CaeluneCAUTION
Caelune (凯露恩) — Local-first retrieval for private Markdown, PDF, and Tika documents, with a Windows desktop app and read-only MCP server.|本地优先的私人知识检索工具。
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A local-first Windows desktop app and read-only MCP server for searching private Markdown, PDF, and Tika-backed knowledge bases.
[](https://github.com/EllisMorrow/Caelune/releases/latest) [](https://github.com/EllisMorrow/Caelune/releases/latest) [](#privacy-boundary) [](https://registry.modelcontextprotocol.io/v0/servers?search=io.github.EllisMorrow/caelune-mcp) [](https://github.com/EllisMorrow/Caelune/releases) [](LICENSE)
Download Windows app · 中文说明 · Website · User Wiki · MCP Setup
What Caelune does
Caelune builds searchable indexes from knowledge you already keep on your own computer. It combines exact-text retrieval, structural signals, semantic vector search, optional reranking, and source-aware context assembly.
The desktop app manages data roots, Runtime components, models, knowledge-base builds, live watch, queries, and result review. The optional MCP server exposes the same retrieval core to MCP-capable AI clients through two read-only tools.
86e1b38b7924OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add caelune -- uvx caelune
{
"mcpServers": {
"caelune": {
"command": "uvx",
"args": [
"caelune"
]
}
}
}Trust audit
CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (7 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (17)
importlib.import_module(module_name)
module = importlib.import_module(str(probe['import_name']))
submodule = importlib.import_module(str(submodule_name))
url = f'http://127.0.0.1:{port}{HEALTHCHECK_PATH}'url = f'http://127.0.0.1:{port}{request_path}'.nojekyll
digest = hashlib.sha1(normalized.lower().encode("utf-8")).hexdigest()[:10]content_hash=hashlib.sha1(raw_bytes).hexdigest(),
digest = hashlib.sha1(f'{source_path}|{page_no}|{position}|{text}'.encode('utf-8', errors='ignore')).hexdigest()[:20]content_hash = hashlib.sha1(hash_payload.encode('utf-8', errors='ignore')).hexdigest()file_hash = hashlib.sha1(text.encode("utf-8")).hexdigest()url='http://127.0.0.1:9998/tika',
with patch('omniclip_rag.extensions.runtimes.tika_runtime.urllib.request.urlopen', side_effect=urllib.error.HTTPError('http://127.0.0.1:9998/tika', 405, 'Method Not Allowed', {}, None)):lancedb, onnxruntime, sentence-transformers, transformers, huggingface-hub, modelscope, pyinstaller, pypdf
docs/assets/caelune-local-search-flow.png
docs/assets/social-preview.png
Gates applied: no_behavioural_pass.
86e1b38b7924full audit observations/trust-audit/mcp-server/ellismorrow__caelune.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 86e1b38b7924 | CAUTION | C | 75 | first audit |
Questions
What is the Caelune MCP server?
Caelune (凯露恩) — Local-first retrieval for private Markdown, PDF, and Tika documents, with a Windows desktop app and read-only MCP server.|本地优先的私人知识检索工具。
Is Caelune safe to connect to an agent?
With care. The audit graded it C (75/100) and found 17 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Caelune need?
No credential environment variables were found in its source, so it appears to need none.
How does Caelune run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as caelune.
How current is this page?
The grade is for one exact copy of the source (86e1b38b7924), read on 2026-10-08. The repository is watched and re-audited when it changes.