RatelCAUTION
Context engineering for AI agents. ~80% fewer tokens. Fix tool overload. Skills and memory with in-process BM25 and semantic retrieval. Progressive Disclosure. No vector DB.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Ratel Your AI agent is paying for tools it never uses. Ratel fixes that.
Docs • Skills • Discord
Introduction
The context engineering layer for AI agents. Selects only the tools and skills relevant to each turn, recovering accuracy lost to tool overload and cutting what you pay per call. No vector DB, no infra.
Why
- Cost: Every tool schema, every skill, and a growing list of instructions in the system prompt are tokens you pay for on every call. Send them all up front and you pay for them all, every turn.
- Accuracy: Models get worse as that context grows. Crowd it with tools, skills, and instructions a turn doesn't need and the model picks the wrong option and drifts off task.
- Ratel fixes both: it indexes your tools
872fff5b5ec2OBSERVED · 2026-10-01Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add telemetry --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env AWS_ACCESS_KEY_ID=${AWS_ACCESS_KEY_ID} --env AWS_SECRET_ACCESS_KEY=${AWS_SECRET_ACCESS_KEY} --env AWS_SESSION_TOKEN=${AWS_SESSION_TOKEN} -- npx -y @ratel-ai/[email protected]{
"mcpServers": {
"telemetry": {
"command": "npx",
"args": [
"-y",
"@ratel-ai/[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"AWS_ACCESS_KEY_ID": "${AWS_ACCESS_KEY_ID}",
"AWS_SECRET_ACCESS_KEY": "${AWS_SECRET_ACCESS_KEY}",
"AWS_SESSION_TOKEN": "${AWS_SESSION_TOKEN}"
}
}
}
}Exposed tools (75)
63 read · 12 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
a | read | always one |
address | read | Shop location |
after_empty | read | tool listed after an empty page |
after_empty_cursor | read | tool listed after empty-string cursor |
again | read | another page |
alpha | read | first page |
api-design | read | REST API design patterns: resource naming, status codes, pagination. |
auth | write | Set up login and sessions. |
b | read | always two |
bad | read | an invalid fact |
beta | read | first page |
boom | read | always fails |
broken | write | A native-shaped tool missing its execute handler. |
broken_watch | read | Watch a broken job. |
cancellation-policy | read | How to cancel or reschedule a booking and get a refund. |
cap | read | a capability tool |
charges | read | ... |
ci-triage | read | Diagnose why the build failed in CI |
deploy | write | Deploy an app |
deploy-fact | write | Original fact |
deploy-skill | write | Deploy an application. |
deploy_app | write | Deploy the app to production servers. |
docker_build | read | Build a Docker image from a Dockerfile |
dup | read | first listing |
echo | read | echoes its args |
endless | read | never finishes |
fact | read | composedonlyterm |
fail | read | Fail a job. |
first_page | read | page one |
frontend-slides | read | Build animation-rich HTML presentations from scratch. |
fs | read | filesystem helpers |
gamma | read | second page |
gh_run_list | write | List CI workflow runs and whether the build passed |
github | read | GitHub API |
good | read | a valid fact |
hours | read | Opening hours |
invalid-number | read | Invalid number |
lint | read | Lint the code |
migrations | read | Reversible DB migrations. |
min | read | a minimal skill, no tags or body |
mixed_case | read | Mixed-case schema keys. |
mutable | read | Accepted description |
n | read | d |
orphan | read | A plain native tool with a JSON schema but no id. |
outer | read | invokes a nested search |
oversized | read | Oversized schema |
oversized_tool | read | Oversized schema |
page_one | read | first page tool |
page_two | read | second page tool |
pdf | read | fill pdf forms |
ping | read | Ping |
push | write | Deploy the project to Vercel production. |
r | read | retrieved one |
read | read | Read a file |
read_file | read | Read a file from disk |
replaceable | read | New numeric tool. |
review_code | read | Review source |
s1 | read | a playbook |
search | read | Search the tool catalog for matching tools. |
search_files | read | Grep across files in a directory using a regular expression. |
send_email | write | Send an email via SMTP. |
shop-address | read | Where the barbershop is located and its opening hours. |
shop_address | read | Where the shop is |
skill | read | composedonlyterm |
stream_outer | read | streams after a nested search |
stuck | read | stuck in pagination |
t | read | a tool |
t1 | read | read a file from disk |
tool | read | composedonlyterm |
vault_rotate | read | Rotate a signing key in the vault |
vercel-deploy | write | How to deploy to Vercel: env vars, preview vs production, rollbacks. |
watch | read | Watch a job. |
write | write | Write a file |
write_file | write | Write a file |
x | read | d |
Trust audit
CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (20)
types_mod = __import__(module_name, fromlist=["PaginatedRequestParams"])
"beacon", "harvest", "prune",
.adr-dir
.lycheeignore
mcp opentelemetry-sdk -e ../../telemetry/python
'opentelemetry-sdk>=1.41,<1.42' ../../telemetry/python dist/*.whl
new URL("../../../../.github/workflows/release.yml", import.meta.url),"../../../protocol/v1/conformance/vectors.json"
serde_json::from_str(include_str!("../../telemetry/conformance/fixtures.json")).unwrap()baseUrl: "http://127.0.0.1:1",
yield f"http://127.0.0.1:{port}/embeddings"f"http://127.0.0.1:{server.server_port}/embeddings",yield f"http://127.0.0.1:{server.server_port}/embeddings", statereturn f"http://127.0.0.1:{listener.getsockname()[1]}", listener@types/node, tsx, typescript
@ai-sdk/openai, ai, @types/node, tsx, typescript
@types/node, tsx, typescript
@mastra/core, zod, @types/node, tsx, typescript
@ai-sdk/openai, @modelcontextprotocol/sdk, ai, @types/node, tsx, typescript
docs/assets/ratel-hero.gif
Gates applied: no_behavioural_pass.
872fff5b5ec2full audit observations/trust-audit/mcp-server/ratel-ai__ratel.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | 872fff5b5ec2 | CAUTION | B | 86 | first audit |
Questions
What is the Ratel MCP server?
Context engineering for AI agents. ~80% fewer tokens. Fix tool overload. Skills and memory with in-process BM25 and semantic retrieval. Progressive Disclosure. No vector DB.
What tools does Ratel expose?
75 in total: 63 read-only, 12 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Ratel safe to connect to an agent?
With care. The audit graded it B (86/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Ratel need?
It reads ANTHROPIC_API_KEY, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY, AWS_SESSION_TOKEN, OPENAI_API_KEY and RATEL_S3_TEST_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Ratel run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @ratel-ai/telemetry at 0.5.0.
How current is this page?
The grade is for one exact copy of the source (872fff5b5ec2), read on 2026-10-01. The repository is watched and re-audited when it changes.