Code KnowledgeCAUTION
MCP tool that lets Cline inquire about a code base
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A knowledge management tool for code repositories using vector embeddings. This tool helps maintain and query knowledge about your codebase using advanced embedding techniques.
Building and Installing
1. Build the Package
First, you need to build the distribution files:
# Clone the repository git clone https://github.com/yourusername/code-knowledge-tool.git cd code-knowledge-tool # Create and activate a virtual environment python -m venv venv source venv/bin/activate # Install build tools python -m pip install --upgrade pip build # Build the package python -m build
This will create two files in the dist/ directory:
- codeknowledgetool-0.1.0-py3-none-any.whl (wheel file for installation)
- codeknowledgetool-0.1.0.tar.gz (source distribution)
2. Install the Package
Prerequisites
- Ensure Ollama is installed and running:
# Install Ollama (if not already installed) curl https://ollama.ai/install.sh | sh # Start Ollama service ollama serve
- Install the package:
Option 1: Install from wheel file (recommended for usage)
# Navigate to where you built the package cd /path/to/code_knowledge_tool # Install from the wheel file pip install dist/code_knowledge_tool-0.1.0-py3-none-any.whl
Option 2: Install in editable mode (recommended for development)
This option is best if you want to modify the tool or contribute to its development:
# Assuming you're already in the code-knowledge-tool directory # and have activated your virtual environment # Install in editable mode with development dependencies pip install -e ".[dev]"
Integration with RooCode/Cline
- Copy the MCP configuration to your settings:
For Cline (VSCode):
# Open the settings file open ~/Library/Application\ Support/Code/User/globalStorage/rooveterinaryinc.roo-cline/settings/cline_mcp_settings.json
Add this configuration:
{
"mcpServers": {
"code_knowledge": {
0b878a002580OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add code-knowledge-store -- uvx code-knowledge-store
{
"mcpServers": {
"code-knowledge-store": {
"command": "uvx",
"args": [
"code-knowledge-store"
]
}
}
}Exposed tools (2)
1 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add_knowledge | write | Add new knowledge to the repository. |
search_knowledge | read | Search existing knowledge. |
Trust audit
CAUTIONgrade B · trust 83/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (16)
DB_DSN = "postgresql://postgres:postgres@localhost:54320/memory_db"
"postgresql://postgres:postgres@localhost:54320/postgres"
.clinerules
.gitmodules
Before making any decisions or providing guidance, you should: 1. Query relevant context from the knowledge base
For more control, you can use the low-level server implementation directly. This gives you full access to the protocol and allows you to customize every aspect of your server, including lifecycle mana
For more control, you can use the low-level server implementation directly. This gives you full access to the protocol and allows you to customize every aspect of your server, including lifecycle mana
"""Load environment variables from .env file."""
help="Load environment variables from a .env file",
# Load from .env file if specified
logger.error(f"Failed to load .env file: {e}")logger.error("python-dotenv is not installed. Cannot load .env file.")curl https://ollama.ai/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass, no_license.
0b878a002580full audit observations/trust-audit/mcp-server/davidvc__code-knowledge.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 0b878a002580 | CAUTION | B | 83 | first audit |
Questions
What is the Code Knowledge MCP server?
MCP tool that lets Cline inquire about a code base
What tools does Code Knowledge expose?
2 in total: 1 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Code Knowledge safe to connect to an agent?
With care. The audit graded it B (83/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Code Knowledge need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (0b878a002580), read on 2026-10-09. The repository is watched and re-audited when it changes.