Atlas / MCP servers / study8677 / RepoBrain

RepoBrainSAFE

mcp/study8677/repobrain-1

🧠 RepoBrain (formerly Antigravity) — Give your repo a brain. ChatGPT for your codebase: works in Claude Code, Cursor, Codex, Windsurf & more.

Verdict
SAFE
Grade
B
Trust score
88 /100
Exposed tools
4 3r · 1w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
1,326
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Give your repo a brain 🧠 — ChatGPT for your codebase, works in Claude Code, Cursor, Codex, Windsurf & 4 more.

Formerly known as Antigravity Workspace Template — same project, new name.

[](LICENSE) [](https://python.org/) [](https://github.com/study8677/repobrain/actions) [](https://deepwiki.com/study8677/repobrain) [](https://github.com/xiaolai/nlpm-for-claude) [](https://github.com/study8677/repobrain/stargazers)

English · 中文 · Español

Read from source at commit 8d98e1f0e250OBSERVED · 2026-09-25
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add repobrain-engine --env MSB_API_KEY=${MSB_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- uvx repobrain-engine
claude-desktop
{
  "mcpServers": {
    "repobrain-engine": {
      "command": "uvx",
      "args": [
        "repobrain-engine"
      ],
      "env": {
        "MSB_API_KEY": "${MSB_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (4)

3 read · 1 write · 0 destructive.

ToolRiskDescription
ask_projectreadAnswer a question about the project using the knowledge hub.
create_issuewriteCreate a GitHub issue
refresh_projectreadRebuild the project knowledge base (.repobrain/conventions.md and structure.md).
test_toolreadA test tool
04

Trust audit

SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (22)

LOWInventory / provenance · inv.hidden_file · CWE-1104
cli/src/rb_cli/templates/.clinerules
.clinerules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
cli/src/rb_cli/templates/.repobrain/.version
.version
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
cli/src/rb_cli/templates/.windsurfrules
.windsurfrules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
engine/tests/test_ask_tools.py:86
result = tools["read_file"]("../../etc/passwd")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
engine/tests/test_ask_tools.py:124
result = tools["list_directory"]("../../")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/en/SANDBOX.md:39
export MSB_SERVER_URL=http://127.0.0.1:5555
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/en/SANDBOX.md:59
| `MSB_SERVER_URL` | `http://127.0.0.1:5555` | Microsandbox server URL |
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/en/SANDBOX.md:111
export MSB_SERVER_URL=http://127.0.0.1:5555
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/es/SANDBOX.md:40
export MSB_SERVER_URL=http://127.0.0.1:5555
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/es/SANDBOX.md:63
| `MSB_SERVER_URL` | `http://127.0.0.1:5555` | URL del servidor Microsandbox |
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
.context/system_prompt.md:9
1.  **Follow the Persona**: You are a Senior Developer Advocate and Solutions Architect. Be helpful, authoritative, and precise.
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
openspec/changes/2026-01-09-add-sandbox-execution/proposal.md:11
- Agent-generated code runs directly on the host with full privileges
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
INSTALL.md:70
cat >> .env <<'EOF'
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
INSTALL.md:84
cat >> .env <<'EOF'
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:165
cat > .env <<EOF
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README_CN.md:205
cat > .env <<EOF
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README_ES.md:188
cat > .env <<EOF
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
README.md:74
> Read https://github.com/study8677/repobrain/blob/main/AI_INSTALL.md and follow it to install RepoBrain in this project.
Why it matters. remote text is to be obeyed as instructions
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/en/SANDBOX.md:31
curl -sSL https://get.microsandbox.dev | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/es/SANDBOX.md:32
curl -sSL https://get.microsandbox.dev | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/zh/SANDBOX.md:30
curl -sSL https://get.microsandbox.dev | sh
INFOInventory / provenance · inv.oversize · CWE-1104
docs/assets/doloffer-banner-cn.png
docs/assets/doloffer-banner-cn.png
Why it matters. 1394403 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-09-25 · audit v0.4.1 · source sha 8d98e1f0e250full audit observations/trust-audit/mcp-server/study8677__repobrain-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-258d98e1f0e250SAFEB88first audit
06

Questions

What is the RepoBrain MCP server?

🧠 RepoBrain (formerly Antigravity) — Give your repo a brain. ChatGPT for your codebase: works in Claude Code, Cursor, Codex, Windsurf & more.

What tools does RepoBrain expose?

4 in total: 3 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is RepoBrain safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does RepoBrain need?

It reads MSB_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does RepoBrain run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as repobrain-engine.

How current is this page?

The grade is for one exact copy of the source (8d98e1f0e250), read on 2026-09-25. The repository is watched and re-audited when it changes.

Advertisement