Atlas / MCP servers / mhalder / Qdrant

QdrantCAUTION

mcp/mhalder/qdrant-6

MCP server for semantic search using local Qdrant vector database and OpenAI embeddings

Verdict
CAUTION
Grade
D
Trust score
62 /100
Exposed tools
35 29r · 2w · 4d
Transport
stdio · streamable-http
License
MIT
Stars
36
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/mhalder/qdrant-mcp-server/actions/workflows/ci.yml) [](https://codecov.io/gh/mhalder/qdrant-mcp-server)

A Model Context Protocol (MCP) server providing semantic search capabilities using Qdrant vector database with multiple embedding providers.

Features

  • Zero Setup: Works out of the box with Ollama - no API keys required
  • Privacy-First: Local embeddings and vector storage - data never leaves your machine
  • Code Vectorization: Intelligent codebase indexing with AST-aware chunking and semantic code search
  • Git History Search: Index commit history for semantic search over past changes, fixes, and patterns
  • Advanced Search: Contextual search (code + git with correlations) and federated search across multiple repositories
  • Multiple Providers: Ollama (default), OpenAI, Cohere, and Voyage AI
  • Hybrid Search: Combine semantic and keyword search for better results
  • Semantic Search: Natural language search with metadata filtering
  • Incremental Indexing: Efficient updates - only re-index changed files
  • Configurable Prompts: Create custom prompts for guided workflows without code changes
  • Rate Limiting: Intelligent throttling with exponential backoff
  • Full CRUD: Create, search, and manage collections and documents
  • Structured Logging: JSON logging via Pino with configurable log levels
  • Flexible Deployment: Run locally (stdio) or as a remote HTTP server
  • API Key Authentication: Connect to secured Qdrant instances (Qdrant Cloud, self-hosted with API keys)

Quick Start

Prerequisites

  • Node.js 22.x or 24.x
  • Podman or Docker with Compose support

Installation

# Clone and install
git clone https://github.com/mhalder/qdrant-mcp-server.git
cd qdrant-mcp-server

# Node 22.x
n
Read from source at commit 63a2921e1d9eOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add qdrant-mcp-server --env API_KEY=${API_KEY} --env COHERE_API_KEY=${COHERE_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env QDRANT_API_KEY=${QDRANT_API_KEY} -- npx -y @mhalder/[email protected]
claude-desktop
{
  "mcpServers": {
    "qdrant-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@mhalder/[email protected]"
      ],
      "env": {
        "API_KEY": "${API_KEY}",
        "COHERE_API_KEY": "${COHERE_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}",
        "QDRANT_API_KEY": "${QDRANT_API_KEY}"
      }
    }
  }
}
03

Exposed tools (35)

29 read · 2 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
Invalid-NamereadTest
add_documentswrite
another_promptreadAnother prompt
another_validreadTest
arg1readFirst argument
clear_git_indexdestructive
clear_indexdestructive
collectionreadCollection name
contextual_searchread
create_collectionwrite
delete_collectiondestructive
delete_documentsdestructive
federated_searchread
filterreadFilter
get_collection_inforead
get_git_index_statusread
get_index_statusread
hybrid_searchread
index_codebaseread
index_git_historyread
index_new_commitsread
limitreadNumber of results
list_collectionsread
namereadName
optional_argreadOptional argument
prompt1readFirst prompt
prompt2readSecond prompt
queryreadSearch query
reindex_changesread
required_argreadRequired argument
search_coderead
search_git_historyread
semantic_searchread
test_promptreadA test prompt
valid_name_123readTest
04

Trust audit

CAUTIONgrade D · trust 62/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (22)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/code/indexer.test.ts:283
'const apiKey = "sk_test_FAKE_KEY_FOR_TESTING_ONLY_NOT_REAL";'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/code/integration.test.ts:573
'export const apiKey = "sk_test_FAKE_KEY_FOR_TESTING_NOT_REAL_KEY";\nconsole.log("Secrets file");'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/code/metadata.test.ts:153
const code = 'const apiKey = "sk_live_1234567890abcdefghij";';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/code/metadata.test.ts:173
const code = 'const token = "ghp_1234567890abcdefghijklmnopqrstuvwxyz";';
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/code/metadata.test.ts:192
const code = 'const API_KEY = "sk_live_1234567890abcdefghij";';
MEDIUMHard-coded secrets · secret.github · CWE-798, CWE-321
tests/code/metadata.test.ts:173
const code = 'const token = "ghp_1234567890abcdefghijklmnopqrstuvwxyz";';
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/code/metadata.test.ts:168
const code = "-----BEGIN PRIVATE KEY-----\nMIIEvgIBADANBg";
MEDIUMHard-coded secrets · secret.stripe · CWE-798, CWE-321
tests/code/metadata.test.ts:153
const code = 'const apiKey = "sk_live_1234567890abcdefghij";';
MEDIUMHard-coded secrets · secret.stripe · CWE-798, CWE-321
tests/code/metadata.test.ts:192
const code = 'const API_KEY = "sk_live_1234567890abcdefghij";';
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_git_index, clear_index, delete_collection, delete_documents
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.codecov.yml
.codecov.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.releaserc.json
.releaserc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.yamlfmt
.yamlfmt
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/code/indexer.ts:784
const hash = createHash("md5").update(normalized).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/code/indexer.ts:793
const hash = createHash("md5").update(absolutePath).digest("hex");
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/git/indexer.ts:720
const hash = createHash("md5").update(identifier).digest("hex");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/code/chunker/tree-sitter-chunker.ts:16
import logger from "../../logger.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/code/chunker/character-chunker.test.ts:2
import { CharacterChunker } from "../../../src/code/chunker/character-chunker.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/code/chunker/character-chunker.test.ts:3
import type { ChunkerConfig } from "../../../src/code/types.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/code/chunker/tree-sitter-chunker.test.ts:2
import { TreeSitterChunker } from "../../../src/code/chunker/tree-sitter-chunker.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/code/chunker/tree-sitter-chunker.test.ts:3
import type { ChunkerConfig } from "../../../src/code/types.js";
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @qdrant/js-client-rest, bottleneck, cohere-ai, express, ignore, openai, picomatch
Why it matters. 34 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 63a2921e1d9efull audit observations/trust-audit/mcp-server/mhalder__qdrant-6.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0863a2921e1d9eCAUTIOND62first audit
06

Questions

What is the Qdrant MCP server?

MCP server for semantic search using local Qdrant vector database and OpenAI embeddings

What tools does Qdrant expose?

35 in total: 29 read-only, 2 that write, and 4 that can delete or overwrite (clear_git_index, clear_index, delete_collection, delete_documents). Every one is listed on this page with its risk.

Is Qdrant safe to connect to an agent?

With care. The audit graded it D (62/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Qdrant need?

It reads API_KEY, COHERE_API_KEY, OPENAI_API_KEY, QDRANT_API_KEY and VOYAGE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Qdrant run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @mhalder/qdrant-mcp-server at 3.3.5.

How current is this page?

The grade is for one exact copy of the source (63a2921e1d9e), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement