# VibeRaven Guides

> Read-only VibeRaven guides: explain a finding, search launch guides, get a Supabase checklist.

- name: io.github.ohad6k/viberaven-guides
- version: 1.0.0
- connection class: R0 (autonomous)
- trust: 80/100 flags: no-repository
- quality: 95/100 (strong)
- owner: not claimed
- descriptor: https://api.protogrid.dev/v1/servers/io.github.ohad6k%2Fviberaven-guides
- tools: https://api.protogrid.dev/v1/servers/io.github.ohad6k%2Fviberaven-guides/tools

**An agent can connect right now, no human step.** Remote endpoint, no authentication, reachable on the last probe.

## Connection (mcpServers)

```json
{
  "mcpServers": {
    "viberaven-guides": {
      "type": "http",
      "url": "https://viberaven.dev/mcp"
    }
  }
}
```


## Trust

- hygiene: 80
- liveness: 100
- freshness: 100
- provenance: 45
- drivers: +website +reachable +uptime-100% +updated-9d-ago -no-repository
- Derived from observable signals (official registry feed and our own credential-free probes); no code audit performed.

## Quality 95/100 (strong)

### protocol: 100 (weight 25)

- pass `protocol.modern`: supports 2026-07-28 (server/discover)
- pass `protocol.stateless`: answers without a session
- pass `protocol.transport`: streamable HTTP
- pass `protocol.list_ttl`: tool list is cacheable (ttlMs 3600000)

### authorization: n/a (weight 15)

- n/a `auth.prm`, `auth.as_metadata`, `auth.cimd`: no remote uses OAuth
- n/a `auth.secret_in_url`: no templated URL

### tool hygiene: 100 (weight 30)

- pass `tools.descriptions`: every tool has a description
- pass `tools.description_length`: descriptions are concise
- pass `tools.schemas`: every tool has an object input schema
- pass `tools.annotations`: 3 of 3 tools declare readOnlyHint or destructiveHint
- pass `tools.directory_hints`: every tool declares readOnlyHint, destructiveHint, idempotentHint and openWorldHint
- pass `tools.token_cost`: about 682 tokens to load every tool
- pass `tools.api_dump`: tools are not a one-to-one API dump

### stability: 75 (weight 15)

- warn `stability.changes`: 17 tool changes in 30 days
- pass `stability.rug_pull`: no tool changed its meaning under the same name

### dependencies: n/a (weight 15)

- n/a `deps.known_vulns`, `deps.mcp_sdk_version`, `deps.resolvable`: no npm or PyPI package

- tools: 3, about 682 tokens to load them all
- tool set hash: 087c547477e7d1bbcf1d21ad2f15ad00
- tools last changed: 2026-10-09T01:00:15.411Z
- badge: [![protogrid quality](https://protogrid.dev/badge/io.github.ohad6k/viberaven-guides.svg)](https://protogrid.dev/servers/io.github.ohad6k/viberaven-guides)
- Checks run on what our credential-free, read-only probes observe; tools are never called and no code audit is performed.

### Tool changes

- 2026-10-09 `launch_checklist` changed (description)
  - before: Use this when the user wants a manual pre-launch checklist for a Lovable + Supabase app or a Next.js + Supabase app on Vercel. Returns the checklist published on viberaven.dev for that stack with its sources, and the one optional local VibeRaven step (`npx -y viberaven@1.6.6 check`), which is advice, not a gate. The items are manual checks the user does in their dashboards and code; this tool does not run any of them.
  - after: Use this when the user wants a manual pre-launch checklist for a Lovable + Supabase app or a Next.js + Supabase app on Vercel. Returns the checklist published on viberaven.dev for that stack with its sources, and the one optional local VibeRaven step (`npx -y viberaven@1.6.7 check`), which is advice, not a gate. The items are manual checks the user does in their dashboards and code; this tool does not run any of them.
- 2026-10-09 `explain_finding` changed (description)
  - before: Use this when the user asks what a VibeRaven finding id means, for example rls_disabled or env_var_drift, or pastes a finding from a VibeRaven 1.6.6 report. Returns what the rule detects in repository files, why it matters, how to fix it and what it does not check, quoted from viberaven.dev with a source link for each part. It does not read the user's repository, database or Vercel project. Known ids: rls_disabled, rls_no_policies, rls_policy_allows_all_read, rls_policy_allows_all_write, security_definer_function_executable, pooler_port_mismatch, service_role_key_in_client_code, env_var_drift. An unknown id returns found: false and the list of known ids.
  - after: Use this when the user asks what a VibeRaven finding id means, for example rls_disabled or env_var_drift, or pastes a finding from a VibeRaven 1.6.7 report. Returns what the rule detects in repository files, why it matters, how to fix it and what it does not check, quoted from viberaven.dev with a source link for each part. It does not read the user's repository, database or Vercel project. Known ids: rls_disabled, rls_no_policies, rls_policy_allows_all_read, rls_policy_allows_all_write, security_definer_function_executable, pooler_port_mismatch, service_role_key_in_client_code, env_var_drift. An unknown id returns found: false and the list of known ids.
- 2026-10-08 `launch_checklist` changed (description)
  - before: Use this when the user wants a manual pre-launch checklist for a Lovable + Supabase app or a Next.js + Supabase app on Vercel. Returns the checklist published on viberaven.dev for that stack with its sources, and the one optional local VibeRaven step (`npx -y viberaven@1.6.5 check`), which is advice, not a gate. The items are manual checks the user does in their dashboards and code; this tool does not run any of them.
  - after: Use this when the user wants a manual pre-launch checklist for a Lovable + Supabase app or a Next.js + Supabase app on Vercel. Returns the checklist published on viberaven.dev for that stack with its sources, and the one optional local VibeRaven step (`npx -y viberaven@1.6.6 check`), which is advice, not a gate. The items are manual checks the user does in their dashboards and code; this tool does not run any of them.
- 2026-10-08 `explain_finding` changed (description)
  - before: Use this when the user asks what a VibeRaven finding id means, for example rls_disabled or env_var_drift, or pastes a finding from a VibeRaven 1.6.5 report. Returns what the rule detects in repository files, why it matters, how to fix it and what it does not check, quoted from viberaven.dev with a source link for each part. It does not read the user's repository, database or Vercel project. Known ids: rls_disabled, rls_no_policies, rls_policy_allows_all_read, rls_policy_allows_all_write, security_definer_function_executable, pooler_port_mismatch, service_role_key_in_client_code, env_var_drift. An unknown id returns found: false and the list of known ids.
  - after: Use this when the user asks what a VibeRaven finding id means, for example rls_disabled or env_var_drift, or pastes a finding from a VibeRaven 1.6.6 report. Returns what the rule detects in repository files, why it matters, how to fix it and what it does not check, quoted from viberaven.dev with a source link for each part. It does not read the user's repository, database or Vercel project. Known ids: rls_disabled, rls_no_policies, rls_policy_allows_all_read, rls_policy_allows_all_write, security_definer_function_executable, pooler_port_mismatch, service_role_key_in_client_code, env_var_drift. An unknown id returns found: false and the list of known ids.
- 2026-10-06 `launch_checklist` changed (description)
  - before: Use this when the user wants a manual pre-launch checklist for a Lovable + Supabase app or a Next.js + Supabase app on Vercel. Returns the checklist published on viberaven.dev for that stack with its sources, and the one optional local VibeRaven step (`npx -y viberaven@1.6.4 check`), which is advice, not a gate. The items are manual checks the user does in their dashboards and code; this tool does not run any of them.
  - after: Use this when the user wants a manual pre-launch checklist for a Lovable + Supabase app or a Next.js + Supabase app on Vercel. Returns the checklist published on viberaven.dev for that stack with its sources, and the one optional local VibeRaven step (`npx -y viberaven@1.6.5 check`), which is advice, not a gate. The items are manual checks the user does in their dashboards and code; this tool does not run any of them.
- 2026-10-06 `explain_finding` changed (description)
  - before: Use this when the user asks what a VibeRaven finding id means, for example rls_disabled or env_var_drift, or pastes a finding from a VibeRaven 1.6.4 report. Returns what the rule detects in repository files, why it matters, how to fix it and what it does not check, quoted from viberaven.dev with a source link for each part. It does not read the user's repository, database or Vercel project. Known ids: rls_disabled, rls_no_policies, rls_policy_allows_all_read, rls_policy_allows_all_write, security_definer_function_executable, pooler_port_mismatch, service_role_key_in_client_code, env_var_drift. An unknown id returns found: false and the list of known ids.
  - after: Use this when the user asks what a VibeRaven finding id means, for example rls_disabled or env_var_drift, or pastes a finding from a VibeRaven 1.6.5 report. Returns what the rule detects in repository files, why it matters, how to fix it and what it does not check, quoted from viberaven.dev with a source link for each part. It does not read the user's repository, database or Vercel project. Known ids: rls_disabled, rls_no_policies, rls_policy_allows_all_read, rls_policy_allows_all_write, security_definer_function_executable, pooler_port_mismatch, service_role_key_in_client_code, env_var_drift. An unknown id returns found: false and the list of known ids.
- 2026-10-05 `launch_checklist` changed (description)
  - before: Use this when the user wants a manual pre-launch checklist for a Lovable + Supabase app or a Next.js + Supabase app on Vercel. Returns the checklist published on viberaven.dev for that stack with its sources, and the one optional local VibeRaven step (`npx -y viberaven@1.6.3 check`), which is advice, not a gate. The items are manual checks the user does in their dashboards and code; this tool does not run any of them.
  - after: Use this when the user wants a manual pre-launch checklist for a Lovable + Supabase app or a Next.js + Supabase app on Vercel. Returns the checklist published on viberaven.dev for that stack with its sources, and the one optional local VibeRaven step (`npx -y viberaven@1.6.4 check`), which is advice, not a gate. The items are manual checks the user does in their dashboards and code; this tool does not run any of them.
- 2026-10-05 `explain_finding` changed (description)
  - before: Use this when the user asks what a VibeRaven finding id means, for example rls_disabled or env_var_drift, or pastes a finding from a VibeRaven 1.6.3 report. Returns what the rule detects in repository files, why it matters, how to fix it and what it does not check, quoted from viberaven.dev with a source link for each part. It does not read the user's repository, database or Vercel project. Known ids: rls_disabled, rls_no_policies, rls_policy_allows_all_read, rls_policy_allows_all_write, security_definer_function_executable, pooler_port_mismatch, service_role_key_in_client_code, env_var_drift. An unknown id returns found: false and the list of known ids.
  - after: Use this when the user asks what a VibeRaven finding id means, for example rls_disabled or env_var_drift, or pastes a finding from a VibeRaven 1.6.4 report. Returns what the rule detects in repository files, why it matters, how to fix it and what it does not check, quoted from viberaven.dev with a source link for each part. It does not read the user's repository, database or Vercel project. Known ids: rls_disabled, rls_no_policies, rls_policy_allows_all_read, rls_policy_allows_all_write, security_definer_function_executable, pooler_port_mismatch, service_role_key_in_client_code, env_var_drift. An unknown id returns found: false and the list of known ids.
- 2026-10-04 `launch_checklist` changed (description)
  - before: Use this when the user wants a manual pre-launch checklist for a Lovable + Supabase app or a Next.js + Supabase app on Vercel. Returns the checklist published on viberaven.dev for that stack with its sources, and the one optional local VibeRaven step (`npx -y viberaven@1.6.2 check`), which is advice, not a gate. The items are manual checks the user does in their dashboards and code; this tool does not run any of them.
  - after: Use this when the user wants a manual pre-launch checklist for a Lovable + Supabase app or a Next.js + Supabase app on Vercel. Returns the checklist published on viberaven.dev for that stack with its sources, and the one optional local VibeRaven step (`npx -y viberaven@1.6.3 check`), which is advice, not a gate. The items are manual checks the user does in their dashboards and code; this tool does not run any of them.
- 2026-10-04 `explain_finding` changed (description)
  - before: Use this when the user asks what a VibeRaven finding id means, for example rls_disabled or env_var_drift, or pastes a finding from a VibeRaven 1.6.2 report. Returns what the rule detects in repository files, why it matters, how to fix it and what it does not check, quoted from viberaven.dev with a source link for each part. It does not read the user's repository, database or Vercel project. Known ids: rls_disabled, rls_no_policies, rls_policy_allows_all_read, rls_policy_allows_all_write, security_definer_function_executable, pooler_port_mismatch, service_role_key_in_client_code, env_var_drift. An unknown id returns found: false and the list of known ids.
  - after: Use this when the user asks what a VibeRaven finding id means, for example rls_disabled or env_var_drift, or pastes a finding from a VibeRaven 1.6.3 report. Returns what the rule detects in repository files, why it matters, how to fix it and what it does not check, quoted from viberaven.dev with a source link for each part. It does not read the user's repository, database or Vercel project. Known ids: rls_disabled, rls_no_policies, rls_policy_allows_all_read, rls_policy_allows_all_write, security_definer_function_executable, pooler_port_mismatch, service_role_key_in_client_code, env_var_drift. An unknown id returns found: false and the list of known ids.

Full history: https://api.protogrid.dev/v1/servers/io.github.ohad6k%2Fviberaven-guides/changes

## Remotes

- https://viberaven.dev/mcp (streamable-http, auth none, reachable true, uptime30d 1)

## Packages

_none_

## Tools (3)

- `explain_finding`: Use this when the user asks what a VibeRaven finding id means, for example rls_disabled or env_var_drift, or pastes a finding from a VibeRaven 1.6.7 report. Returns what the rule detects in repository files, why it matters, how to fix it and what it does not check, quoted from viberaven.dev with a source link for each part. It does not read the user's repository, database or Vercel project. Known ids: rls_disabled, rls_no_policies, rls_policy_allows_all_read, rls_policy_allows_all_write, security_definer_function_executable, pooler_port_mismatch, service_role_key_in_client_code, env_var_drift. An unknown id returns found: false and the list of known ids.
- `launch_checklist`: Use this when the user wants a manual pre-launch checklist for a Lovable + Supabase app or a Next.js + Supabase app on Vercel. Returns the checklist published on viberaven.dev for that stack with its sources, and the one optional local VibeRaven step (`npx -y viberaven@1.6.7 check`), which is advice, not a gate. The items are manual checks the user does in their dashboards and code; this tool does not run any of them.
- `search_guides`: Use this when the user has a launch question about an AI-built app on Vercel + Supabase, such as Supabase RLS, env vars on Vercel, a Stripe webhook after deploy or a client handoff. Searches the launch guides published on viberaven.dev by keyword and returns up to 5 matches, each with its title, URL and the short answer from the page. It only searches those published pages: it does not browse the web or read the user's project. No match returns an empty list.
