Atlas / MCP servers / egroup-labs / Kept

KeptCAUTION

mcp/egroup-labs/kept

Search, archive, and recall your AI conversations. ChatGPT, Claude, Gemini, Grok, Kimi. Local-first, MIT licensed.

Verdict
CAUTION
Grade
B
Trust score
81 /100
Exposed tools
34 27r · 5w · 2d
Transport
stdio
License
MIT
Stars
144
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Kept saves your AI conversations as local Markdown files, then gives you a desktop app to search, browse, connect, and reuse them.

It works with ChatGPT, Claude, Gemini, Grok, and Kimi. Your archive lives on your machine under ~/.kept/, with an Obsidian-compatible vault plus local indexes for full-text search, topics, projects, and graph views.

Quick Install | Download | Setup | Build from source | MCP server

Why Kept

AI chats often become working memory: debugging trails, research notes, product decisions, prompts, snippets, and half-finished ideas. Most of that history stays inside vendor UIs.

Kept turns it into files you own.

  • Plain Markdown, grouped by provider.
  • Fast local search with SQLite FTS5.
  • Graph and topic views for finding connections across old conversations.
  • Optional chat over your own archive using the model provider you configure.
  • An MCP server so coding agents can read, search, and manage the vault.

How It Works

Chromium browser extension
-> reads conversations from provider API endpoints using your signed-in session
-> normalizes messages and supported image assets
-> sends them to the Kept desktop app on http://localhost:18241

Kept desktop app
-> writes Markdown files to ~/.k
Read from source at commit 589f2199a7ffOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add kept-vault-server -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "kept-vault-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (34)

27 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AnthropicreadClaude models for chat and knowledge graph extraction
OpenAIreadGPT models for chat and knowledge graph extraction
OpenRouterreadRoute to 300+ models from any provider
commitwriteCreate a git commit with conventional format
delete_filedestructiveDelete a file from the vault. Cannot delete directories.
deploywriteDeploy to production
execute_codewriteRun a python, javascript, or shell snippet on the user
get_neighborsreadGet all directly connected nodes and edges for a given node ID.
get_statsreadGet aggregate statistics about the knowledge graph: entity count, triple count, conversation count, project count, and top entities.
grep_knowledge_filesreadSearch knowledge base files using a regex pattern. Optionally scope to a single file. Returns matching lines with file path and line number.
grep_vaultreadRegex search across all markdown files in the vault
highlight_nodesreadHighlight specific nodes in the knowledge graph view by emitting a frontend event.
list_conversationsreadList all archived conversations with metadata (title, platform, model, date, message count). Optionally filter by platform.
list_directoryreadList contents of a directory.
list_fs_allowed_pathsreadList the filesystem paths the agent is allowed to access.
list_knowledge_filesreadList all files and directories in the user
list_nodesreadList nodes in the knowledge graph, optionally filtered by node type.
list_vaultreadList all files and directories in the vault root
move_filewriteMove or rename a file within the vault
read_conversationreadRead the full markdown content of a specific conversation by its file path. Use this after searching to read conversations in detail.
read_filereadRead a file from the local filesystem (scoped to allowed directories).
read_imagereadDescribe or extract text from an image file.
read_knowledge_filereadRead the full text content of a file from the knowledge base. Use list_knowledge_files first to discover available files.
read_pdfreadExtract text content from a PDF file (scoped to allowed directories).
read_web_pagereadFetch and extract readable text from a public HTTP(S) web page. Use after web_search when a result needs verification or more detail.
recommend_conversationreadRecommend a conversation to link to the project. Call this for each relevant conversation you find.
reviewreadReview code changes
search_conversation_contentreadFull-text search across archived conversations. Optionally filter by platform or title. Returns deduplicated results with cleaned snippets.
search_conversationsreadFull-text search across all archived conversations. Returns matching conversation titles, snippets, and file paths. Use FTS5 query syntax: simple words are OR
search_knowledge_filesreadCase-insensitive text search across all knowledge base files. Returns matching lines with file path, line number, and content.
search_nodesreadSearch for nodes in the knowledge graph by keyword. Returns matching nodes and their edges.
update_filedestructiveOverwrite an existing file in the vault. Fails if file does not exist.
web_searchreadSearch the public web for current or source-backed information. Returns title, URL, and snippet results. Use this for current events, recent facts, product/library/version lookups, or when the user asks to search the web.
write_filewriteCreate a new file in the vault. Fails if file already exists.
04

Trust audit

CAUTIONgrade B · trust 81/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (15 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (19)

MEDIUMInventory / provenance · inv.binary · CWE-1104
app/src-tauri/icons/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
extension/connect.js:27
console.log("[Kept connect.js] token from meta tag:", token ? token.slice(0, 8) + "..." : "MISSING");
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
app/src-tauri/src/commands.rs:1458
.post("http://127.0.0.1:11434/api/chat")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
app/src-tauri/src/commands.rs:1944
.post("http://127.0.0.1:11434/api/embeddings")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
app/src-tauri/src/commands.rs:3763
.get("http://127.0.0.1:11434/api/tags")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
app/src-tauri/src/commands.rs:3833
.get("http://127.0.0.1:11434/api/tags")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
app/src-tauri/src/server.rs:692
Ok(_) => log::info!("Kept HTTP server listening on http://127.0.0.1:18241 and http://[::1]:18241"),
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
app/src/components/MarkdownRenderer.tsx:27
if (/^[a-zA-Zα-ωΑ-Ω]$/.test(t)) return true;
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_file, update_file
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
app/src-tauri/src/commands.rs:918
std::path::PathBuf::from(env!("CARGO_MANIFEST_DIR")).join("../../extension");
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp/tests/tools/explore.test.ts:2
import { listDirectory, listVault } from '../../src/tools/explore.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp/tests/tools/manage.test.ts:4
import { deleteFile, moveFile } from '../../src/tools/manage.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp/tests/tools/manage.test.ts:63
moveFile(tv.vault, { source: 'old.md', destination: '../../escape.md' }),
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp/tests/tools/read.test.ts:2
import { readFile } from '../../src/tools/read.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
app/package.json
@crabnebula/tauri-plugin-drag, @fontsource-variable/dm-sans, @fontsource/dm-serif-display, @tauri-apps/api, @tauri-apps/plugin-dialog, @tauri-apps/plugin-opener, @tauri-apps/plugin-process, @tauri-app
Why it matters. 37 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp/package.json
@modelcontextprotocol/sdk, fast-glob, zod, @types/node, typescript, vitest
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
demo.gif
demo.gif
Why it matters. 12437371 bytes not read
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:72
curl -fsSL https://kept.work/install.sh | bash
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:84
curl -fsSL https://raw.githubusercontent.com/egroup-labs/kept.work/main/scripts/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 589f2199a7fffull audit observations/trust-audit/mcp-server/egroup-labs__kept.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07589f2199a7ffCAUTIONB81first audit
06

Questions

What is the Kept MCP server?

Search, archive, and recall your AI conversations. ChatGPT, Claude, Gemini, Grok, Kimi. Local-first, MIT licensed.

What tools does Kept expose?

34 in total: 27 read-only, 5 that write, and 2 that can delete or overwrite (delete_file, update_file). Every one is listed on this page with its risk.

Is Kept safe to connect to an agent?

With care. The audit graded it B (81/100) and found 19 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Kept need?

No credential environment variables were found in its source, so it appears to need none.

How does Kept run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as kept-vault-server at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (589f2199a7ff), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement