Archive AgentBLOCK
Find your files with natural language and ask questions.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
An intelligent file indexer with powerful AI search (RAG engine), automatic OCR, and a seamless MCP interface.
[](https://github.com/Andrew-Jang/RAGHub?tab=readme-ov-file#rag-projects) [](https://mcphub.com/mcp-servers/shredEngineer/Archive-Agent) [](https://mcp.so/server/Archive-Agent/shredEngineer) [](https://mseep.ai/app/499d8d83-02c8-4c9b-9e4f-8e8391395482) [](https://deepwiki.com/shredEngineer/Archive-Agent)
Archive Agent brings RAG to your command line and connects to your tools via MCP — it's not a chatbot.
Find what you need with natural language
- Unlock your documents with semantic AI search & query
- Files are split using semantic chunking with context headers and committed to a local database.
- RAG engine1 uses reranking and expanding of retrieved chunks
1 [Retrieval Augmented Generation](https://en.wikipedia.org/wiki/Retrieval-augmented_generation) is the method of matching pre-made snippets of information to a query.
Natively index your documents on-device
- Includes local AI file system indexer
- Natively ingests PDFs, images, Markdown, plaintext, and more...
- Selects and tracks files using patterns like
~/Documents/*.pdf - Transcribes images using [automatic OCR](#ocr-st
438b6e2da6a5OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add archive-agent --env OPENAI_API_KEY=${OPENAI_API_KEY} --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} -- uvx archive-agent{
"mcpServers": {
"archive-agent": {
"command": "uvx",
"args": [
"archive-agent"
],
"env": {
"OPENAI_API_KEY": "${OPENAI_API_KEY}",
"OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}"
}
}
}
}Exposed tools (7)
7 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_answer_rag | read | |
get_chunk_headers | read | |
get_collections | read | |
get_files_changed | read | |
get_files_tracked | read | |
get_patterns | read | |
get_search_result | read |
Trust audit
BLOCKgrade D · trust 64/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (15)
echo "| (sudo) Install pandoc |"
sudo apt update && sudo apt install -y pandoc
echo "| (sudo) Install Qdrant server |"
sudo --preserve-env=LOCAL_AUTH_PASSWORD ./manage-qdrant.sh start
echo "Usage: sudo --preserve-env=LOCAL_AUTH_PASSWORD $0 [start|stop|update|recreate]"
system use found in code, not declared in the description
test_combinations_text_image.docx
return hashlib.sha1(point_str.encode('utf-8')).hexdigest()[:16]profile_name_hash = hashlib.sha1(profile_name.encode('utf-8')).hexdigest()[:8]| `mcp_server_host` | MCP server host (default `http://127.0.0.1`; set to `http://0.0.0.0` to expose in LAN) |
curl -H "api-key: $LOCAL_AUTH_PASSWORD" http://127.0.0.1:6333/collections
candidate = base64.b64decode(value, validate=True).decode("utf-8").partition(":")[2]read from the environment variable `LOCAL_AUTH_PASSWORD`.
archive_agent/assets/Screencapture-GUI.mov
test_data/ai_vision_easy_hard/test_ai_vision_hard.png
Gates applied: no_behavioural_pass.
438b6e2da6a5full audit observations/trust-audit/mcp-server/shredengineer__archive-agent.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 438b6e2da6a5 | BLOCK | D | 64 | first audit |
Questions
What is the Archive Agent MCP server?
Find your files with natural language and ask questions.
What tools does Archive Agent expose?
7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Archive Agent safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (64/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Archive Agent need?
It reads OPENAI_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (438b6e2da6a5), read on 2026-10-07. The repository is watched and re-audited when it changes.