RAG Vault lets your AI coding assistant search your private documents locally. Everything runs on your machine and your data stays private.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
When Vitest UI server is listening, arbitrary file can be read and executed
Multer Vulnerable to Denial of Service via Uncontrolled Recursion
Multer vulnerable to Denial of Service via deeply nested field names
Multer vulnerable to Denial of Service via resource exhaustion
Multer vulnerable to Denial of Service via incomplete cleanup
process.env. You'll be asked to provide them before it can run.ALLOWED_SCAN_ROOTS— Home directory Directories allowed for database scanningBASE_DIR— 2. Pick a documents directory and set to that path.CACHE_DIR— "": "./.cache",CODEX_HOMECORS_ORIGINS— localhost Allowed origins (comma-separated, or )DB_PATH— "": "./documents/.rag-db",EMBEDDER_INIT_TIMEOUT_MSJSON_BODY_LIMIT— 5mb Max request body sizeMAX_FILE_SIZE— 104857600 (100 MB) Biggest file you can ingestMCP_CONNECT_TIMEOUT_MSMODEL_NAME— Xenova/all-MiniLM-L6-v2 HuggingFace embedding modelRAG_API_KEY— API Authentication: Optional API key viaRAG_EMBEDDING_DEVICE— "": "cpu",RAG_GROUPING— "": "related"RAG_HYBRID_WEIGHT— "": "0.6",RAG_HYDE_API_BASE_URLRAG_HYDE_API_KEY— unset API key for LLM backend (required when RAG_HYDE_BACKEND=api)RAG_HYDE_API_MODEL— claude-haiku-4-5-20251001 Model for LLM-based expansionRAG_HYDE_BACKEND— rule-based rule-based for local template expansion, api for LLM-based HyDERAG_HYDE_ENABLED— false Turn on query expansion for better recallRAG_HYDE_EXPANSIONS— 2 Number of expanded queries to generateRAG_MAX_DISTANCE— unset Drops results below this relevance threshold (use with boost mode; rrf scores are rank-based)RAG_RERANKER_CANDIDATE_MULTIPLIER— 2 Fetch this many extra candidates for the reranker to scoreRAG_RERANKER_DEVICE— auto Device for the reranker (same options as RAG_EMBEDDING_DEVICE)RAG_RERANKER_ENABLED— false Turn on cross-encoder reranking for better resultsRAG_RERANKER_MODEL— Xenova/ms-marco-MiniLM-L-6-v2 HuggingFace cross-encoder model (~23MB ONNX, downloads on first use)RAG_RRF_K— 60 RRF smoothing constant (only applies in rrf mode). Industry standard is 60.RAG_SEARCH_MODE— boost Fusion mode: boost (multiplicative keyword boost) or rrf (Reciprocal Rank Fusion)RATE_LIMIT_MAX_REQUESTS— 100 Max requests per windowRATE_LIMIT_WINDOW_MS— 60000 Rate limit time window (ms)REQUEST_LOGGING— false Turn on request audit loggingREQUEST_TIMEOUT_MS— 30000 API request timeoutRERANKER_INIT_TIMEOUT_MS— 600000 (10 min) Timeout for model download and initializationUPLOAD_DIR— ./uploads/ Temporary directory for web UI file uploadsVECTORSTORE_INIT_TIMEOUT_MSWEB_PORT— 3000 Port for web interface[](https://m8ven.ai/mcp/robthepcguy-rag-vault-9kylie)