QdrantCAUTION
MCP server for semantic search using local Qdrant vector database and OpenAI embeddings
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/mhalder/qdrant-mcp-server/actions/workflows/ci.yml) [](https://codecov.io/gh/mhalder/qdrant-mcp-server)
A Model Context Protocol (MCP) server providing semantic search capabilities using Qdrant vector database with multiple embedding providers.
Features
- Zero Setup: Works out of the box with Ollama - no API keys required
- Privacy-First: Local embeddings and vector storage - data never leaves your machine
- Code Vectorization: Intelligent codebase indexing with AST-aware chunking and semantic code search
- Git History Search: Index commit history for semantic search over past changes, fixes, and patterns
- Advanced Search: Contextual search (code + git with correlations) and federated search across multiple repositories
- Multiple Providers: Ollama (default), OpenAI, Cohere, and Voyage AI
- Hybrid Search: Combine semantic and keyword search for better results
- Semantic Search: Natural language search with metadata filtering
- Incremental Indexing: Efficient updates - only re-index changed files
- Configurable Prompts: Create custom prompts for guided workflows without code changes
- Rate Limiting: Intelligent throttling with exponential backoff
- Full CRUD: Create, search, and manage collections and documents
- Structured Logging: JSON logging via Pino with configurable log levels
- Flexible Deployment: Run locally (stdio) or as a remote HTTP server
- API Key Authentication: Connect to secured Qdrant instances (Qdrant Cloud, self-hosted with API keys)
Quick Start
Prerequisites
- Node.js 22.x or 24.x
- Podman or Docker with Compose support
Installation
# Clone and install git clone https://github.com/mhalder/qdrant-mcp-server.git cd qdrant-mcp-server # Node 22.x n
63a2921e1d9eOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add qdrant-mcp-server --env API_KEY=${API_KEY} --env COHERE_API_KEY=${COHERE_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env QDRANT_API_KEY=${QDRANT_API_KEY} -- npx -y @mhalder/[email protected]{
"mcpServers": {
"qdrant-mcp-server": {
"command": "npx",
"args": [
"-y",
"@mhalder/[email protected]"
],
"env": {
"API_KEY": "${API_KEY}",
"COHERE_API_KEY": "${COHERE_API_KEY}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}",
"QDRANT_API_KEY": "${QDRANT_API_KEY}"
}
}
}
}Exposed tools (35)
29 read · 2 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Invalid-Name | read | Test |
add_documents | write | |
another_prompt | read | Another prompt |
another_valid | read | Test |
arg1 | read | First argument |
clear_git_index | destructive | |
clear_index | destructive | |
collection | read | Collection name |
contextual_search | read | |
create_collection | write | |
delete_collection | destructive | |
delete_documents | destructive | |
federated_search | read | |
filter | read | Filter |
get_collection_info | read | |
get_git_index_status | read | |
get_index_status | read | |
hybrid_search | read | |
index_codebase | read | |
index_git_history | read | |
index_new_commits | read | |
limit | read | Number of results |
list_collections | read | |
name | read | Name |
optional_arg | read | Optional argument |
prompt1 | read | First prompt |
prompt2 | read | Second prompt |
query | read | Search query |
reindex_changes | read | |
required_arg | read | Required argument |
search_code | read | |
search_git_history | read | |
semantic_search | read | |
test_prompt | read | A test prompt |
valid_name_123 | read | Test |
Trust audit
CAUTIONgrade D · trust 62/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (22)
'const apiKey = "sk_test_FAKE_KEY_FOR_TESTING_ONLY_NOT_REAL";'
'export const apiKey = "sk_test_FAKE_KEY_FOR_TESTING_NOT_REAL_KEY";\nconsole.log("Secrets file");'const code = 'const apiKey = "sk_live_1234567890abcdefghij";';
const code = 'const token = "ghp_1234567890abcdefghijklmnopqrstuvwxyz";';
const code = 'const API_KEY = "sk_live_1234567890abcdefghij";';
const code = 'const token = "ghp_1234567890abcdefghijklmnopqrstuvwxyz";';
const code = "-----BEGIN PRIVATE KEY-----\nMIIEvgIBADANBg";
const code = 'const apiKey = "sk_live_1234567890abcdefghij";';
const code = 'const API_KEY = "sk_live_1234567890abcdefghij";';
clear_git_index, clear_index, delete_collection, delete_documents
.codecov.yml
.releaserc.json
.yamlfmt
const hash = createHash("md5").update(normalized).digest("hex");const hash = createHash("md5").update(absolutePath).digest("hex");const hash = createHash("md5").update(identifier).digest("hex");import logger from "../../logger.js";
import { CharacterChunker } from "../../../src/code/chunker/character-chunker.js";import type { ChunkerConfig } from "../../../src/code/types.js";import { TreeSitterChunker } from "../../../src/code/chunker/tree-sitter-chunker.js";import type { ChunkerConfig } from "../../../src/code/types.js";@modelcontextprotocol/sdk, @qdrant/js-client-rest, bottleneck, cohere-ai, express, ignore, openai, picomatch
Gates applied: no_behavioural_pass.
63a2921e1d9efull audit observations/trust-audit/mcp-server/mhalder__qdrant-6.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 63a2921e1d9e | CAUTION | D | 62 | first audit |
Questions
What is the Qdrant MCP server?
MCP server for semantic search using local Qdrant vector database and OpenAI embeddings
What tools does Qdrant expose?
35 in total: 29 read-only, 2 that write, and 4 that can delete or overwrite (clear_git_index, clear_index, delete_collection, delete_documents). Every one is listed on this page with its risk.
Is Qdrant safe to connect to an agent?
With care. The audit graded it D (62/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Qdrant need?
It reads API_KEY, COHERE_API_KEY, OPENAI_API_KEY, QDRANT_API_KEY and VOYAGE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Qdrant run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @mhalder/qdrant-mcp-server at 3.3.5.
How current is this page?
The grade is for one exact copy of the source (63a2921e1d9e), read on 2026-10-08. The repository is watched and re-audited when it changes.