RESTHeartBLOCK
The Agent-native Backend for MongoDB
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A backend for web, mobile, AI and IoT apps.
[](https://github.com/SoftInstigate/restheart/commits/master) [](https://github.com/SoftInstigate/restheart/actions/workflows/branch.yml) [](https://github.com/SoftInstigate/restheart) [](https://central.sonatype.com/namespace/org.restheart) [](https://javadoc.io/doc/org.restheart/restheart-commons) [](https://hub.docker.com/r/softinstigate/restheart/) [](https://join.slack.com/t/restheart/shared_invite/zt-1olrhtoq8-5DdYLBWYDonFGEALhmgSXQ) [](https://cla-assistant.io/SoftInstigate/restheart)
What RESTHeart is
RESTHeart is a backend for web, mobile, AI and IoT apps. It gives an application the backend it would otherwise have to write — AI agents and RAG, accounts, permissions, data APIs, live data, email, payments — as configuration, not code. What an application needs beyond it goes into plugins, in Java, Kotlin, JavaScript or TypeScript.
Example
curl "https://demo.restheart.org/messages?filter={\"from\":\"Bob\"}&pagesize=1"No route was written for /messages. It is a MongoDB collec
01af831a22b4OBSERVED · 2026-09-26Exposed tools (10)
8 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
ccHider | read | hides credit card numbers |
helloWorldInterceptor | read | modifies the response of helloWorldService |
helloWorldService | read | just another Hello World |
helloWorldTS | read | Test typescript |
httpClientService | write | a service that uses java.net.http.HttpClient to execute a GET request |
mclientService | read | just an example JavaScript service that uses the MongoClient |
mongoGetDocInteceptor | read | a js interceptor that modified the response of GET /coll/<docid> |
mongoPostCollInterceptor | write | modifies the content of POST requests adding a timestamp |
nodePromiseSrv | read | just an example node service that requires http and returns a promise |
requireModuleService | read | just an example JavaScript service that uses a CommonJS module |
Trust audit
BLOCKgrade F · trust 53/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (13 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const parsed = eval(code);
evaluated = eval(code);
TOKEN=\$(curl -sX PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 60")
ISELF=\$(curl -s -H "X-aws-ec2-metadata-token: \$TOKEN" http://169.254.169.254/latest/meta-data/instance-id)
curl --insecure https://letsencrypt.org/certs/${FNAME} > ${outdir}/${FNAME}* Input: mongodb://user:secretPass@host:27017/db
TOKEN=\$(curl -sX PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 60")
ISELF=\$(curl -s -H "X-aws-ec2-metadata-token: \$TOKEN" http://169.254.169.254/latest/meta-data/instance-id)
smtp-username: AKIAX4NFDXSDBHZ4RU6K
smtp-username: AKIAX4NFDXSDBHZ4RU6K
String original = "mongodb://repoUser:myPassword@localhost:27017/mydb";
String original = "mongodb+srv://repoUser:[email protected]/?authSource=admin&replicaSet=rs0";
String original = "mongodb://repoUser:admin@caas-mongo/?authSource=admin&replicaSet=rs0";
String original = "mongodb://user123:p%40ss%[email protected]:27017/db";
And param token = '0000000011111111222222223333333344444444555555556666666677777777'
And param token = '0000000011111111222222223333333344444444555555556666666677777777'
.helmignore
Then visit: http://127.0.0.1:8080
Health check: curl http://127.0.0.1:8080/ping
proxy-pass: http://127.0.0.1:8080/echo
moment, one-liner-joke
Access-Control-Allow-Credentials: true
- [**Accounts**](https://restheart.org/docs/accounts/overview): sign-up, login, email verification, password reset, team invitations, Google sign-in, tokens and API keys
http -a admin:secret :8080/contacts name=uji [email protected] message="This is cool!"
$ echo '{"_id":"user","$schema":"http://json-schema.org/draft-04/schema#","type":"object","properties":{"_id":{"type":"string","pattern":"^\\w+@[a-zA-Z_]+?.[a-zA-Z]{2,3}$"},"password":{"type":"string"Gates applied: no_behavioural_pass.
01af831a22b4full audit observations/trust-audit/mcp-server/softinstigate__restheart.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-26 | 01af831a22b4 | BLOCK | F | 53 | first audit |
Questions
What is the RESTHeart MCP server?
The Agent-native Backend for MongoDB
What tools does RESTHeart expose?
10 in total: 8 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is RESTHeart safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (53/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does RESTHeart need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (01af831a22b4), read on 2026-09-26. The repository is watched and re-audited when it changes.