knowledge-graph-systemBLOCK
Kappa Graph — κ(G). A semantic knowledge graph where knowledge has weight. Extracts concepts, measures grounding strength, preserves disagreement, traces everything to source.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A semantic knowledge graph that extracts concepts from documents, tracks how well-supported they are, and remembers where sources disagree.
[κ(G)](https://en.wikipedia.org/wiki/Connectivity_(graph_theory)) — vertex connectivity of a graph. The minimum number of connections you'd need to cut before the graph falls apart. A measure of how robust the structure is.
Also kg — the unit of mass. Because knowledge here has weight. Grounding scores measure how heavy an idea is: well-evidenced claims carry more than thin ones. Contested concepts weigh differently than unchallenged ones.
Quick Start
Install Client Tools
The kg CLI, MCP server (for AI assistants), and optional FUSE filesystem:
curl -fsSL https://raw.githubusercontent.com/aaronsb/knowledge-graph-system/main/client-manager.sh | bash
Or just the CLI: npm install -g @aaronsb/kg-cli
Deploy the Platform
Run your own knowledge graph backend:
curl -fsSL https://raw.githubusercontent.com/aaronsb/knowledge-graph-system/main/install.sh | bash
Or from source:
git clone https://github.com/aaronsb/knowledge-graph-system.git cd knowledge-graph-system ./operator.sh init # Interactive setup ./operator.sh start # Start containers
See Quick Start Guide for details.
See It In Action
Interactive graph exploration with smart search, concept clustering, and relationship visualization

20 read · 1 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Count | read | Maximum number of results to return |
Depth | read | Number of hops to traverse (1-5) |
Direction | read | Outgoing, incoming, or both directions |
Exclude | read | Hide relationships with these statuses |
Grounding | read | Fetch confidence/reliability score |
Ontologies | read | List of ontology names to include |
Ontology | read | Optional filter by ontology/document name |
Pattern | read | Text pattern to exclude |
Query | read | Text to search for in concept labels |
Similarity | read | How closely concepts must match (50-100%) |
Target | read | Destination concept (by search or ID) |
artifact | read | Manage saved artifacts (ADR-116). Artifacts persist computed results like search results, projections, and polarity analyses for later recall. Three actions available: - |
catalog | read | Browse what is actually stored in the knowledge graph (ADR-501). A deterministic, filesystem-like view of the ontology -> document -> concept hierarchy. Use this to answer |
concept | read | Work with concepts: get details (ALL evidence + relationships), find related concepts (neighborhood exploration), or discover connections (paths between concepts). For |
document | read | Work with documents: list all, show content, or get concepts (ADR-507). Three actions available: - |
epistemic_status | read | Vocabulary epistemic status classification (ADR-610 Phase 2). Knowledge validation state for relationship types. Three actions available: - |
epoch | read | Read the graph epoch event log (ADR-203). Every mutation to the knowledge graph (ingestion job, agent reasoning, ontology annealing, manual edit) records a monotonic event with a wall-clock timestamp. This tool exposes that log so you can ask |
explore-graph | read | Learn how to explore the knowledge graph effectively |
graph | destructive | Create, edit, delete, and list concepts and edges in the knowledge graph (ADR-308). This tool provides deterministic graph editing without going through the LLM ingest pipeline. Use for manual curation, agent-driven knowledge building, and precise graph manipulation. **Actions:** - |
ingest | write | Ingest content into the knowledge graph: submit text, inspect files, ingest files, or ingest directories. Use action parameter to specify operation. |
job | destructive | Manage ingestion jobs: get status, list jobs, approve, cancel, delete, or cleanup. Use action parameter to specify operation. |
ontology | read | Manage ontologies (knowledge domains/collections): list all, get info, list files, or delete. Use action parameter to specify operation. |
search | read | Search for concepts, source passages, or documents using semantic similarity. Your ENTRY POINT to the graph. CONCEPT SEARCH (type: |
Trust audit
BLOCKgrade F · trust 23/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (19 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
const tool = eval(`(${toolStr})`);'**/.ssh/**',
'**/id_rsa',
'**/id_rsa.pub',
'**/id_ed25519',
'**/id_ed25519.pub',
only the trailing pole (`....H` → `....E`) and the number is untouched. The pole
publish-wizard.sh
publish.sh
console.log(); // New line after password input
console.log(); // New line after password input
console.log(); // New line after password input
console.log(` Client Secret: ${client.client_secret}`);print(f" client_secret: {_mask_secret(secret) if secret else '(not set)'}")test: ["CMD", "wget", "--no-verbose", "--no-check-certificate", "--tries=1", "--spider", "https://127.0.0.1/"]
process.stdout.write(colors.status.success('\n✓ Confirmed! You\'re probably human! 👩💻\n'));sys.stdout.write(f"{Colors.SUCCESS}✓ Confirmed! You're probably human! 👩💻{Colors.NC}\r\n")DATABASE_URL=postgresql://kg_user:securepassword123@localhost:5432/knowledge_graph
token = "invalid_token_format"
token = "my-secret-token-12345"
token = "consistent-token-xyz"
graph, job
cfg = yaml.load(f, Loader=_Loader)
hash_val = int(hashlib.md5(ontology.encode()).hexdigest()[:6], 16)
concept_hash = hashlib.md5(sentence.encode()).hexdigest()[:12]
Gates applied: no_behavioural_pass.
a1d1bbe985d9full audit observations/trust-audit/mcp-server/aaronsb__knowledge-graph-system.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-02 | a1d1bbe985d9 | BLOCK | F | 23 | first audit |
Questions
What is the knowledge-graph-system MCP server?
Kappa Graph — κ(G). A semantic knowledge graph where knowledge has weight. Extracts concepts, measures grounding strength, preserves disagreement, traces everything to source.
What tools does knowledge-graph-system expose?
23 in total: 20 read-only, 1 that write, and 2 that can delete or overwrite (graph, job). Every one is listed on this page with its risk.
Is knowledge-graph-system safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (23/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does knowledge-graph-system need?
It reads ACCESS_TOKEN_EXPIRE_MINUTES, GARAGE_ACCESS_KEY_ID, GARAGE_SECRET_ACCESS_KEY, KG_API_KEY, KG_OAUTH_CLIENT_ID, KG_OAUTH_CLIENT_SECRET, MAX_EXTRACTION_TOKENS, POSTGRES_PASSWORD, TOKEN_COST_EMBEDDING_SMALL and TOKEN_COST_GPT4O from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does knowledge-graph-system run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as viz-app at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (a1d1bbe985d9), read on 2026-10-02. The repository is watched and re-audited when it changes.