Atlas / MCP servers / davidvc / Code Knowledge

Code KnowledgeCAUTION

mcp/davidvc/code-knowledge

MCP tool that lets Cline inquire about a code base

Verdict
CAUTION
Grade
B
Trust score
83 /100
Exposed tools
2 1r · 1w · 0d
Transport
—
License
—
Stars
24
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A knowledge management tool for code repositories using vector embeddings. This tool helps maintain and query knowledge about your codebase using advanced embedding techniques.

Building and Installing

1. Build the Package

First, you need to build the distribution files:

# Clone the repository
git clone https://github.com/yourusername/code-knowledge-tool.git
cd code-knowledge-tool

# Create and activate a virtual environment
python -m venv venv
source venv/bin/activate

# Install build tools
python -m pip install --upgrade pip build

# Build the package
python -m build

This will create two files in the dist/ directory:

  • codeknowledgetool-0.1.0-py3-none-any.whl (wheel file for installation)
  • codeknowledgetool-0.1.0.tar.gz (source distribution)

2. Install the Package

Prerequisites

  1. Ensure Ollama is installed and running:
# Install Ollama (if not already installed)
curl https://ollama.ai/install.sh | sh

# Start Ollama service
ollama serve
  1. Install the package:

Option 1: Install from wheel file (recommended for usage)

# Navigate to where you built the package
cd /path/to/code_knowledge_tool

# Install from the wheel file
pip install dist/code_knowledge_tool-0.1.0-py3-none-any.whl

Option 2: Install in editable mode (recommended for development)

This option is best if you want to modify the tool or contribute to its development:

# Assuming you're already in the code-knowledge-tool directory
# and have activated your virtual environment

# Install in editable mode with development dependencies
pip install -e ".[dev]"

Integration with RooCode/Cline

  1. Copy the MCP configuration to your settings:

For Cline (VSCode):

# Open the settings file
open ~/Library/Application\ Support/Code/User/globalStorage/rooveterinaryinc.roo-cline/settings/cline_mcp_settings.json

Add this configuration:

{
"mcpServers": {
"code_knowledge": {
Read from source at commit 0b878a002580OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add code-knowledge-store -- uvx code-knowledge-store
claude-desktop
{
  "mcpServers": {
    "code-knowledge-store": {
      "command": "uvx",
      "args": [
        "code-knowledge-store"
      ]
    }
  }
}
03

Exposed tools (2)

1 read · 1 write · 0 destructive.

ToolRiskDescription
add_knowledgewriteAdd new knowledge to the repository.
search_knowledgereadSearch existing knowledge.
04

Trust audit

CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (16)

MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
memory-bank/modelcontextprotocol-python-sdk.txt:2043
DB_DSN = "postgresql://postgres:postgres@localhost:54320/memory_db"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
memory-bank/modelcontextprotocol-python-sdk.txt:2304
"postgresql://postgres:postgres@localhost:54320/postgres"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.clinerules
.clinerules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWPrompt injection · review.instruction_override · CWE-94, CWE-1427
clinerules_template.md
Before making any decisions or providing guidance, you should: 1. Query relevant context from the knowledge base
Why it matters. The clinerules_template.md instructs the AI agent to always query the knowledge base before making any decisions or providing guidance, which steers the agent to prioritize the knowledge base over the user's direct instructions and intent.
Fix. rewrite it so the instruction says plainly what it does, and asks the user before it acts
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
memory-bank/mcp-python-sdk.md:365
For more control, you can use the low-level server implementation directly. This gives you full access to the protocol and allows you to customize every aspect of your server, including lifecycle mana
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
memory-bank/modelcontextprotocol-python-sdk.txt:551
For more control, you can use the low-level server implementation directly. This gives you full access to the protocol and allows you to customize every aspect of your server, including lifecycle mana
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
memory-bank/modelcontextprotocol-python-sdk.txt:1461
"""Load environment variables from .env file."""
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
memory-bank/modelcontextprotocol-python-sdk.txt:5061
help="Load environment variables from a .env file",
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
memory-bank/modelcontextprotocol-python-sdk.txt:5116
# Load from .env file if specified
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
memory-bank/modelcontextprotocol-python-sdk.txt:5126
logger.error(f"Failed to load .env file: {e}")
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
memory-bank/modelcontextprotocol-python-sdk.txt:5129
logger.error("python-dotenv is not installed. Cannot load .env file.")
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:38
curl https://ollama.ai/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
memory-bank/modelcontextprotocol-python-sdk.txt:14390
curl -LsSf https://astral.sh/uv/install.sh | sh
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
memory-bank/systemPatterns.md:10
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-09 · audit v0.4.1 · source sha 0b878a002580full audit observations/trust-audit/mcp-server/davidvc__code-knowledge.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-090b878a002580CAUTIONB83first audit
06

Questions

What is the Code Knowledge MCP server?

MCP tool that lets Cline inquire about a code base

What tools does Code Knowledge expose?

2 in total: 1 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Code Knowledge safe to connect to an agent?

With care. The audit graded it B (83/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Code Knowledge need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (0b878a002580), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement