RagRabbitBLOCK
Open Source, Self-Hosted, AI Search and LLM.txt for your website
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
RagRabbit <a href="https://vercel.com/new/clone?repository-url=https%3A%2F%2Fgithub.com%2Fmadarco%2Fragrabbit&env=OPENAIAPIKEY,AUTHUSERNAME,AUTHPASSWORD,AUTHSECRET&envDescription=Get%20an%20OpenAI%20Api%20Key%20and%20set%20AUTHUSERNAME%20and%20AUTH_PASSWORD%20to%20the%20desired%20credentials%20to%20secure%20the%20admin%20section.%20Also%20be%20sure%20to%20enable%20the%20Postgres%20database%20integration&envLink=https%3A%2F%2Fplatform.openai.com%2Fapi-keys&demo-title=RagRabbit%20-%20AI%20Site%20Search%20and%20LLM.txt&demo-description=Site%20AI%20Search%20and%20LLM.txt%20in%20Minutes%2C%20Open%20Source%20with%201%20Click%20Deploy%20on%20Vercel.&demo-url=https%3A%2F%2Fragrabbit.vercel.app%2F&demo-image=https%3A%2F%2Fragrabbit.vercel.app%2Fopengraph-image.png&stores=%5B%7B%22type%22%3A%22postgres%22%7D%5D&root-directory=apps/saas">
Self Hosted Site AI Search, LLMs.txt, MCP Server that crawls your content. 1-Click Deploy on Vercel.
[](https://vercel.com/new/clone?repository-url=https%3A%2F%2Fgithub.com%2Fmadarco%2Fragrabbit&env=OPENAIAPIKEY,AUTHUSERNAME,AUTHPASSWORD,AUTHSECRET&envDescription=Get%20an%20OpenAI%20Api%20Key%20and%20set%20AUTHUSERNAME%20and%20AUTH_PASSWORD%20to%20the%20desired%20credentials%20to%20secure%20the%20admin%20section.%2
bda0798518d5OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add typescript-config --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AUTH_USERNAME=${AUTH_USERNAME} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env RESEND_AUTH=${RESEND_AUTH} -- npx -y @repo/[email protected]{
"mcpServers": {
"typescript-config": {
"command": "npx",
"args": [
"-y",
"@repo/[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"AUTH_USERNAME": "${AUTH_USERNAME}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}",
"RESEND_AUTH": "${RESEND_AUTH}"
}
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
rag_tool | read | This tool can answer detailed questions. |
search_docs | read | Retrieve relevant documents about ${name} based on a query |
Trust audit
BLOCKgrade D · trust 63/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (20)
POSTGRES_URL="postgresql://johndoe:randompassword@localhost:5432/mydb?schema=public"
#POSTGRES_URL="postgres://default:[email protected]/verceldb?sslmode=require"
#POSTGRES_URL_NON_POOLING="postgres://default:[email protected]/verceldb?sslmode=require"
.prettierignore
.syncpackrc
.eslintrc.js
return crypto.createHash("md5").update(content).digest("hex");"../../../packages/design/(base|components|hooks|shadcn|lib)/**/*.stories.@(js|jsx|mjs|ts|tsx)",
import { validateApiRequest } from "../../utils";import { validateApiRequest } from "../../utils";import { getLlmsConfig, getPageTree, TreePage } from "../../utils";import { getWidgetConfig } from "../../dashboard/widget/actions";@ai-sdk/openai, @dnd-kit/core, @dnd-kit/sortable, @dnd-kit/utilities, @hookform/resolvers, @next-safe-action/adapter-react-hook-form, @radix-ui/react-dropdown-menu, @radix-ui/react-icons
@hookform/resolvers, @next-safe-action/adapter-react-hook-form, @radix-ui/react-dropdown-menu, @radix-ui/react-icons, @t3-oss/env-nextjs, next-safe-action, pino, pino-pretty
rimraf, prettier, syncpack, turbo, typescript
@hookform/resolvers, @next-safe-action/adapter-react-hook-form, next-safe-action, zod, @vercel/node, react-hook-form
@auth/drizzle-adapter, @t3-oss/env-nextjs, zod
apps/docs/public/ragrabbit.gif
apps/docs/public/ragrabbit_small.gif
- 🛠️ Flexible: Authentication, Open Source, API Keys access
Gates applied: no_behavioural_pass.
bda0798518d5full audit observations/trust-audit/mcp-server/madarco__ragrabbit.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | bda0798518d5 | BLOCK | D | 63 | first audit |
Questions
What is the RagRabbit MCP server?
Open Source, Self-Hosted, AI Search and LLM.txt for your website
What tools does RagRabbit expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is RagRabbit safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (63/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does RagRabbit need?
It reads ANTHROPIC_API_KEY, AUTH_USERNAME, OPENAI_API_KEY and RESEND_AUTH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does RagRabbit run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @repo/typescript-config at 0.0.1.
How current is this page?
The grade is for one exact copy of the source (bda0798518d5), read on 2026-10-07. The repository is watched and re-audited when it changes.