NeedleSAFE
Needle MCP Server for easy RAG.Long-term memory for LLMs.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/needle-mcp)
MCP (Model Context Protocol) server to manage documents and perform searches using Needle through Claude's Desktop Application.
Table of Contents
- Overview
- Features
- Usage
- Commands in Claude Desktop
- Result in Needle
- Installation
- Video Explanation
Overview
Needle MCP Server allows you to:
- Organize and store documents for quick retrieval.
- Perform powerful searches via Claude's large language model.
- Integrate seamlessly with the Needle ecosystem for advanced document management.
MCP (Model Context Protocol) standardizes the way LLMs connect to external data sources. You can use Needle MCP Server to easily enable semantic search tools in your AI applications, making data buried in PDFs, DOCX, XLSX, and other files instantly accessible by LLMs.
We recommend using our remote MCP server for the best experience - no local setup required.
Features
- Document Management: Easily add and organize documents on the server.
- Search & Retrieval: Claude-based natural language search for quick answers.
- Easy Integration: Works with Claude Desktop and Needle collections.
Usage
Commands in Claude Desktop
Below is an example of how the commands can be used in Claude Desktop to interact with the server:

5 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
needle_add_file | write | |
needle_create_collection | write | |
needle_get_collection_details | read | |
needle_get_collection_stats | read | |
needle_list_collections | read | |
needle_list_files | read | |
needle_search | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
9062f152545bfull audit observations/trust-audit/mcp-server/needle-ai__needle.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 9062f152545b | SAFE | B | 89 | first audit |
Questions
What is the Needle MCP server?
Needle MCP Server for easy RAG.Long-term memory for LLMs.
What tools does Needle expose?
7 in total: 5 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Needle safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Needle need?
It reads NEEDLE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Needle run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as needle-mcp.
How current is this page?
The grade is for one exact copy of the source (9062f152545b), read on 2026-10-07. The repository is watched and re-audited when it changes.