KeptCAUTION
Search, archive, and recall your AI conversations. ChatGPT, Claude, Gemini, Grok, Kimi. Local-first, MIT licensed.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Kept saves your AI conversations as local Markdown files, then gives you a desktop app to search, browse, connect, and reuse them.
It works with ChatGPT, Claude, Gemini, Grok, and Kimi. Your archive lives on your machine under ~/.kept/, with an Obsidian-compatible vault plus local indexes for full-text search, topics, projects, and graph views.
Quick Install | Download | Setup | Build from source | MCP server
Why Kept
AI chats often become working memory: debugging trails, research notes, product decisions, prompts, snippets, and half-finished ideas. Most of that history stays inside vendor UIs.
Kept turns it into files you own.
- Plain Markdown, grouped by provider.
- Fast local search with SQLite FTS5.
- Graph and topic views for finding connections across old conversations.
- Optional chat over your own archive using the model provider you configure.
- An MCP server so coding agents can read, search, and manage the vault.
How It Works
Chromium browser extension -> reads conversations from provider API endpoints using your signed-in session -> normalizes messages and supported image assets -> sends them to the Kept desktop app on http://localhost:18241 Kept desktop app -> writes Markdown files to ~/.k
589f2199a7ffOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add kept-vault-server -- npx -y [email protected]
{
"mcpServers": {
"kept-vault-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (34)
27 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Anthropic | read | Claude models for chat and knowledge graph extraction |
OpenAI | read | GPT models for chat and knowledge graph extraction |
OpenRouter | read | Route to 300+ models from any provider |
commit | write | Create a git commit with conventional format |
delete_file | destructive | Delete a file from the vault. Cannot delete directories. |
deploy | write | Deploy to production |
execute_code | write | Run a python, javascript, or shell snippet on the user |
get_neighbors | read | Get all directly connected nodes and edges for a given node ID. |
get_stats | read | Get aggregate statistics about the knowledge graph: entity count, triple count, conversation count, project count, and top entities. |
grep_knowledge_files | read | Search knowledge base files using a regex pattern. Optionally scope to a single file. Returns matching lines with file path and line number. |
grep_vault | read | Regex search across all markdown files in the vault |
highlight_nodes | read | Highlight specific nodes in the knowledge graph view by emitting a frontend event. |
list_conversations | read | List all archived conversations with metadata (title, platform, model, date, message count). Optionally filter by platform. |
list_directory | read | List contents of a directory. |
list_fs_allowed_paths | read | List the filesystem paths the agent is allowed to access. |
list_knowledge_files | read | List all files and directories in the user |
list_nodes | read | List nodes in the knowledge graph, optionally filtered by node type. |
list_vault | read | List all files and directories in the vault root |
move_file | write | Move or rename a file within the vault |
read_conversation | read | Read the full markdown content of a specific conversation by its file path. Use this after searching to read conversations in detail. |
read_file | read | Read a file from the local filesystem (scoped to allowed directories). |
read_image | read | Describe or extract text from an image file. |
read_knowledge_file | read | Read the full text content of a file from the knowledge base. Use list_knowledge_files first to discover available files. |
read_pdf | read | Extract text content from a PDF file (scoped to allowed directories). |
read_web_page | read | Fetch and extract readable text from a public HTTP(S) web page. Use after web_search when a result needs verification or more detail. |
recommend_conversation | read | Recommend a conversation to link to the project. Call this for each relevant conversation you find. |
review | read | Review code changes |
search_conversation_content | read | Full-text search across archived conversations. Optionally filter by platform or title. Returns deduplicated results with cleaned snippets. |
search_conversations | read | Full-text search across all archived conversations. Returns matching conversation titles, snippets, and file paths. Use FTS5 query syntax: simple words are OR |
search_knowledge_files | read | Case-insensitive text search across all knowledge base files. Returns matching lines with file path, line number, and content. |
search_nodes | read | Search for nodes in the knowledge graph by keyword. Returns matching nodes and their edges. |
update_file | destructive | Overwrite an existing file in the vault. Fails if file does not exist. |
web_search | read | Search the public web for current or source-backed information. Returns title, URL, and snippet results. Use this for current events, recent facts, product/library/version lookups, or when the user asks to search the web. |
write_file | write | Create a new file in the vault. Fails if file already exists. |
Trust audit
CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (15 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (19)
icon.icns
console.log("[Kept connect.js] token from meta tag:", token ? token.slice(0, 8) + "..." : "MISSING");.post("http://127.0.0.1:11434/api/chat").post("http://127.0.0.1:11434/api/embeddings").get("http://127.0.0.1:11434/api/tags").get("http://127.0.0.1:11434/api/tags")Ok(_) => log::info!("Kept HTTP server listening on http://127.0.0.1:18241 and http://[::1]:18241"),if (/^[a-zA-Zα-ωΑ-Ω]$/.test(t)) return true;
delete_file, update_file
std::path::PathBuf::from(env!("CARGO_MANIFEST_DIR")).join("../../extension");import { listDirectory, listVault } from '../../src/tools/explore.js';import { deleteFile, moveFile } from '../../src/tools/manage.js';moveFile(tv.vault, { source: 'old.md', destination: '../../escape.md' }),import { readFile } from '../../src/tools/read.js';@crabnebula/tauri-plugin-drag, @fontsource-variable/dm-sans, @fontsource/dm-serif-display, @tauri-apps/api, @tauri-apps/plugin-dialog, @tauri-apps/plugin-opener, @tauri-apps/plugin-process, @tauri-app
@modelcontextprotocol/sdk, fast-glob, zod, @types/node, typescript, vitest
demo.gif
curl -fsSL https://kept.work/install.sh | bash
curl -fsSL https://raw.githubusercontent.com/egroup-labs/kept.work/main/scripts/install.sh | bash
Gates applied: no_behavioural_pass.
589f2199a7fffull audit observations/trust-audit/mcp-server/egroup-labs__kept.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 589f2199a7ff | CAUTION | B | 81 | first audit |
Questions
What is the Kept MCP server?
Search, archive, and recall your AI conversations. ChatGPT, Claude, Gemini, Grok, Kimi. Local-first, MIT licensed.
What tools does Kept expose?
34 in total: 27 read-only, 5 that write, and 2 that can delete or overwrite (delete_file, update_file). Every one is listed on this page with its risk.
Is Kept safe to connect to an agent?
With care. The audit graded it B (81/100) and found 19 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Kept need?
No credential environment variables were found in its source, so it appears to need none.
How does Kept run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as kept-vault-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (589f2199a7ff), read on 2026-10-07. The repository is watched and re-audited when it changes.