VeraCAUTION
Local code search combining BM25, vector similarity, and cross-encoder reranking. Parses 60+ languages with tree-sitter, runs entirely offline, and returns structured results with file paths, line ranges, and symbol metadata. Built in Rust.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/VeraTools/Vera/blob/master/LICENSE) [](https://github.com/VeraTools/Vera/actions/workflows/ci.yml) [](https://www.npmjs.com/package/@vera-ai/cli) [](https://pypi.org/project/vera-ai/) [](https://github.com/VeraTools/Vera/releases) [](docs/supported-languages.md)
Docs · Install Guide · Features · Query Guide · Benchmarks · How It Works · Models · Supported Languages
Local, symbol-aware code search for developers and AI agents.
Hybrid BM25 + vector search with optional reranking, 65 languages, one static binary. Indexes stay on your machine; results come back as symbol-bounded chunks with file paths, line ranges, and scores.
Vector Enhanced Reranking Agent
Quick Start
1. Install
bunx @vera-ai/cli install # or: npx -y @vera-ai/cli install / uvx vera-ai install
2. Set up and index
Zero-setup local (CPU, no key, no GPU):
vera setup --potion-code --index .
Best measured search quality (one OpenRouter key, Qwen preset):
vera setup --api --index .
GPU and other backends
vera setup # Interactive wizard, i
a18484620bb1OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add cli --env EMBEDDING_MODEL_API_KEY=${EMBEDDING_MODEL_API_KEY} -- npx -y @vera-ai/[email protected]{
"mcpServers": {
"cli": {
"command": "npx",
"args": [
"-y",
"@vera-ai/[email protected]"
],
"env": {
"EMBEDDING_MODEL_API_KEY": "${EMBEDDING_MODEL_API_KEY}"
}
}
}
}Exposed tools (6)
6 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
.clinerules | read | Cline project rules |
.cursorrules | read | Cursor project rules |
.windsurfrules | read | Windsurf project rules |
AGENTS.md | read | shared agent instructions used by many tools |
CLAUDE.md | read | Claude Code project instructions |
COPILOT.md | read | GitHub Copilot coding agent instructions |
Trust audit
CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (24)
"http://127.0.0.1:19999".to_string(), // No server here.
let base_url = format!("http://127.0.0.1:{}", port);let base_url = format!("http://127.0.0.1:{port}");let base_url = format!("http://127.0.0.1:{port}");let base_url = format!("http://127.0.0.1:{port}");tree-sitter.wasm
.coderabbit.yaml
.envrc
.pre-commit-config.yaml
.prettierignore
.prettierrc.json
"answer": "## 1. `from_object` and `from_pyfile`\n\n**`from_object(obj)`** (`src/flask/config.py:218-254`)\n\n- Import-string handling: if `obj` is a `str` it is replaced by `import_string(obj)` (`con
module.exports = require("../../build/Release/tree_sitter_proto_binding");module.exports = require("../../build/Debug/tree_sitter_proto_binding");module.exports.nodeTypeInfo = require("../../src/node-types.json");pub const NODE_TYPES: &'static str = include_str!("../../src/node-types.json");module.exports = require("../../build/Release/tree_sitter_sql_binding");nan, tree-sitter-cli
nan, prettier, tree-sitter-cli
`vera serve` starts a local HTTP inference server exposing OpenAI-compatible embeddings (`POST /v1/embeddings`), Cohere/Jina-compatible reranking (`POST /v1/rerank`), and a health endpoint, with beare
benchmarks/results/semble/2026-08-16-vera-cuda-v1-full.json
crates/tree-sitter-sql/src/parser.c
How does Flask decide whether to load .env files? Cite path:line.
Which functions read environment variables, and where?
Gates applied: no_behavioural_pass.
a18484620bb1full audit observations/trust-audit/mcp-server/lemon07r__vera.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | a18484620bb1 | CAUTION | B | 83 | first audit |
Questions
What is the Vera MCP server?
Local code search combining BM25, vector similarity, and cross-encoder reranking. Parses 60+ languages with tree-sitter, runs entirely offline, and returns structured results with file paths, line ranges, and symbol metadata. Built in Rust.
What tools does Vera expose?
6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Vera safe to connect to an agent?
With care. The audit graded it B (83/100) and found 24 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Vera need?
It reads EMBEDDING_MODEL_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (a18484620bb1), read on 2026-10-07. The repository is watched and re-audited when it changes.