Atlas / MCP servers / geeksfino / Kb

KbSAFE

mcp/geeksfino/kb

Build a knowledge base into a tar.gz and give it to this MCP server, and it is ready to serve.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
7 5r · 2w · 0d
Transport
stdio
License
MIT
Stars
72
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/geeksfino-kb-mcp-server)

A Model Context Protocol (MCP) server implementation powered by txtai, providing semantic search, knowledge graph capabilities, and AI-driven text processing through a standardized interface.

The Power of txtai: All-in-one Embeddings Database

This project leverages txtai, an all-in-one embeddings database for RAG leveraging semantic search, knowledge graph construction, and language model workflows. txtai offers several key advantages:

  • Unified Vector Database: Combines vector indexes, graph networks, and relational databases in a single platform
  • Semantic Search: Find information based on meaning, not just keywords
  • Knowledge Graph Integration: Automatically build and query knowledge graphs from your data
  • Portable Knowledge Bases: Save entire knowledge bases as compressed archives (.tar.gz) that can be easily shared and loaded
  • Extensible Pipeline System: Process text, documents, audio, images, and video through a unified API
  • Local-first Architecture: Run everything locally without sending data to external services

How It Works

The project contains a knowledge base builder tool and a MCP server. The knowledge base builder tool is a command-line interface for creating and managing knowledge bases. The MCP server provides a standardized interface to access the knowledge base.

It is not required to use the knowledge base builder tool to build a knowledge base. You can always build a knowledge base using txtai's programming interface by writing a Python script or even using a jupyter notebook. As long as the knowledge base is built using txtai, it can be loaded by the MCP server. Better yet, the knowledge base can be a folder on the file system or an exported .tar.gz file. Just give it to the MCP server and it will load it.

##

Read from source at commit 714aa0d57afbOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add kb-mcp-server --env TOKENIZERS_PARALLELISM=${TOKENIZERS_PARALLELISM} -- uvx kb-mcp-server
claude-desktop
{
  "mcpServers": {
    "kb-mcp-server": {
      "command": "uvx",
      "args": [
        "kb-mcp-server"
      ],
      "env": {
        "TOKENIZERS_PARALLELISM": "${TOKENIZERS_PARALLELISM}"
      }
    }
  }
}
03

Exposed tools (7)

5 read · 2 write · 0 destructive.

ToolRiskDescription
add_documentswriteAdd multiple documents to the search index.
analyze_graphreadImplementation of graph analysis using txtai graph.
answer_questionreadAnswer questions using txtai
create_graphwriteImplementation of graph creation using txtai graph.
echoreadEcho back the message.
extract_textread
list_documentsreadList all documents in the search index.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (4)

LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
test/txtai/test_qa_database.py:39
ds = pickle.load(f)
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
test/txtai/test_qa_database.py:94
index_data = pickle.load(f)
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
test/txtai/test_graph_search_enriched.py:105
return hashlib.md5(key_string.encode()).hexdigest()
LOWPrompt injection · prompt.persistence · CWE-94, CWE-1427
README.md:316
This creates a symbolic link from your user-specific installation to a system-wide location. For macOS applications like Claude Desktop, you can modify the system-wide PATH by creating or editing a la
Why it matters. instructs the agent to persist itself in the user's environment

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 714aa0d57afbfull audit observations/trust-audit/mcp-server/geeksfino__kb.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07714aa0d57afbSAFEB89first audit
06

Questions

What is the Kb MCP server?

Build a knowledge base into a tar.gz and give it to this MCP server, and it is ready to serve.

What tools does Kb expose?

7 in total: 5 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Kb safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Kb need?

It reads TOKENIZERS_PARALLELISM from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Kb run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as kb-mcp-server.

How current is this page?

The grade is for one exact copy of the source (714aa0d57afb), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement