The LibrarianSAFE
Skill librarian MCP server — every installed skill costs tokens; the librarian keeps your whole collection out of agent context. Agents ask, get the few right skills for the task, and their outcomes curate the collection. Fully local: Ollama + SQLite + optional Apple Intelligence.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A skill librarian MCP server — your agents stop carrying the whole skill collection in context and start asking for the one right book.
How it started
One question in a chat:
"I'm sure you know better than the internet what you need to get better. What's the best workflow with Claude Code? Installing skills and just you pick the best? More the better? Less is more?"
The answer: less is more. Every installed skill costs tokens and adds triggering ambiguity — with 50 skills, descriptions overlap and the wrong one fires; with 8 sharp ones, triggering is nearly deterministic.
But the collection had ~3,000. So instead of installing any of them: give the collection a librarian.
find_skill(intent)→ librarian recommends- agent uses the skill, does the work
report_outcome(skill, worked: true/false, note)→ librarian logs it
"The poetic part: the librarian is itself the curation loop. Log every query and what got picked vs ignored — skills that never surface are your kill candidates, queries that match nothing are your gaps. The collection optimizes itself from its own usage data."
"So the full shape: SQLite (skills, embeddings, query log, outcome log) + FastMCP + two read tools + one write tool. Maybe 300 lines of Python. It's small, it's one thing, and it compounds."
It's ~600 lines now. Scope creep found even the librarian. The original conversation — typed poolside on a phone, typos preserved on purpose — is in ORIGIN.md.
What it is
A local-first MCP server that acts as a **libra
940a77489db3OBSERVED · 2026-10-09Exposed tools (5)
5 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
librarian_brainstorm | read | Surface a wide, diverse spread of skills for ideation — not convergence. |
librarian_find | read | Recommend the best skills in the collection for a stated intent. |
librarian_reindex | read | Rescan the skills directory, embed new/changed SKILL.md files, prune deleted ones. |
librarian_report | read | Report whether a recommended skill actually worked. Append-only. |
librarian_stats | read | Digest of collection health for curation decisions. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
940a77489db3full audit observations/trust-audit/mcp-server/aka-kika__the-librarian.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 940a77489db3 | SAFE | B | 89 | first audit |
Questions
What is the The Librarian MCP server?
Skill librarian MCP server — every installed skill costs tokens; the librarian keeps your whole collection out of agent context. Agents ask, get the few right skills for the task, and their outcomes curate the collection. Fully local: Ollama + SQLite + optional Apple Intelligence.
What tools does The Librarian expose?
5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is The Librarian safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does The Librarian need?
No credential environment variables were found in its source, so it appears to need none.
How does The Librarian run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (940a77489db3), read on 2026-10-09. The repository is watched and re-audited when it changes.