Atlas / MCP servers / raintree-technology / Docpull

DocpullBLOCK

mcp/raintree-technology/docpull

Local-first Python CLI and MCP server for versioned, cited context from web and document sources.

Verdict
BLOCK
Grade
F
Trust score
54 /100
Exposed tools
17 16r · 1w · 0d
Transport
stdio
License
MIT
Stars
28
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Active open-source project · MIT License

DocPull turns changing public web sources into cited, reproducible context for AI agents and retrieval pipelines. Use it when your application needs to know which sources it used, whether they changed, and how to rebuild the same context later.

[](https://www.python.org/downloads/) [](https://pypi.org/project/docpull/) [](LICENSE)

Install and sync your first source

pip install docpull
docpull init stripe-docs
docpull add https://docs.stripe.com
docpull sync
docpull diff
docpull export context-pack --target cursor

The project stores declared sources in docpull.yaml and resolved inputs in .docpull/context.lock.json. Later syncs produce a hash-based diff while preserving source URLs, content hashes, run IDs, citations, and export metadata.

No account or paid API is required for this path. Direct fetching, discovery, extraction, indexing, pack analysis, and diffs run locally.

Why use DocPull

  • Reproduce agent context. Stable IDs, hashes, manifests, and lockfiles show which

source versions produced an answer or artifact.

  • Detect source drift. Sync and diff documentation, product pages, policies,

feeds, repositories, packages, standards, and local documents.

  • Keep evidence inspectable. Markdown, NDJSON, SQLite, citations, and provenance

sidec

Read from source at commit c112d7eb37f9OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add docpull -- None docpull==6.5.5
03

Exposed tools (17)

16 read · 1 write · 0 destructive.

ToolRiskDescription
audit_packwriteWrite pack.audit.json and PACK_AUDIT.md with deterministic quality dimensions.
brand_packreadBuild an evidence-backed brand pack through the common workflow protocol.
ensure_docsreadFetch Markdown for a configured source alias. Optionally indexes for semantic search.
export_packreadExport a local pack to agent-safe JSONL or skill/rule formats.
graph_neighborsreadList cited neighboring nodes for matching graph entity nodes.
graph_queryreadSearch graph nodes and cited graph edge evidence without generating an answer.
graph_statusreadReport whether local graph artifacts are missing, current, or stale.
grep_docsreadFAST exact text search - use for known method/function/component names. Examples: -
image_packreadBuild a bounded visual-asset manifest through the common workflow protocol.
list_indexedreadList all indexed source aliases with chunk counts
list_sourcesreadList available source aliases
pack_citationsreadBuild a stable citation/source map for a docpull context pack.
pack_diffreadDiff two docpull context packs by URL and content hashes without shelling out.
pack_scorereadScore a docpull context pack for agent-readiness without shelling out.
pack_searchreadSearch a docpull context pack locally and return cited excerpts.
product_packreadBuild product and pricing evidence through the common workflow protocol.
search_docsreadSemantic search for CONCEPTS - use when you don
04

Trust audit

BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (9 observation(s))
Network
declared (22 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
bench/src/docpull_bench/serialization.py:38
return yaml.load(payload, Loader=_UniqueKeySafeLoader)
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/docpull/rendering.py:667
"eval(source);",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/docpull/cli.py:532
"--insecure-tls",
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/docpull/cli.py:809
"[red]Configuration error:[/red] --insecure-tls is no longer supported; "
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
plugin/skills/docpull-research/SKILL.md:50
- **Pasted documentation or source URL**: call `fetch_url(url=...)` if you only need one static/server-rendered page. For a whole source site you don't have an alias for, tell the user to run `/web-ad
Why it matters. asks the agent to act without the user's knowledge
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/docpull/pack_tools.py:711
console.print(f"[green]Signing key:[/green] {payload['private_key']}")
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/docpull/security/injection.py:135
"exfil_to_url",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/docpull/security/injection.py:136
"exfiltration",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/docpull/security/injection.py:137
r"\b(?:send|post|exfiltrate|forward|upload|transmit)\b[^\n]{0,80}?https?://",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/docpull/security/injection.py:142
"exfiltration",
MEDIUMNetwork egress · net.beacon_words · CWE-200, CWE-319
src/docpull/security/injection.py:146
_p("run_following_command", "exfiltration", r"\brun\s+the\s+following\s+command\b", re.IGNORECASE),
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
bench/cases/controlled-v1.yaml:10
url: http://127.0.0.1:8765/index.html
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
bench/cases/controlled-v1.yaml:24
- http://127.0.0.1:8765/index.html
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
bench/cases/controlled-v1.yaml:46
url: http://127.0.0.1:8765/index.html
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
bench/cases/controlled-v1.yaml:60
- http://127.0.0.1:8765/index.html
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
bench/cases/controlled-v1.yaml:61
- http://127.0.0.1:8765/guide.html
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
bench/src/docpull_bench/lifecycle.py:549
secret = "DOCPULL_LIFECYCLE_SENTINEL_SECRET"
LOWInventory / provenance · inv.binary · CWE-1104
bench/fixtures/v2/parse/03-document.docx
03-document.docx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.infisical.json
.infisical.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
bench/capabilities/competitor-matrix-2026-07-14.yaml:81
- ../../README.md
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
bench/capabilities/competitor-matrix-2026-07-14.yaml:82
- ../../docs/context-pack-contract-v3.md
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
bench/capabilities/competitor-matrix-2026-07-14.yaml:83
- ../../docs/context-ci.md
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
bench/experimental/external-suites/wandr/check.sh:5
BENCH_ROOT="$(cd "$SCRIPT_DIR/../../.." && pwd)"
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
docs/CHANGELOG.md:843
`http://169.254.169.254/`, `http://localhost`, `file:///etc/passwd`,
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
mcp/src/source_resolver.test.ts:91
"https://169.254.169.254.nip.io/latest/meta-data/", // wildcard rebinding
Why it matters. cloud metadata endpoint: the classic SSRF credential grab

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha c112d7eb37f9full audit observations/trust-audit/mcp-server/raintree-technology__docpull.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09c112d7eb37f9BLOCKF54first audit
06

Questions

What is the Docpull MCP server?

Local-first Python CLI and MCP server for versioned, cited context from web and document sources.

What tools does Docpull expose?

17 in total: 16 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Docpull safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (54/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Docpull need?

It reads DOCPULL_MCP_EMBEDDING_MAX_INPUT_TOKENS, E2B_API_KEY, NCBI_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Docpull run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @raintree-technology/docpull-sdk at 6.5.5.

How current is this page?

The grade is for one exact copy of the source (c112d7eb37f9), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement