# ai·rete·rag (remote · ai-rete-rag.com)

Author rules from policy docs, then decide: a Rete engine gives the verdict, an LLM explains why.

- Trust score: 74/100 (medium)
- Change this week: 0
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-21

## Components

- remote · `ai-rete-rag.com`: 74/100 (this document), [markdown](https://verifymcp.io/servers/com-ai-rete-rag-ai-rete-rag-mcp/ai-rete-rag.md), [page](https://verifymcp.io/servers/com-ai-rete-rag-ai-rete-rag-mcp/ai-rete-rag)
- remote · `ai-rete-rag.com`: 36/100, [markdown](https://verifymcp.io/servers/com-ai-rete-rag-ai-rete-rag-mcp/mcp-auth.md), [page](https://verifymcp.io/servers/com-ai-rete-rag-ai-rete-rag-mcp/mcp-auth)
- pypi · `ai-rete-rag-mcp`: 81/100, [markdown](https://verifymcp.io/servers/com-ai-rete-rag-ai-rete-rag-mcp/ai-rete-rag-mcp.md), [page](https://verifymcp.io/servers/com-ai-rete-rag-ai-rete-rag-mcp/ai-rete-rag-mcp)

## Channel facts

- Endpoint: `https://ai-rete-rag.com/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.7.0`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-21.

- **Endpoint Security**: 57/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation check failed: no authorisation is required to call this server, and it exposes a tool marked destructive (put_rules).
  - HTTPS is enforced; there's no plaintext access path.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 66/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 1843 tokens (~230/item across 8 items; 8 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 100/100
  - No destabilizing schema changes in the last 30 days.
- **Tool Coverage**: 71/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 0% of tool parameters carry a description.
  - Structured output schemas are declared (100% of tools); any adoption earns full credit.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - We read all 8 captured tool definition(s), and no name or description among them implies an irreversible operation.
  - An AI judge read all 9 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the ai·rete·rag MCP server?

ai·rete·rag is a hosted endpoint at https://ai-rete-rag.com/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add --transport http com-ai-rete-rag-ai-rete-rag-mcp 'https://ai-rete-rag.com/mcp'
```

### Cursor

```json
{
  "mcpServers": {
    "com-ai-rete-rag-ai-rete-rag-mcp": {
      "url": "https://ai-rete-rag.com/mcp"
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-ai-rete-rag-ai-rete-rag-mcp": {
      "type": "http",
      "url": "https://ai-rete-rag.com/mcp"
    }
  }
}
```

### Codex

```toml
[mcp_servers.com-ai-rete-rag-ai-rete-rag-mcp]
url = "https://ai-rete-rag.com/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-ai-rete-rag-ai-rete-rag-mcp": {
      "type": "remote",
      "url": "https://ai-rete-rag.com/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-ai-rete-rag-ai-rete-rag-mcp --url 'https://ai-rete-rag.com/mcp' --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  com-ai-rete-rag-ai-rete-rag-mcp:
    url: "https://ai-rete-rag.com/mcp"
```

### Netclaw

```json
{
  "McpServers": {
    "com-ai-rete-rag-ai-rete-rag-mcp": {
      "Transport": "http",
      "Url": "https://ai-rete-rag.com/mcp"
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-ai-rete-rag-ai-rete-rag-mcp -t streamable-http -u 'https://ai-rete-rag.com/mcp'
```

### Other

```json
{
  "mcpServers": {
    "com-ai-rete-rag-ai-rete-rag-mcp": {
      "type": "http",
      "url": "https://ai-rete-rag.com/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-04 (score 74, 0)

- [security] Stability: 0.97 → pass

### 2026-09-03 (score 74, +1)

No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-08-31 (score 73, +1)

No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-08-29 (score 72, +1)

No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-08-27 (score 71, +1)

No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-08-26 (score 70, +2)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-08-24 (score 68, +1)

No change was recorded against any check on this day. Stability & Change Management went from 60 to 63. That category is still filling its 30-day observation window: 18 days of observed history at the previous scan, 19 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-08-11 (score 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

## MCP tools (8)

### `decide` (~392 tokens)

Make a decision

Make a deterministic, auditable decision in a domain.

The verdict comes from the domain's rule set (Rete engine, never the LLM),
so it is reproducible and compliant. The explanation is generated from the
domain's ingested policy documents.

Args:
    domain: Rule-set domain, e.g. "loan", "fraud", "clinical".
    query: Natural-language question or decision request.
    facts: Structured facts for working memory, e.g.
        {"credit_score": 710, "annual_income": 85000}. Use `list_rules`
        to see which fields a domain's rules test.
    unstructured_text: Optional free text (an application, a case note);
        facts are extracted from it automatically and merged.
    response_mode: "verdict_only" (fastest), "verdict_with_explanation",
        or "full_audit" (every rule evaluation + retrieved chunks, available
        on every plan including the free tier).
        rule_firings come back in causal order: a rule that matched a fact
        asserted by an earlier firing appears after it, with the derived
        facts listed under `asserted_facts`.
    filter_retrieval_with_rules: Pattern 01 — run the rules first and let a
        fired rule's `retrieval_scope` action narrow which documents the
        retrieval searches before it runs.
    extract_from_retrieval: Pattern 02 — parse the retrieved documents into
        facts and assert them into working memory, so rules fire on what was
        actually read (not just the facts you passed).

Input parameters:

- `domain` (string, required)
- `extract_from_retrieval` (boolean)
- `facts`
- `filter_retrieval_with_rules` (boolean)
- `query` (string, required)
- `response_mode` (string)
- `unstructured_text`

Output parameters:

- `result` (string)

### `list_rules` (~169 tokens)

List rules

List the decision rules for one domain (or all domains).

Returns each rule's conditions — either a flat AND list (field / operator /
value) or a `when` condition tree (nested all/any/not) — plus its verdict,
salience, and any asserted facts (`action.assert`, the facts a rule
produces for other rules to consume). `edges` lists the derived rule→rule
dependencies: src asserts a fact type that dst's conditions test (forward
chaining). Each rule may also carry `citation` — the policy sentence it
encodes — which is what lets a decision be traced back to the source
clause. Also includes overlap warnings. Use this to learn which fact
fields a domain expects before calling `decide`.

Input parameters:

- `domain`

Output parameters:

- `result` (string)

### `ingest_text` (~150 tokens)

Ingest policy text

Add policy/reference text to a domain's knowledge base.

The text is chunked and embedded; explanations for future decisions in this
domain will cite it. Creating a new domain claims it for your account
(plan limits apply). The built-in demo domains are read-only — ingest into
your own domain instead. On team plans, only the domain admin (the member
who created the domain, or the subscription owner) can add documents.

Args:
    domain: Domain to ingest into (existing or new).
    text: The policy or reference text.
    source: Optional source name shown in the document list.

Input parameters:

- `domain` (string, required)
- `source`
- `text` (string, required)

Output parameters:

- `result` (string)

### `list_documents` (~27 tokens)

List documents

List the documents ingested into a domain's knowledge base.

Input parameters:

- `domain` (string, required)

Output parameters:

- `result` (string)

### `get_rule_source` (~61 tokens)

Get rule source (YAML)

Fetch a domain's rule set as editable YAML (plus the parsed rules and
whether you may edit it). Use this before `put_rules` to see the current
rules; the built-in demo domains are read-only.

Input parameters:

- `domain` (string, required)

Output parameters:

- `result` (string)

### `put_rules` (~713 tokens)

Save rules

Create or replace a domain's rule set from YAML (self-serve rule authoring).

The first save to a new domain claims it for your account (plan limits
apply); the built-in demo domains are read-only. Rules are validated before
saving — set dry_run=true to validate without persisting. The response
reports ok/errors, the parsed rules, and any overlap warnings.

YAML format — a list of rules. Flat form (conditions are AND-ed):
    - name: "Approve"
      salience: 10
      conditions:
        - type: loan
          field: credit_score
          op: ">="
          value: 700
      action:
        verdict: "APPROVED"
        reason: "Credit score meets threshold"

Tree form — `when:` holds nested all/any/not condition groups, and an
action may assert derived facts that other rules consume (forward
chaining; the rule graph derives from these automatically):
    - name: "Sepsis Screen"
      salience: 30
      when:
        all:
          - {type: clinical, field: temperature_f, op: ">=", value: 101.5}
          - any:
              - {type: clinical, field: wbc_count, op: ">", value: 12.0}
              - {type: clinical, field: bands_pct, op: ">", value: 10}
      action:
        verdict: "URGENT_ALERT"
        assert:
          - {type: sepsis_flag, fields: {severity: high}}
    - name: "Escalate"
      salience: 40
      when:
        all:
          - {type: sepsis_flag, field: severity, op: "==", value: high}
          - {type: clinical, field: age, op: ">=", value: 65}
      action:
        verdict: "ADMIT_ICU"

Use either `conditions:` or `when:` per rule, never both. `not` passes
when the inner condition does not hold (including when the field is
absent). Produce/consume cycles between rules are rejected at validation.
An action may also carry `retrieval_scope: { <key>: <value> }` to narrow
which documents retrieval searches (Pattern 01).

A rule may also carry `citation:` — the policy sentence it encodes. It is
stored with the rule and shown beside it in decision a…

Input parameters:

- `domain` (string, required)
- `dry_run` (boolean)
- `rules_yaml` (string, required)

Output parameters:

- `result` (string)

### `import_policy_rules` (~193 tokens)

Draft rules from a policy

Convert a written policy document into DRAFT decision rules (LLM-assisted).

Returns validated draft rules (when/action, including chained asserts where
the policy stages its determinations), derived rule→rule edges, and overlap
warnings. Each returned rule carries a `citation` field holding the policy
sentence it encodes (also summarized in the top-level `citations` map).
NOTHING IS SAVED: review the drafts (and show them to the user), then
persist explicitly with `put_rules` — validate first with dry_run=true,
and keep each rule's `citation` in the YAML you save so the audit trail
back to the policy survives.

Args:
    domain: Domain the rules are drafted for (an owned domain or a new name).
    policy_text: The policy document text (max ~50k characters).

Input parameters:

- `domain` (string, required)
- `policy_text` (string, required)

Output parameters:

- `result` (string)

### `get_usage` (~22 tokens)

Check usage and quota

Show this account's decision usage, plan, and remaining monthly quota.

Output parameters:

- `result` (string)

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/com-ai-rete-rag-ai-rete-rag-mcp/ai-rete-rag#diagnostics

## Score history

- 2026-09-21: 74
- 2026-09-20: 74
- 2026-09-19: 74
- 2026-09-18: 74
- 2026-09-17: 74
- 2026-09-16: 74
- 2026-09-15: 74
- 2026-09-14: 74
- 2026-09-13: 74
- 2026-09-12: 74
- 2026-09-11: 74
- 2026-09-10: 74
- 2026-09-09: 74
- 2026-09-08: 74
- 2026-09-07: 74
- 2026-09-06: 74
- 2026-09-05: 74
- 2026-09-04: 74
- 2026-09-03: 74
- 2026-09-02: 73
- 2026-09-01: 73
- 2026-08-31: 73
- 2026-08-30: 72
- 2026-08-29: 72
- 2026-08-28: 71
- 2026-08-27: 71
- 2026-08-26: 70
- 2026-08-25: 68
- 2026-08-24: 68
- 2026-08-23: 67

## Common questions

### What is the ai·rete·rag MCP server?

ai·rete·rag is an MCP server listed in the public MCP registry as com.ai-rete-rag/ai-rete-rag-mcp. Author rules from policy docs, then decide: a Rete engine gives the verdict, an LLM explains why. This page covers its hosted endpoint (https://ai-rete-rag.com/mcp).

### Is the ai·rete·rag MCP server safe to use?

ai·rete·rag scores 74 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the ai·rete·rag MCP server expose?

ai·rete·rag exposes 8 tools: decide, list_rules, ingest_text, list_documents, get_rule_source, and 3 more. Their descriptions and schemas cost roughly 1,727 tokens of context every time the server is loaded.

### Does the ai·rete·rag MCP server require authentication?

No. We connected to ai·rete·rag without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

### Is the ai·rete·rag MCP server still maintained?

ai·rete·rag is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

## Links

- Remote endpoint: https://ai-rete-rag.com/mcp
- Repository: https://github.com/zaharajabeen13-create/ai-rete-rag-mcp
- Website: https://ai-rete-rag.com/
- Changelog RSS feed: https://verifymcp.io/servers/com-ai-rete-rag-ai-rete-rag-mcp/ai-rete-rag.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-ai-rete-rag-ai-rete-rag-mcp/ai-rete-rag.json
- HTML version of this page: https://verifymcp.io/servers/com-ai-rete-rag-ai-rete-rag-mcp/ai-rete-rag
