Atlas / MCP servers / mnemox-ai / Idea Reality

Idea RealitySAFE

mcp/mnemox-ai/idea-reality

Pre-build reality check for AI coding agents. Scans GitHub, HN, npm, PyPI, Product Hunt. MCP server. 290+ stars.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
822
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 繁體中文

How to check if someone already built your app idea — automatically.

idea-reality-mcp is an MCP server that scans GitHub, npm, PyPI, Hacker News, and Stack Overflow to check if your startup idea already exists. It returns a 0–100 reality score with evidence, trend detection, and pivot suggestions — so your AI agent can decide whether to build, pivot, or kill the idea before writing any code.

When to use this: You're about to start a new project and want to know if similar tools already exist, how competitive the space is, and whether the market is growing or declining.

Project status (August 2026): Maintenance mode. The tool works, stays free & open source, and the hosted API remains up; bug reports are reviewed, but no new features are planned.
Not just checking — building it? After a reality check, open your idea as a public project on [AngelRun](https://angelrun.vercel.app/new?utm_source=idea-reality&utm_medium=readme&utm_campaign=demand-cta) — ship updates, climb the season, and get seen by angels.

[](https://pypi.org/project/idea-reality-mcp/) [](https://smithery.ai/server/idea-reality-mcp) [](https://opensource.org/licenses/MIT) [](https://github.com/mnemox-ai/idea-reality-mcp/actions/workflows/ci.yml) [](https://github.com/mnemox-ai/idea-reality-mcp) [](https://pepy.tech/project/idea-reality-mcp)

Read from source at commit 56a4754edf0dOBSERVED · 2026-09-27
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add idea-reality-mcp --env GITHUB_TOKEN=${GITHUB_TOKEN} -- None idea-reality-mcp==0.5.0
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
idea_checkreadCheck if a product idea already exists before building it.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
api/main.py:176
"http://127.0.0.1:5500",  # VS Code Live Server
LOWNetwork egress · net.env_exfil · CWE-200, CWE-319
tests/test_pypi.py:92
os.environ.items() ... httpx.
Why it matters. reads secrets in the same file that sends data out
LOWNetwork egress · net.env_exfil · CWE-200, CWE-319
tests/test_stackoverflow.py:156
os.environ.items() ... httpx.
Why it matters. reads secrets in the same file that sends data out
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
scripts/turso_http.py:45
return base64.b64decode(cell["base64"])
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
api/requirements.txt
fastapi, uvicorn, anthropic, libsql-client, httpx, numpy
Why it matters. 6 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/2026-07-06-demand-sensing-accelerator-master-plan.md:68
- 🔴 **Turso ANN 向量索引=放棄(這台建不了)**。crowd 真實延遲**其實才 ~6s 不是 26s**(26s 是我當時猛打 DB 的競爭假象),所以**沒那麼急**。而且 ANN 索引在此環境建不起來:Turso HTTP `/v2/pipeline` **有 ~60s 硬上限**、10k×1536 bulk build 超時斷線;libsql sync client 在 W
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-09-27 · audit v0.4.1 · source sha 56a4754edf0dfull audit observations/trust-audit/mcp-server/mnemox-ai__idea-reality.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2756a4754edf0dSAFEB89first audit
06

Questions

What is the Idea Reality MCP server?

Pre-build reality check for AI coding agents. Scans GitHub, HN, npm, PyPI, Product Hunt. MCP server. 290+ stars.

What tools does Idea Reality expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Idea Reality safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Idea Reality need?

It reads ANTHROPIC_API_KEY, EXPORT_KEY, GITHUB_TOKEN, LIBRARIES_IO_KEY, OPENAI_API_KEY, PRODUCTHUNT_TOKEN, STACKEXCHANGE_KEY and TURSO_AUTH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Idea Reality run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as idea-reality-mcp.

How current is this page?

The grade is for one exact copy of the source (56a4754edf0d), read on 2026-09-27. The repository is watched and re-audited when it changes.

Advertisement