KollektivBLOCK
Kollektiv MCP enables you to chat with and query your own documents directly from IDEs and MCP clients. Private, secure, and integrated into your favorite code editor
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
🚨 IMPORTANT: This experimental MCP server is now DEPRECATED and will be shut down soon. For updates, visit kollektiv.sh Please do not use this server for new projects.
&replace=%241&logo=typescript&label=TypeScript) [](https://workers.cloudflare.com/) [](https://supabase.io/) [](https://github.com/alexander-zuev/kollektiv-mcp/actions) [](https://codecov.io/gh/alexander-zuev/kollektiv-mcp) [](LICENSE)
~~🧠 Your personal LLM knowledgebase~~ (DEPRECATED)
[Original Description - No longer maintained] Kollektiv MCP enables you to build personal LLM knowledge base in seconds and use it from your favorite editor / client. No more infrastructure setup, chunking, syncing - just upload your data and start chatting. Supports all major MCP clients out of the box - Cursor, Windsurf, Claude Desktop, etc.
⚠️ Deprecation Notice
This experimental MCP server is DEPRECATED and will be shut down soon. The service endpoints may stop working at any time without notice.
Do not use this for new projects or production use.
💿 Connection (DEPRECATED - MAY NOT WORK)
The simplest way to connect to Kollektiv MCP is to copy & paste the following configuration into your editor's mcp.json file. All clien
d5c4475b8e3aOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add kollektiv-mcp -- npx -y [email protected]
{
"mcpServers": {
"kollektiv-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
list_uploaded_documents | read | Returns the list of documents current user has previously uploaded to Kollektiv. |
Trust audit
BLOCKgrade F · trust 56/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
exec(query: string): Promise<D1ExecResult>;
import { testSession, testUser } from "../../../mocks";import {createMockContext} from "../../../mocks/hono-mocks";atob(data: string): string;
declare function atob(data: string): string;
@cloudflare/workers-oauth-provider, @radix-ui/colors, @supabase/ssr, @supabase/supabase-js, agents, ajv, camelcase-keys, hono
load_dotenv() # load environment variables from .env
This creates the beginnings of a .NET console application that can read the API key from user secrets.
Your own methods can access the Agent's environment variables and bindings on `this.env`, state on `this.setState`, and call other methods on the Agent via `this.yourMethodName`.
- Return only `newProps` to update both the grant and access token (the access token inherits these
another service and wants to match its access token TTL to the upstream access token TTL. This helps
curl -LsSf https://astral.sh/uv/install.sh | sh
bMVTbqpg&code_challenge_method=S256&redirect_uri=http%3A%2 F%2Fexp.azraelxuemo.cn%3A9876%2Foauth%2Fcallback 4. Start a http server to receive the code Python3 - m http.server 9876 5. Send th
Client->>+Server: POST InitializedNotification<br>Mcp-Session-Id: 1868a90c...
Client->>+Server: POST ... request ...<br>Mcp-Session-Id: 1868a90c...
Client->>+Server: POST ... notification/response ...<br>Mcp-Session-Id: 1868a90c...
The Model Context Protocol uses [a subset of OAuth 2.1 for authorization](https://spec.modelcontextprotocol.io/specification/draft/basic/authorization/). OAuth allows your users to grant limited acces
cf-output/VGChartz 2024.md
docs/workers-llm.txt
Gates applied: no_behavioural_pass.
d5c4475b8e3afull audit observations/trust-audit/mcp-server/alexander-zuev__kollektiv.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d5c4475b8e3a | BLOCK | F | 56 | first audit |
Questions
What is the Kollektiv MCP server?
Kollektiv MCP enables you to chat with and query your own documents directly from IDEs and MCP clients. Private, secure, and integrated into your favorite code editor
What tools does Kollektiv expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Kollektiv safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (56/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Kollektiv need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (d5c4475b8e3a), read on 2026-10-07. The repository is watched and re-audited when it changes.