Atlas / MCP servers / madarco / RagRabbit

RagRabbitBLOCK

mcp/madarco/ragrabbit

Open Source, Self-Hosted, AI Search and LLM.txt for your website

Verdict
BLOCK
Grade
D
Trust score
63 /100
Exposed tools
2 2r · 0w · 0d
Transport
stdio
License
MIT
Stars
136
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

RagRabbit <a href="https://vercel.com/new/clone?repository-url=https%3A%2F%2Fgithub.com%2Fmadarco%2Fragrabbit&env=OPENAIAPIKEY,AUTHUSERNAME,AUTHPASSWORD,AUTHSECRET&envDescription=Get%20an%20OpenAI%20Api%20Key%20and%20set%20AUTHUSERNAME%20and%20AUTH_PASSWORD%20to%20the%20desired%20credentials%20to%20secure%20the%20admin%20section.%20Also%20be%20sure%20to%20enable%20the%20Postgres%20database%20integration&envLink=https%3A%2F%2Fplatform.openai.com%2Fapi-keys&demo-title=RagRabbit%20-%20AI%20Site%20Search%20and%20LLM.txt&demo-description=Site%20AI%20Search%20and%20LLM.txt%20in%20Minutes%2C%20Open%20Source%20with%201%20Click%20Deploy%20on%20Vercel.&demo-url=https%3A%2F%2Fragrabbit.vercel.app%2F&demo-image=https%3A%2F%2Fragrabbit.vercel.app%2Fopengraph-image.png&stores=%5B%7B%22type%22%3A%22postgres%22%7D%5D&root-directory=apps/saas">

Self Hosted Site AI Search, LLMs.txt, MCP Server that crawls your content. 1-Click Deploy on Vercel.

[](https://vercel.com/new/clone?repository-url=https%3A%2F%2Fgithub.com%2Fmadarco%2Fragrabbit&env=OPENAIAPIKEY,AUTHUSERNAME,AUTHPASSWORD,AUTHSECRET&envDescription=Get%20an%20OpenAI%20Api%20Key%20and%20set%20AUTHUSERNAME%20and%20AUTH_PASSWORD%20to%20the%20desired%20credentials%20to%20secure%20the%20admin%20section.%2

Read from source at commit bda0798518d5OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add typescript-config --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AUTH_USERNAME=${AUTH_USERNAME} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env RESEND_AUTH=${RESEND_AUTH} -- npx -y @repo/[email protected]
claude-desktop
{
  "mcpServers": {
    "typescript-config": {
      "command": "npx",
      "args": [
        "-y",
        "@repo/[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "AUTH_USERNAME": "${AUTH_USERNAME}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "RESEND_AUTH": "${RESEND_AUTH}"
      }
    }
  }
}
03

Exposed tools (2)

2 read · 0 write · 0 destructive.

ToolRiskDescription
rag_toolreadThis tool can answer detailed questions.
search_docsreadRetrieve relevant documents about ${name} based on a query
04

Trust audit

BLOCKgrade D · trust 63/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (20)

HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
apps/saas/.env.example:1
POSTGRES_URL="postgresql://johndoe:randompassword@localhost:5432/mydb?schema=public"
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
apps/saas/.env.example:6
#POSTGRES_URL="postgres://default:[email protected]/verceldb?sslmode=require"
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
apps/saas/.env.example:7
#POSTGRES_URL_NON_POOLING="postgres://default:[email protected]/verceldb?sslmode=require"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.syncpackrc
.syncpackrc
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
packages/design/.eslintrc.js
.eslintrc.js
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
packages/rag/scraping/db.ts:189
return crypto.createHash("md5").update(content).digest("hex");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/saas/.storybook/main.ts:15
"../../../packages/design/(base|components|hooks|shadcn|lib)/**/*.stories.@(js|jsx|mjs|ts|tsx)",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/saas/app/(api)/api/content/route.ts:6
import { validateApiRequest } from "../../utils";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/saas/app/(api)/api/process/route.ts:6
import { validateApiRequest } from "../../utils";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/saas/app/(llms.txt)/dashboard/llms/actions.ts:10
import { getLlmsConfig, getPageTree, TreePage } from "../../utils";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
apps/saas/app/(rag)/chat/ui/chat.tsx:3
import { getWidgetConfig } from "../../dashboard/widget/actions";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/saas/package.json
@ai-sdk/openai, @dnd-kit/core, @dnd-kit/sortable, @dnd-kit/utilities, @hookform/resolvers, @next-safe-action/adapter-react-hook-form, @radix-ui/react-dropdown-menu, @radix-ui/react-icons
Why it matters. 32 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
apps/web/package.json
@hookform/resolvers, @next-safe-action/adapter-react-hook-form, @radix-ui/react-dropdown-menu, @radix-ui/react-icons, @t3-oss/env-nextjs, next-safe-action, pino, pino-pretty
Why it matters. 21 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
rimraf, prettier, syncpack, turbo, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/actions/package.json
@hookform/resolvers, @next-safe-action/adapter-react-hook-form, next-safe-action, zod, @vercel/node, react-hook-form
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/auth/package.json
@auth/drizzle-adapter, @t3-oss/env-nextjs, zod
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
apps/docs/public/ragrabbit.gif
apps/docs/public/ragrabbit.gif
Why it matters. 2876858 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
apps/docs/public/ragrabbit_small.gif
apps/docs/public/ragrabbit_small.gif
Why it matters. 1837548 bytes not read
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:32
- 🛠️ Flexible: Authentication, Open Source, API Keys access
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha bda0798518d5full audit observations/trust-audit/mcp-server/madarco__ragrabbit.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07bda0798518d5BLOCKD63first audit
06

Questions

What is the RagRabbit MCP server?

Open Source, Self-Hosted, AI Search and LLM.txt for your website

What tools does RagRabbit expose?

2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is RagRabbit safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (63/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does RagRabbit need?

It reads ANTHROPIC_API_KEY, AUTH_USERNAME, OPENAI_API_KEY and RESEND_AUTH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does RagRabbit run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @repo/typescript-config at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (bda0798518d5), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement