Atlas / MCP servers / aaronsb / knowledge-graph-system

knowledge-graph-systemBLOCK

mcp/aaronsb/knowledge-graph-system

Kappa Graph — κ(G). A semantic knowledge graph where knowledge has weight. Extracts concepts, measures grounding strength, preserves disagreement, traces everything to source.

Verdict
BLOCK
Grade
F
Trust score
23 /100
Exposed tools
23 20r · 1w · 2d
Transport
stdio
License
Apache-2.0
Stars
128
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A semantic knowledge graph that extracts concepts from documents, tracks how well-supported they are, and remembers where sources disagree.

[κ(G)](https://en.wikipedia.org/wiki/Connectivity_(graph_theory)) — vertex connectivity of a graph. The minimum number of connections you'd need to cut before the graph falls apart. A measure of how robust the structure is.

Also kg — the unit of mass. Because knowledge here has weight. Grounding scores measure how heavy an idea is: well-evidenced claims carry more than thin ones. Contested concepts weigh differently than unchallenged ones.

Quick Start

Install Client Tools

The kg CLI, MCP server (for AI assistants), and optional FUSE filesystem:

curl -fsSL https://raw.githubusercontent.com/aaronsb/knowledge-graph-system/main/client-manager.sh | bash

Or just the CLI: npm install -g @aaronsb/kg-cli

Deploy the Platform

Run your own knowledge graph backend:

curl -fsSL https://raw.githubusercontent.com/aaronsb/knowledge-graph-system/main/install.sh | bash

Or from source:

git clone https://github.com/aaronsb/knowledge-graph-system.git
cd knowledge-graph-system
./operator.sh init    # Interactive setup
./operator.sh start   # Start containers

See Quick Start Guide for details.

See It In Action

Interactive graph exploration with smart search, concept clustering, and relationship visualization

![CLI with Inline Image Evidence](docs/media/screenshots/cli-searc

Read from source at commit a1d1bbe985d9OBSERVED · 2026-10-02
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add viz-app --env ACCESS_TOKEN_EXPIRE_MINUTES=${ACCESS_TOKEN_EXPIRE_MINUTES} --env GARAGE_ACCESS_KEY_ID=${GARAGE_ACCESS_KEY_ID} --env GARAGE_SECRET_ACCESS_KEY=${GARAGE_SECRET_ACCESS_KEY} --env KG_API_KEY=${KG_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "viz-app": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ACCESS_TOKEN_EXPIRE_MINUTES": "${ACCESS_TOKEN_EXPIRE_MINUTES}",
        "GARAGE_ACCESS_KEY_ID": "${GARAGE_ACCESS_KEY_ID}",
        "GARAGE_SECRET_ACCESS_KEY": "${GARAGE_SECRET_ACCESS_KEY}",
        "KG_API_KEY": "${KG_API_KEY}"
      }
    }
  }
}
03

Exposed tools (23)

20 read · 1 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
CountreadMaximum number of results to return
DepthreadNumber of hops to traverse (1-5)
DirectionreadOutgoing, incoming, or both directions
ExcludereadHide relationships with these statuses
GroundingreadFetch confidence/reliability score
OntologiesreadList of ontology names to include
OntologyreadOptional filter by ontology/document name
PatternreadText pattern to exclude
QueryreadText to search for in concept labels
SimilarityreadHow closely concepts must match (50-100%)
TargetreadDestination concept (by search or ID)
artifactreadManage saved artifacts (ADR-116). Artifacts persist computed results like search results, projections, and polarity analyses for later recall. Three actions available: -
catalogreadBrowse what is actually stored in the knowledge graph (ADR-501). A deterministic, filesystem-like view of the ontology -> document -> concept hierarchy. Use this to answer
conceptreadWork with concepts: get details (ALL evidence + relationships), find related concepts (neighborhood exploration), or discover connections (paths between concepts). For
documentreadWork with documents: list all, show content, or get concepts (ADR-507). Three actions available: -
epistemic_statusreadVocabulary epistemic status classification (ADR-610 Phase 2). Knowledge validation state for relationship types. Three actions available: -
epochreadRead the graph epoch event log (ADR-203). Every mutation to the knowledge graph (ingestion job, agent reasoning, ontology annealing, manual edit) records a monotonic event with a wall-clock timestamp. This tool exposes that log so you can ask
explore-graphreadLearn how to explore the knowledge graph effectively
graphdestructiveCreate, edit, delete, and list concepts and edges in the knowledge graph (ADR-308). This tool provides deterministic graph editing without going through the LLM ingest pipeline. Use for manual curation, agent-driven knowledge building, and precise graph manipulation. **Actions:** -
ingestwriteIngest content into the knowledge graph: submit text, inspect files, ingest files, or ingest directories. Use action parameter to specify operation.
jobdestructiveManage ingestion jobs: get status, list jobs, approve, cancel, delete, or cleanup. Use action parameter to specify operation.
ontologyreadManage ontologies (knowledge domains/collections): list all, get info, list files, or delete. Use action parameter to specify operation.
searchreadSearch for concepts, source passages, or documents using semantic similarity. Your ENTRY POINT to the graph. CONCEPT SEARCH (type:
04

Trust audit

BLOCKgrade F · trust 23/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (19 observation(s))
Network
declared (6 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
cli/scripts/generate-mcp-docs.mjs:149
const tool = eval(`(${toolStr})`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
cli/src/lib/mcp-allowlist.ts:92
'**/.ssh/**',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
cli/src/lib/mcp-allowlist.ts:96
'**/id_rsa',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
cli/src/lib/mcp-allowlist.ts:97
'**/id_rsa.pub',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
cli/src/lib/mcp-allowlist.ts:98
'**/id_ed25519',
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
cli/src/lib/mcp-allowlist.ts:99
'**/id_ed25519.pub',
Why it matters. touches a credential store
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/architecture/access-workflow/ADR-908-documentation-strategy.md:123
only the trailing pole (`....H` → `....E`) and the number is untouched. The pole
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMInventory / provenance · inv.symlink · CWE-1104
publish-wizard.sh
publish-wizard.sh
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
publish.sh
publish.sh
Why it matters. link not followed
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli/src/cli/admin/utils.ts:53
console.log(); // New line after password input
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli/src/cli/ai-config/utils.ts:30
console.log(); // New line after password input
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli/src/cli/config.ts:118
console.log(); // New line after password input
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
cli/src/cli/oauth.ts:156
console.log(`  Client Secret: ${client.client_secret}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
fuse/kg_fuse/cli.py:803
print(f"  client_secret: {_mask_secret(secret) if secret else '(not set)'}")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
install.sh:2287
test: ["CMD", "wget", "--no-verbose", "--no-check-certificate", "--tries=1", "--spider", "https://127.0.0.1/"]
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
cli/src/cli/admin/utils.ts:158
process.stdout.write(colors.status.success('\n✓ Confirmed! You\'re probably human! 👩💻\n'));
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
operator/admin/ai_safety_confirmation.py:203
sys.stdout.write(f"{Colors.SUCCESS}✓ Confirmed! You're probably human! 👩💻{Colors.NC}\r\n")
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/architecture/ingestion-content/ADR-305.1-multimodal-image-ingestion.md:1446
DATABASE_URL=postgresql://kg_user:securepassword123@localhost:5432/knowledge_graph
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/api/test_auth_dependencies.py:76
token = "invalid_token_format"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/api/test_oauth_utils.py:168
token = "my-secret-token-12345"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/api/test_oauth_utils.py:182
token = "consistent-token-xyz"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
graph, job
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
docs/scripts/doclint.py:284
cfg = yaml.load(f, Loader=_Loader)
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
api/app/lib/gexf_exporter.py:187
hash_val = int(hashlib.md5(ontology.encode()).hexdigest()[:6], 16)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
api/app/lib/mock_ai_provider.py:119
concept_hash = hashlib.md5(sentence.encode()).hexdigest()[:12]

Gates applied: no_behavioural_pass.

Audited 2026-10-02 · audit v0.4.1 · source sha a1d1bbe985d9full audit observations/trust-audit/mcp-server/aaronsb__knowledge-graph-system.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-02a1d1bbe985d9BLOCKF23first audit
06

Questions

What is the knowledge-graph-system MCP server?

Kappa Graph — κ(G). A semantic knowledge graph where knowledge has weight. Extracts concepts, measures grounding strength, preserves disagreement, traces everything to source.

What tools does knowledge-graph-system expose?

23 in total: 20 read-only, 1 that write, and 2 that can delete or overwrite (graph, job). Every one is listed on this page with its risk.

Is knowledge-graph-system safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (23/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does knowledge-graph-system need?

It reads ACCESS_TOKEN_EXPIRE_MINUTES, GARAGE_ACCESS_KEY_ID, GARAGE_SECRET_ACCESS_KEY, KG_API_KEY, KG_OAUTH_CLIENT_ID, KG_OAUTH_CLIENT_SECRET, MAX_EXTRACTION_TOKENS, POSTGRES_PASSWORD, TOKEN_COST_EMBEDDING_SMALL and TOKEN_COST_GPT4O from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does knowledge-graph-system run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as viz-app at 0.0.0.

How current is this page?

The grade is for one exact copy of the source (a1d1bbe985d9), read on 2026-10-02. The repository is watched and re-audited when it changes.

Advertisement