DocpullBLOCK
Local-first Python CLI and MCP server for versioned, cited context from web and document sources.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Active open-source project · MIT License
DocPull turns changing public web sources into cited, reproducible context for AI agents and retrieval pipelines. Use it when your application needs to know which sources it used, whether they changed, and how to rebuild the same context later.
[](https://www.python.org/downloads/) [](https://pypi.org/project/docpull/) [](LICENSE)
Install and sync your first source
pip install docpull docpull init stripe-docs docpull add https://docs.stripe.com docpull sync docpull diff docpull export context-pack --target cursor
The project stores declared sources in docpull.yaml and resolved inputs in .docpull/context.lock.json. Later syncs produce a hash-based diff while preserving source URLs, content hashes, run IDs, citations, and export metadata.
No account or paid API is required for this path. Direct fetching, discovery, extraction, indexing, pack analysis, and diffs run locally.
Why use DocPull
- Reproduce agent context. Stable IDs, hashes, manifests, and lockfiles show which
source versions produced an answer or artifact.
- Detect source drift. Sync and diff documentation, product pages, policies,
feeds, repositories, packages, standards, and local documents.
- Keep evidence inspectable. Markdown, NDJSON, SQLite, citations, and provenance
sidec
c112d7eb37f9OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add docpull -- None docpull==6.5.5
Exposed tools (17)
16 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
audit_pack | write | Write pack.audit.json and PACK_AUDIT.md with deterministic quality dimensions. |
brand_pack | read | Build an evidence-backed brand pack through the common workflow protocol. |
ensure_docs | read | Fetch Markdown for a configured source alias. Optionally indexes for semantic search. |
export_pack | read | Export a local pack to agent-safe JSONL or skill/rule formats. |
graph_neighbors | read | List cited neighboring nodes for matching graph entity nodes. |
graph_query | read | Search graph nodes and cited graph edge evidence without generating an answer. |
graph_status | read | Report whether local graph artifacts are missing, current, or stale. |
grep_docs | read | FAST exact text search - use for known method/function/component names. Examples: - |
image_pack | read | Build a bounded visual-asset manifest through the common workflow protocol. |
list_indexed | read | List all indexed source aliases with chunk counts |
list_sources | read | List available source aliases |
pack_citations | read | Build a stable citation/source map for a docpull context pack. |
pack_diff | read | Diff two docpull context packs by URL and content hashes without shelling out. |
pack_score | read | Score a docpull context pack for agent-readiness without shelling out. |
pack_search | read | Search a docpull context pack locally and return cited excerpts. |
product_pack | read | Build product and pricing evidence through the common workflow protocol. |
search_docs | read | Semantic search for CONCEPTS - use when you don |
Trust audit
BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (9 observation(s))
- Network
- declared (22 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
return yaml.load(payload, Loader=_UniqueKeySafeLoader)
"eval(source);",
"--insecure-tls",
"[red]Configuration error:[/red] --insecure-tls is no longer supported; "
- **Pasted documentation or source URL**: call `fetch_url(url=...)` if you only need one static/server-rendered page. For a whole source site you don't have an alias for, tell the user to run `/web-ad
console.print(f"[green]Signing key:[/green] {payload['private_key']}")"exfil_to_url",
"exfiltration",
r"\b(?:send|post|exfiltrate|forward|upload|transmit)\b[^\n]{0,80}?https?://","exfiltration",
_p("run_following_command", "exfiltration", r"\brun\s+the\s+following\s+command\b", re.IGNORECASE),url: http://127.0.0.1:8765/index.html
- http://127.0.0.1:8765/index.html
url: http://127.0.0.1:8765/index.html
- http://127.0.0.1:8765/index.html
- http://127.0.0.1:8765/guide.html
secret = "DOCPULL_LIFECYCLE_SENTINEL_SECRET"
03-document.docx
.infisical.json
- ../../README.md
- ../../docs/context-pack-contract-v3.md
- ../../docs/context-ci.md
BENCH_ROOT="$(cd "$SCRIPT_DIR/../../.." && pwd)"
`http://169.254.169.254/`, `http://localhost`, `file:///etc/passwd`,
"https://169.254.169.254.nip.io/latest/meta-data/", // wildcard rebinding
Gates applied: instruction_override, no_behavioural_pass.
c112d7eb37f9full audit observations/trust-audit/mcp-server/raintree-technology__docpull.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | c112d7eb37f9 | BLOCK | F | 54 | first audit |
Questions
What is the Docpull MCP server?
Local-first Python CLI and MCP server for versioned, cited context from web and document sources.
What tools does Docpull expose?
17 in total: 16 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Docpull safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (54/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Docpull need?
It reads DOCPULL_MCP_EMBEDDING_MAX_INPUT_TOKENS, E2B_API_KEY, NCBI_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Docpull run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @raintree-technology/docpull-sdk at 6.5.5.
How current is this page?
The grade is for one exact copy of the source (c112d7eb37f9), read on 2026-10-09. The repository is watched and re-audited when it changes.