LilbeeBLOCK
The whole local AI stack in one executable: it runs and manages local AI models across every GPU, and it's a search engine you can talk to, with cited answers from your files, code, and the web. MCP server for coding agents, web crawler, TUI, CLI, REST API, Python library. No Ollama or LM Studio nee
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The whole local AI stack in one executable: it runs and manages the models, and searches everything you own with them.
Project site · Tutorial reels · PyPI · Obsidian plugin · REST API · Chat (#lilbee)
153e30a9ea48OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add lilbee --env GEMINI_API_KEY=${GEMINI_API_KEY} --env HF_TOKEN=${HF_TOKEN} --env LILBEE_HF_TOKEN=${LILBEE_HF_TOKEN} --env LILBEE_QA_KEY=${LILBEE_QA_KEY} -- npx -y [email protected]{
"mcpServers": {
"lilbee": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"GEMINI_API_KEY": "${GEMINI_API_KEY}",
"HF_TOKEN": "${HF_TOKEN}",
"LILBEE_HF_TOKEN": "${LILBEE_HF_TOKEN}",
"LILBEE_QA_KEY": "${LILBEE_QA_KEY}"
}
}
}
}Exposed tools (6)
6 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Bash | read | Executes a bash command and returns its output. |
Read | read | Reads a file from the local filesystem. |
a | read | |
open | read | |
search | read | Find docs |
x | read |
Trust audit
BLOCKgrade F · trust 52/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
exec( # noqa: S102 payload is emitted by Python's own stdlib into sys.executable
cls = getattr(importlib.import_module(module), cls_name)
return importlib.import_module(f".{name}", __name__)module = importlib.import_module(module_name)
console.print(token.content, end="")
"runes ᛒᛖᛖ, zero-width joins, ligature ﷽",
.coveragerc-windows
.gitleaks.toml
.pre-commit-config.yaml
.SRCINFO
.SRCINFO
module = importlib.import_module(f"{pkg.__name__}.{found.name}")cls = getattr(importlib.import_module(module), cls_name)
h = hashlib.md5(open(f, "rb").read()).hexdigest()
mkdir -p ~/.ssh
printf '%s\n' "${BUCKET_SSH_KEY}" > ~/.ssh/scoop_bucketchmod 600 ~/.ssh/scoop_bucket
ssh-keyscan github.com >> ~/.ssh/known_hosts 2>/dev/null
mkdir -p ~/.ssh
result = CrawlResult(url="https://evil.com/../../etc/passwd", markdown="# Malicious")
files=[("data", ("../../escape.txt", b"safe", "text/plain"))],validate_upload_names(["../../a/b.txt"])
assert _find_page("../../etc/passwd") is Noneassert _find_page("summaries/../../../etc/passwd") is Nonelambda *a, **kw: [(10, 1, 6, "", ("::ffff:169.254.169.254", 0, 0, 0))],Gates applied: no_behavioural_pass.
153e30a9ea48full audit observations/trust-audit/mcp-server/tobocop2__lilbee.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 153e30a9ea48 | BLOCK | F | 52 | first audit |
Questions
What is the Lilbee MCP server?
The whole local AI stack in one executable: it runs and manages local AI models across every GPU, and it's a search engine you can talk to, with cited answers from your files, code, and the web. MCP server for coding agents, web crawler, TUI, CLI, REST API, Python library. No Ollama or LM Studio nee
What tools does Lilbee expose?
6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Lilbee safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (52/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Lilbee need?
It reads GEMINI_API_KEY, HF_TOKEN, LILBEE_HF_TOKEN, LILBEE_QA_KEY and LILBEE_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Lilbee run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as lilbee at 0.6.101.
How current is this page?
The grade is for one exact copy of the source (153e30a9ea48), read on 2026-10-08. The repository is watched and re-audited when it changes.