Atlas / MCP servers / tobocop2 / Lilbee

LilbeeBLOCK

mcp/tobocop2/lilbee

The whole local AI stack in one executable: it runs and manages local AI models across every GPU, and it's a search engine you can talk to, with cited answers from your files, code, and the web. MCP server for coding agents, web crawler, TUI, CLI, REST API, Python library. No Ollama or LM Studio nee

Verdict
BLOCK
Grade
F
Trust score
52 /100
Exposed tools
6 6r · 0w · 0d
Transport
streamable-http
License
MIT
Stars
63
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The whole local AI stack in one executable: it runs and manages the models, and searches everything you own with them.

Project site · Tutorial reels · PyPI · Obsidian plugin · REST API · Chat (#lilbee)

Read from source at commit 153e30a9ea48OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add lilbee --env GEMINI_API_KEY=${GEMINI_API_KEY} --env HF_TOKEN=${HF_TOKEN} --env LILBEE_HF_TOKEN=${LILBEE_HF_TOKEN} --env LILBEE_QA_KEY=${LILBEE_QA_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "lilbee": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "GEMINI_API_KEY": "${GEMINI_API_KEY}",
        "HF_TOKEN": "${HF_TOKEN}",
        "LILBEE_HF_TOKEN": "${LILBEE_HF_TOKEN}",
        "LILBEE_QA_KEY": "${LILBEE_QA_KEY}"
      }
    }
  }
}
03

Exposed tools (6)

6 read · 0 write · 0 destructive.

ToolRiskDescription
BashreadExecutes a bash command and returns its output.
ReadreadReads a file from the local filesystem.
aread
openread
searchreadFind docs
xread
04

Trust audit

BLOCKgrade F · trust 52/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (5 observation(s))
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/lilbee/__main__.py:81
exec(  # noqa: S102  payload is emitted by Python's own stdlib into sys.executable
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/qa/tui_render_sweep.py:136
cls = getattr(importlib.import_module(module), cls_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/lilbee/__init__.py:118
return importlib.import_module(f".{name}", __name__)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/lilbee/__main__.py:114
module = importlib.import_module(module_name)
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/lilbee/cli/commands/search_chat.py:154
console.print(token.content, end="")
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
scripts/qa/tui_fuzz.py:54
"runes ᛒᛖᛖ, zero-width  joins, ligature ﷽",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.coveragerc-windows
.coveragerc-windows
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
packaging/aur/lilbee-compat/.SRCINFO
.SRCINFO
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
packaging/aur/lilbee-cuda/.SRCINFO
.SRCINFO
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_tui.py:1591
module = importlib.import_module(f"{pkg.__name__}.{found.name}")
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_tui_color_compat.py:459
cls = getattr(importlib.import_module(module), cls_name)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tools/qa/opencode/reelrun.sh:146
h = hashlib.md5(open(f, "rb").read()).hexdigest()
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/publish-compat-packages.yml:187
mkdir -p ~/.ssh
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/publish-compat-packages.yml:188
printf '%s\n' "${BUCKET_SSH_KEY}" > ~/.ssh/scoop_bucket
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/publish-compat-packages.yml:189
chmod 600 ~/.ssh/scoop_bucket
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/publish-compat-packages.yml:190
ssh-keyscan github.com >> ~/.ssh/known_hosts 2>/dev/null
Why it matters. touches a credential store
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/workflows/publish-packages.yml:227
mkdir -p ~/.ssh
Why it matters. touches a credential store
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/test_crawl_integration.py:257
result = CrawlResult(url="https://evil.com/../../etc/passwd", markdown="# Malicious")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/server/test_handlers.py:230
files=[("data", ("../../escape.txt", b"safe", "text/plain"))],
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/server/test_handlers.py:282
validate_upload_names(["../../a/b.txt"])
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/server/test_wiki_routes.py:1279
assert _find_page("../../etc/passwd") is None
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/server/test_wiki_routes.py:1280
assert _find_page("summaries/../../../etc/passwd") is None
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
tests/crawler/test_url_filter.py:91
lambda *a, **kw: [(10, 1, 6, "", ("::ffff:169.254.169.254", 0, 0, 0))],
Why it matters. cloud metadata endpoint: the classic SSRF credential grab

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 153e30a9ea48full audit observations/trust-audit/mcp-server/tobocop2__lilbee.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08153e30a9ea48BLOCKF52first audit
06

Questions

What is the Lilbee MCP server?

The whole local AI stack in one executable: it runs and manages local AI models across every GPU, and it's a search engine you can talk to, with cited answers from your files, code, and the web. MCP server for coding agents, web crawler, TUI, CLI, REST API, Python library. No Ollama or LM Studio nee

What tools does Lilbee expose?

6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Lilbee safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (52/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Lilbee need?

It reads GEMINI_API_KEY, HF_TOKEN, LILBEE_HF_TOKEN, LILBEE_QA_KEY and LILBEE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Lilbee run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as lilbee at 0.6.101.

How current is this page?

The grade is for one exact copy of the source (153e30a9ea48), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement