Refact
BLOCKgrade F · trust 37/100AI Agent that handles engineering tasks end-to-end: integrates with developers’ tools, plans, executes, and iterates until it achieves a successful result.
ai agentdeveloper toolsenterprisefine tuningon premopen sourceragself hostedOverview
From the repository's own README, as read at the audited commit.
<a name="readme-top"></a><div align="center"> <picture> <source media="(prefers-color-scheme: dark)" srcset="https://docs.refact.ai/_astro/logo-dark.CCzD55EA.svg"> <source media="(prefers-color-scheme: light)" srcset="https://docs.refact.ai/_astro/logo-light.CblxRz3x.svg"> <img alt="Refact logo" src="https://docs.refact.ai/_astro/logo-dark.CCzD55EA.svg" width="200"> </picture> <h1 align="center">Refact</h1> <p align="center">Open-source, local-first AI coding assistant for IDE chat, autonomous agent workflows, and tool-powered development.</p></div><div align="center"> <a href="https://github.com/smallcloudai/refact/stargazers"><img src="https://img.shields.io/github/stars/smallcloudai/refact?style=for-the-badge&color=blue" alt="GitHub stars"></a> <a href="https://docs.refact.ai"><img src="https://img.shields.io/badge/documentation-blue?logo=googledocs&logoColor=FFE165&style=for-the-badge" alt="Documentation"></a> <a href="https://github.com/smallcloudai/refact/issues"><img src="https://img.shields.io/badge/issues-github?style=for-the-badge" alt="GitHub issues"></a></div>> [!IMPORTANT]> This repository is kept as the legacy archive for the original Refact project and is no longer the active development home.> Ongoing development has moved to [JegernOUTT/refact](https://github.com/JegernOUTT/refact); please use that repository for new issues, pull requests, and future updates.> Refact Cloud has been retired. Read the announcement: [Refact Cloud is shutting down](https://refact.ai/blog/2026/refact-cloud-is-shutting-down/).## LicenseRefact is distributed under the BSD-3-Clause license. See the repository license for details.
Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add refact-chat-js --env HF_TOKEN=${HF_TOKEN} --env OPENAI_API_KEY=${OPENAI_API_KEY} --env REFACT_TOKEN=${REFACT_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"refact-chat-js": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"HF_TOKEN": "${HF_TOKEN}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}",
"REFACT_TOKEN": "${REFACT_TOKEN}"
}
}
}
}Exposed tools (12) 8 read · 3 write · 1 destructive
Blast radius: 1 tool can delete or overwrite. An agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Definition | read | Find definition of a symbol in the project using AST |
Repository | read | Repository content |
code-review | read | Review code |
commit_message | write | Generate a commit message |
create_issue | write | Create a GitHub issue |
delete_repo | destructive | Delete a repository |
existing-skill | read | Existing |
local_skill | read | A local project skill |
my-plugin | read | A useful plugin |
my_skill | read | Existing description |
plugin_skill | read | A plugin skill |
review | write | Run review |
Details
- Source
- smallcloudai/refact
- npm
refact-chat-js@8.0.4- Transports
- stdio · streamable-http
- Credentials it reads
HF_TOKENOPENAI_API_KEYREFACT_TOKEN- License
- BSD-3-Clause
- Stars
- 3,542 · pushed 106d ago
Trust audit
Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (11 observation(s))
- Network
- declared (13 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
path: "src/AKIA1234567890ABCDEF/config.rs".to_string(),
assert!(!path.contains("AKIA1234567890ABCDEF"));}),!0),this.lastIndex=0}exec(e){this.matcherRe.lastIndex=this.lastIndexthis.rules.push([e,n]),"begin"===n.type&&this.count++}exec(e){fn exec(message: &ChatMessage) -> &Value {let exec = exec(&message);
let exec = exec(&message);
new_cmdline.push("--insecure");"RABBITMQ_URL": "amqp://guest:guest@localhost:5672"
gradle-wrapper.jar
speech: "Snack beacon detected.",
val startupUrl = URI("http://127.0.0.1:${newConfig.port}/")InferenceGlobalContext.connection.get(URI("http://127.0.0.1:$port/v1/graceful-shutdown")).get()?.get()return URI("http://127.0.0.1:${debugPort}/")"/9j/4AAQSkZJRgABAQAAAQABAAD/4gHYSUNDX1BST0ZJTEUAAQEAAAHIAAAAAAQwAABtbnRyUkdCIFhZWiAH4AABAAEAAAAAAABhY3NwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAQAA9tYAAQAAAADTLQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
"/9j/4AAQSkZJRgABAgAAAQABAAD/wAARCAGYAyADAREAAhEBAxEB/9sAQwAIBgYHBgUIBwcHCQkICgwUDQwLCwwZEhMPFB0aHx4dGhwcICQuJyAiLCMcHCg3KSwwMTQ0NB8nOT04MjwuMzQy/9sAQwEJCQkMCwwYDQ0YMiEcITIyMjIyMjIyMjIyMjIyMjIyMjIyMjI
"/9j/4AAQSkZJRgABAgAAAQABAAD/wAARCAMfAXEDAREAAhEBAxEB/9sAQwAIBgYHBgUIBwcHCQkICgwUDQwLCwwZEhMPFB0aHx4dGhwcICQuJyAiLCMcHCg3KSwwMTQ0NB8nOT04MjwuMzQy/9sAQwEJCQkMCwwYDQ0YMiEcITIyMjIyMjIyMjIyMjIyMjIyMjIyMjI
"/9j/4AAQSkZJRgABAgAAAQABAAD/wAARCAGYAyADAREAAhEBAxEB/9sAQwAIBgYHBgUIBwcHCQkICgwUDQwLCwwZEhMPFB0aHx4dGhwcICQuJyAiLCMcHCg3KSwwMTQ0NB8nOT04MjwuMzQy/9sAQwEJCQkMCwwYDQ0YMiEcITIyMjIyMjIyMjIyMjIyMjIyMjIyMjI
"/9j/4AAQSkZJRgABAgAAAQABAAD/wAARCAMfAXEDAREAAhEBAxEB/9sAQwAIBgYHBgUIBwcHCQkICgwUDQwLCwwZEhMPFB0aHx4dGhwcICQuJyAiLCMcHCg3KSwwMTQ0NB8nOT04MjwuMzQy/9sAQwEJCQkMCwwYDQ0YMiEcITIyMjIyMjIyMjIyMjIyMjIyMjIyMjI
let analysis = "please debug ProjectΔ import while keeping the identifier private";
let generated = "Tiny alarm: ProjectΔ import is doing suspicious parkour.";
assert!(!text.to_lowercase().contains("projectδ import"));apiKey: "2bae895dcb109e0a9b87ee935c121c85",
token: "ghp_AbCdEfGhIj1234567890".to_string(),
delete_repo
Gates applied: critical_finding, no_behavioural_pass.
Audited 2026-09-14 · audit v0.4.0 · source sha 7f8594f70b4a · full audit: observations/trust-audit/mcp-server/smallcloudai__refact.json · Report an issue or request a re-scan
Audit history
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-14 | 7f8594f70b4a | BLOCK | F | 37 | first audit |
Alternatives
Other servers in the same categories, safer ones first.
Questions
What is the Refact MCP server?
AI Agent that handles engineering tasks end-to-end: integrates with developers’ tools, plans, executes, and iterates until it achieves a successful result.
What tools does Refact expose?
12 in total: 8 read-only, 3 that write, and 1 that can delete or overwrite (delete_repo). Every one is listed on this page with its risk.
Is Refact safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (37/100) and found 9 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Refact need?
It reads HF_TOKEN, OPENAI_API_KEY and REFACT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Refact run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as refact-chat-js at 8.0.4.
How current is this page?
The grade is for one exact copy of the source (7f8594f70b4a), read on 2026-09-14. The repository is watched and re-audited when it changes.
Provenance: OBSERVED · read 2026-09-14 · job trust-audit-2026-09-14