Atlas / MCP servers / imnmv / ClaudeR

ClaudeRBLOCK

mcp/imnmv/clauder

Connect RStudio to Claude Code, Codex, Gemini, and other LLM agents via MCP. Multi-agent orchestration, automated manuscript auditing, and zero-config setup with uvx

Verdict
BLOCK
Grade
D
Trust score
62 /100
Exposed tools
16 12r · 4w · 0d
Transport
stdio
License
NOASSERTION
Stars
347
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

ClaudeR - The Modern Researcher's Toolkit

Connect a live R or Python session, in RStudio or Positron, to Claude Code, Codex, or any MCP-based LLM agent. For interactive analysis, multi-agent orchestration, and automated manuscript auditing.

ClaudeR connects MCP-configured LLM agents, like Claude Code or Codex, to the R session you are already working in. The agent runs code where your cleaned data and fitted models actually are, sees the plots it draws, reads the objects in your environment, and can edit the file open in your editor. A companion Python package does the same for a li

Read from source at commit da2fa18eb721OBSERVED · 2026-10-03
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add clauder-mcp -- None clauder-mcp==0.16.1
03

Exposed tools (16)

12 read · 4 write · 0 destructive.

ToolRiskDescription
cancel_annotation_jobreadCancel a running annotation job. The current row finishes before stopping. Already-saved rows are kept and the job is resumable.
clean_error_logreadClean a ClaudeR session log by removing error blocks and their duplicates. Parses the log, finds errors, checks if a fix follows each error, removes the error blocks and any duplicate code blocks that preceded them. Returns a report of what was found and removed.
connect_sessionreadConnect to a specific RStudio session by name. Use list_sessions first to see available sessions. Subsequent tool calls will be routed to this session.
create_task_listwriteCreate a task list for the current analysis
execute_rwriteExecute R code and return the output
execute_r_with_plotwriteExecute R code that generates a plot
get_annotation_job_statusreadCheck the status of a running or completed annotation job started with run_annotation_job.
get_async_resultreadCheck the result of an async R job. Waits ~10 seconds before checking to avoid excessive polling. If the job is still running, call this again.
get_r_inforeadGet a summary of the R environment. Returns package count (not full list), first 20 variables, and R version. Use requireNamespace(
get_session_historyreadGet execution history for the current R session. Can filter by agent to see what a specific agent has done.
get_viewer_contentreadGet HTML content from the RStudio Viewer pane (HTML widgets like plotly, DT, leaflet). Returns paginated chunks. Call with offset to get more.
list_checkpointsreadList saved R session checkpoints (file, time, size MB) for the current session, newest last.
list_sessionsreadList available RStudio sessions that this agent can connect to. Shows session name, port, and PID for each active session.
read_filereadRead the contents of a file from disk. Handles plain text (R scripts, logs, CSVs) and manuscripts: .docx and .pdf are transparently extracted as structured text with headings prefixed by #s and table cells emitted row-wise as
search_project_codereadSearch for a regex pattern across project source files (.R, .Rmd, .qmd). Returns matching file, line number, and code snippet. Uses base R grep — safe to use even with system() blocked.
update_task_statuswriteUpdate the status of a task and optionally add notes
04

Trust audit

BLOCKgrade D · trust 62/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (11 observation(s))
Shell
declared (3 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (14)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
R/ui.R:351
.clauder_result <- withVisible(eval(parse(text = code), envir = work_env))
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
R/ui.R:1513
withVisible(eval(parse(text = code), envir = env)),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
clauder-py/src/clauder/server.py:210
exec(compile(code, "<clauder>", "exec"), STATE.namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
R/ui.R:962
sprintf("Running on http://127.0.0.1:%d", input$port)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
R/ui.R.bak_plotfix:883
sprintf("Running on http://127.0.0.1:%d", input$port)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
clauder-mcp/src/clauder_mcp/server.py:177
return f"http://127.0.0.1:{pick['port']}"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
clauder-py/src/clauder/server.py:383
print("clauder: listening on http://127.0.0.1:%d as session '%s'%s.\n"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.Rbuildignore
.Rbuildignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/discovery-reliability.R:9
is.symbol(expr[[2]]) && as.character(expr[[2]]) %in% funcs) eval(expr, env)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
clauder-py/tests/test_clauder.py:52
r = urllib.request.Request("http://127.0.0.1:%d" % PORT,
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
clauder-py/tests/test_clauder.py:186
self.assertTrue(base64.b64decode(r["plot"]["data"]).startswith(b"\x89PNG"))
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:436
No filter fixes this, because running code is the feature. Mitigate by treating agent sessions over third-party documents as you would running a stranger's script: do it in a project directory, keep l
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:574
- **MCP Server Failed to Start**: If using `uvx`, ensure `uv` is installed (`curl -LsSf https://astral.sh/uv/install.sh | sh`). If using the legacy method, this usually means the wrong Python environm
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:87
- **Deep-dive audit release (R 0.3.1 / clauder-mcp 0.6.2).** 20+ bug fixes across the addin, bridge, and Lab Mode: reopened addin UIs now share live state with the running server (settings toggles wor
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-03 · audit v0.4.1 · source sha da2fa18eb721full audit observations/trust-audit/mcp-server/imnmv__clauder.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-03da2fa18eb721BLOCKD62first audit
06

Questions

What is the ClaudeR MCP server?

Connect RStudio to Claude Code, Codex, Gemini, and other LLM agents via MCP. Multi-agent orchestration, automated manuscript auditing, and zero-config setup with uvx

What tools does ClaudeR expose?

16 in total: 12 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is ClaudeR safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (62/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does ClaudeR need?

No credential environment variables were found in its source, so it appears to need none.

How does ClaudeR run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as clauder.

How current is this page?

The grade is for one exact copy of the source (da2fa18eb721), read on 2026-10-03. The repository is watched and re-audited when it changes.

Advertisement