Atlas / MCP servers / lemon07r / Vera

VeraCAUTION

mcp/lemon07r/vera

Local code search combining BM25, vector similarity, and cross-encoder reranking. Parses 60+ languages with tree-sitter, runs entirely offline, and returns structured results with file paths, line ranges, and symbol metadata. Built in Rust.

Verdict
CAUTION
Grade
B
Trust score
83 /100
Exposed tools
6 6r · 0w · 0d
Transport
—
License
MIT
Stars
118
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/VeraTools/Vera/blob/master/LICENSE) [](https://github.com/VeraTools/Vera/actions/workflows/ci.yml) [](https://www.npmjs.com/package/@vera-ai/cli) [](https://pypi.org/project/vera-ai/) [](https://github.com/VeraTools/Vera/releases) [](docs/supported-languages.md)

Docs · Install Guide · Features · Query Guide · Benchmarks · How It Works · Models · Supported Languages

Local, symbol-aware code search for developers and AI agents.

Hybrid BM25 + vector search with optional reranking, 65 languages, one static binary. Indexes stay on your machine; results come back as symbol-bounded chunks with file paths, line ranges, and scores.

Vector Enhanced Reranking Agent

Quick Start

1. Install

bunx @vera-ai/cli install   # or: npx -y @vera-ai/cli install / uvx vera-ai install

2. Set up and index

Zero-setup local (CPU, no key, no GPU):

vera setup --potion-code --index .

Best measured search quality (one OpenRouter key, Qwen preset):

vera setup --api --index .

GPU and other backends

vera setup                                  # Interactive wizard, i
Read from source at commit a18484620bb1OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add cli --env EMBEDDING_MODEL_API_KEY=${EMBEDDING_MODEL_API_KEY} -- npx -y @vera-ai/[email protected]
claude-desktop
{
  "mcpServers": {
    "cli": {
      "command": "npx",
      "args": [
        "-y",
        "@vera-ai/[email protected]"
      ],
      "env": {
        "EMBEDDING_MODEL_API_KEY": "${EMBEDDING_MODEL_API_KEY}"
      }
    }
  }
}
03

Exposed tools (6)

6 read · 0 write · 0 destructive.

ToolRiskDescription
.clinerulesreadCline project rules
.cursorrulesreadCursor project rules
.windsurfrulesreadWindsurf project rules
AGENTS.mdreadshared agent instructions used by many tools
CLAUDE.mdreadClaude Code project instructions
COPILOT.mdreadGitHub Copilot coding agent instructions
04

Trust audit

CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (9 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (24)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/vera-core/src/embedding/tests.rs:654
"http://127.0.0.1:19999".to_string(), // No server here.
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/vera-core/src/local_models/tests.rs:541
let base_url = format!("http://127.0.0.1:{}", port);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/vera-core/src/local_models/tests.rs:592
let base_url = format!("http://127.0.0.1:{port}");
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/vera-core/src/local_models/tests.rs:632
let base_url = format!("http://127.0.0.1:{port}");
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
crates/vera-core/src/local_models/tests.rs:679
let base_url = format!("http://127.0.0.1:{port}");
LOWInventory / provenance · inv.binary · CWE-1104
crates/tree-sitter-sql/docs/vendor/tree-sitter.wasm
tree-sitter.wasm
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coderabbit.yaml
.coderabbit.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
crates/tree-sitter-proto/.envrc
.envrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
crates/tree-sitter-sql/.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
crates/tree-sitter-sql/.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
crates/tree-sitter-sql/.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
benchmarks/agent-bench/results/results.claude-opus-5-medium.json:127
"answer": "## 1. `from_object` and `from_pyfile`\n\n**`from_object(obj)`** (`src/flask/config.py:218-254`)\n\n- Import-string handling: if `obj` is a `str` it is replaced by `import_string(obj)` (`con
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/tree-sitter-proto/bindings/node/index.js:2
module.exports = require("../../build/Release/tree_sitter_proto_binding");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/tree-sitter-proto/bindings/node/index.js:8
module.exports = require("../../build/Debug/tree_sitter_proto_binding");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/tree-sitter-proto/bindings/node/index.js:18
module.exports.nodeTypeInfo = require("../../src/node-types.json");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/tree-sitter-proto/bindings/rust/lib.rs:34
pub const NODE_TYPES: &'static str = include_str!("../../src/node-types.json");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
crates/tree-sitter-sql/bindings/node/index.js:2
module.exports = require("../../build/Release/tree_sitter_sql_binding");
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
crates/tree-sitter-proto/package.json
nan, tree-sitter-cli
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
crates/tree-sitter-sql/package.json
nan, prettier, tree-sitter-cli
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/whats-new.md:236
`vera serve` starts a local HTTP inference server exposing OpenAI-compatible embeddings (`POST /v1/embeddings`), Cohere/Jina-compatible reranking (`POST /v1/rerank`), and a health endpoint, with beare
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
benchmarks/results/semble/2026-08-16-vera-cuda-v1-full.json
benchmarks/results/semble/2026-08-16-vera-cuda-v1-full.json
Why it matters. 2576595 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
crates/tree-sitter-sql/src/parser.c
crates/tree-sitter-sql/src/parser.c
Why it matters. 35756347 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
benchmarks/skill-eval/scenarios.md:26
How does Flask decide whether to load .env files? Cite path:line.
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
benchmarks/skill-eval/scenarios.md:44
Which functions read environment variables, and where?
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha a18484620bb1full audit observations/trust-audit/mcp-server/lemon07r__vera.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07a18484620bb1CAUTIONB83first audit
06

Questions

What is the Vera MCP server?

Local code search combining BM25, vector similarity, and cross-encoder reranking. Parses 60+ languages with tree-sitter, runs entirely offline, and returns structured results with file paths, line ranges, and symbol metadata. Built in Rust.

What tools does Vera expose?

6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Vera safe to connect to an agent?

With care. The audit graded it B (83/100) and found 24 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Vera need?

It reads EMBEDDING_MODEL_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (a18484620bb1), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement