842c6f9e0025131718acd83eab3eb04
01connectFAIL0ms

server never launched: server process exited with code 1 before the MCP handshake, stderr: Server error: [ { "code": "too_small", "minimum": 1, "type": "string", "inclusive": true, "exact": false, "message": "Elasticsearch URL cannot be empty", "path": [ "url" ] }, { "validation": "url", "code": "invalid_string", "message": "Invalid Elasticsearch URL format", "path": [ "url" ] } ]

02discoverSKIPPED0ms

not run, server never launched

03validate_schemasSKIPPED0ms

not run, server never launched

04smoke_test_toolsSKIPPED0ms

not run, server never launched

05error_handlingSKIPPED0ms

not run, server never launched

06streamingSKIPPED0ms

not run, server never launched

07resource_lifecycleSKIPPED0ms

not run, server never launched

08concurrent_callsSKIPPED0ms

not run, server never launched

09reconnectSKIPPED0ms

not run, server never launched

01connectFAIL0ms

server never launched: server process exited with code 1 before the MCP handshake, stderr: Server error: [ { "code": "too_small", "minimum": 1, "type": "string", "inclusive": true, "exact": false, "message": "Elasticsearch URL cannot be empty", "path": [ "url" ] }, { "validation": "url", "code": "invalid_string", "message": "Invalid Elasticsearch URL format", "path": [ "url" ] } ]

02discoverSKIPPED0ms

not run, server never launched

03validate_schemasSKIPPED0ms

not run, server never launched

04smoke_test_toolsSKIPPED0ms

not run, server never launched

05error_handlingSKIPPED0ms

not run, server never launched

06streamingSKIPPED0ms

not run, server never launched

07resource_lifecycleSKIPPED0ms

not run, server never launched

08concurrent_callsSKIPPED0ms

not run, server never launched

09reconnectSKIPPED0ms

not run, server never launched

chatgpt desktop calibratingemulation profile pending real-traffic captureCOMING SOON
SECURITY: REVIEW / 2 finding(s) / review recommended
LOWTHR-INSTALL-03 / Install-time script execution (npm lifecycle)

"prepare" runs on git-dependency installs and local dev (not registry installs): 'npm run build'

package/dist/package.json
LOWTHR-INSTALL-03 / Install-time script execution (npm lifecycle)

"prepare" runs on git-dependency installs and local dev (not registry installs): 'npm run build'

package/package.json
VERDICT: NEEDS LAUNCH ARGUMENTSSANDBOXED RUN, submitted server executed in a disposable microVM, compatibility not assessable: needs arguments: the server requires command-line arguments (for example a database URL) that a bare launch does not pass, Server error: [ { "code": "too_small", "minimum": 1, "type": "string", "inclusive": true, "exact": false, "message": "Elasticsearch URL cannot be empty", "path": [ "url" ] }, { "validation": "url", "code": "invalid_string", "message": "Invalid Elasticsearch URL format", "path": [ "url" ] } ] / security: review, 2 finding(s), 0 highsealed by THRONE / No. ee03bef8 / 2026-06-16
scopeattestation tuple
target
@elastic/mcp-server-elasticsearch npm
engine
sandboxed
claude code
calibration: partial recorded=9,spec=0,assumed=9
cursor
calibration: partial recorded=11,spec=0,assumed=7
chatgpt desktop
calibration: unavailable recorded=0,spec=2,assumed=16
steps exercised
18 of 18
test suite
v1.0.0
security ruleset
v1.0.0
sealed at
2026-06-16 17:31:37Z
evidence hash
sha256:d2ee8d96fd3128be02a21560146e72cf7842c6f9e0025131718acd83eab3eb04
valid until
2026-09-14
executed in a disposable microVM, created for this scan and destroyed after it. nothing outlives a run.

maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.

this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.