Beever AtlasBLOCK
Your First LLM-Wiki Conversation Knowledge Base
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Beever Atlas
Turn your team's Slack, Discord, Teams & Mattermost chats into a self-maintaining wiki — automatically.
7655195ac754OBSERVED · 2026-09-30Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add beever-atlas:0.3.0 -- docker run -i --rm ghcr.io/beever-ai/beever-atlas:0.3.0:None python -m beever_atlas.api.mcp_server
Exposed tools (7)
5 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Lightweight | read | Syncs every hour with quick extraction. Organize knowledge manually. |
Manual | write | Full control — sync and organize only when you choose. |
Real-time | read | Updates every 5 minutes with full extraction and auto-organization. |
list_channels | read | List the channels the bot can actually read on one connection — the |
list_connections | read | List the platform connections (Slack workspaces, Discord servers, file |
start_new_session | write | Mint a fresh conversation session id that starts a new ``ask_channel`` thread. |
whoami | read | Confirm who you are authenticated as and which connection ids you can reach. |
Trust audit
BLOCKgrade F · trust 45/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
".env" ... urllib.request
[0xa9fe0000, 0xffff0000], // 169.254/16 (incl. 169.254.169.254)
"169.254.169.254/32",
**Discord Channel IDs**: In Discord, right-click a channel and select **Copy ID** (requires Developer Mode enabled in Discord settings).
pkg = importlib.import_module(package_name)
mod = importlib.import_module(modinfo.name)
mod = importlib.import_module(f"beever_atlas.wiki.modules.{module_id}")MONGODB_URI=mongodb://admin:<strong-password>@localhost:27017
secret = "VERY-SECRET-VALUE-DO-NOT-LEAK"
api_key="jina-secret-key-AAAA",
api_key="jina-secret-key-AAAA",
api_key="AIza-test-key-XYZ-ABCD",
api_key="AIza-test-key-XYZ-ABCD",
SLACK_BOT_TOKEN=xoxb-your-token-here
SLACK_BOT_TOKEN=xoxb-your-bot-token-here
SLACK_BOT_TOKEN=xoxb-your-token-here
SLACK_BOT_TOKEN=xoxb-your-token-here
SLACK_BOT_TOKEN=xoxb-your-token-here
.pre-commit-config.yaml
mod = importlib.import_module(f"beever_atlas.{submodule}")h = hashlib.sha1(f"{kind}|{native_identity}".encode("utf-8")).hexdigest()config({ path: resolve(import.meta.dirname, "../../.env") });result = await fn(connection_id="../../etc/passwd", ctx=ctx_mock)
result = await fn(channel_id="../../evil", question="Q", ctx=_ctx())
import type { Message } from "../../types/askTypes";Gates applied: instruction_override, no_behavioural_pass.
7655195ac754full audit observations/trust-audit/mcp-server/beever-ai__beever-atlas.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-30 | 7655195ac754 | BLOCK | F | 45 | first audit |
Questions
What is the Beever Atlas MCP server?
Your First LLM-Wiki Conversation Knowledge Base
What tools does Beever Atlas expose?
7 in total: 5 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Beever Atlas safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (45/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Beever Atlas need?
It reads BEEVER_ADMIN_TOKEN, BEEVER_API_KEY, BEEVER_API_KEYS, BOT_SESSION_SECRET, BRIDGE_ALLOW_UNAUTH, BRIDGE_API_KEY, CHANNEL_MEDIA_MINIO_ACCESS_KEY, CHANNEL_MEDIA_MINIO_SECRET_KEY, DISCORD_BOT_TOKEN, DISCORD_PUBLIC_KEY, EMBEDDING_API_KEY and GEMINI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Beever Atlas run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as web at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (7655195ac754), read on 2026-09-30. The repository is watched and re-audited when it changes.