Atlas / MCP servers / aka-kika / The Librarian

The LibrarianSAFE

mcp/aka-kika/the-librarian

Skill librarian MCP server — every installed skill costs tokens; the librarian keeps your whole collection out of agent context. Agents ask, get the few right skills for the task, and their outcomes curate the collection. Fully local: Ollama + SQLite + optional Apple Intelligence.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
5 5r · 0w · 0d
Transport
stdio
License
MIT
Stars
42
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A skill librarian MCP server — your agents stop carrying the whole skill collection in context and start asking for the one right book.

How it started

One question in a chat:

"I'm sure you know better than the internet what you need to get better. What's the best workflow with Claude Code? Installing skills and just you pick the best? More the better? Less is more?"

The answer: less is more. Every installed skill costs tokens and adds triggering ambiguity — with 50 skills, descriptions overlap and the wrong one fires; with 8 sharp ones, triggering is nearly deterministic.

But the collection had ~3,000. So instead of installing any of them: give the collection a librarian.

  • find_skill(intent) → librarian recommends
  • agent uses the skill, does the work
  • report_outcome(skill, worked: true/false, note) → librarian logs it
"The poetic part: the librarian is itself the curation loop. Log every query and what got picked vs ignored — skills that never surface are your kill candidates, queries that match nothing are your gaps. The collection optimizes itself from its own usage data."
"So the full shape: SQLite (skills, embeddings, query log, outcome log) + FastMCP + two read tools + one write tool. Maybe 300 lines of Python. It's small, it's one thing, and it compounds."

It's ~600 lines now. Scope creep found even the librarian. The original conversation — typed poolside on a phone, typos preserved on purpose — is in ORIGIN.md.

What it is

A local-first MCP server that acts as a **libra

Read from source at commit 940a77489db3OBSERVED · 2026-10-09
02

Exposed tools (5)

5 read · 0 write · 0 destructive.

ToolRiskDescription
librarian_brainstormreadSurface a wide, diverse spread of skills for ideation — not convergence.
librarian_findreadRecommend the best skills in the collection for a stated intent.
librarian_reindexreadRescan the skills directory, embed new/changed SKILL.md files, prune deleted ones.
librarian_reportreadReport whether a recommended skill actually worked. Append-only.
librarian_statsreadDigest of collection health for curation decisions.
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 940a77489db3full audit observations/trust-audit/mcp-server/aka-kika__the-librarian.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09940a77489db3SAFEB89first audit
05

Questions

What is the The Librarian MCP server?

Skill librarian MCP server — every installed skill costs tokens; the librarian keeps your whole collection out of agent context. Agents ask, get the few right skills for the task, and their outcomes curate the collection. Fully local: Ollama + SQLite + optional Apple Intelligence.

What tools does The Librarian expose?

5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is The Librarian safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does The Librarian need?

No credential environment variables were found in its source, so it appears to need none.

How does The Librarian run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (940a77489db3), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement