lociSAFE
A queryable second brain over your scattered notes and docs - hybrid retrieval (vector + BM25), section-level citations, and an MCP server so AI agents can use it. ~300 lines, no LangChain.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](README.md) [](README.zh-CN.md) [](README.zh-TW.md) [](README.ja.md) [](https://gitee.com/IvenKooLab/loci) [](README.ko.md)
[](https://github.com/IvenKooLab/loci/actions/workflows/ci.yml) [](https://glama.ai/mcp/servers/IvenKooLab/loci) [](https://modelscope.cn/mcp/servers/IvenKooLab/loci)
Two thousand years ago, orators stored their speeches in the rooms of a palace and walked through them to remember. loci does the same for your files. Loci is the method behind every memory palace: place knowledge in locations, recall it by walking the path.
A queryable "second brain" for the project docs, notes, and chat logs scattered across a dozen directories — and an MCP server so your AI agents can use it too.
Local files → heading-aware chunking → embeddings → hybrid retrieval (vector + BM25) → LLM answer with section-level citations. The index lives entirely on your machine; only embedding/chat calls go out, to any OpenAI-compatible API (Zhipu / DeepSeek / Kimi / OpenAI / ...).
The thesis (from studying the 90k-star platforms and the graveyard of dead lightweight tools —
a1d9a344a83dOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add loci-rag -- None loci-rag==0.6.2
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
print(f"auth: Authorization: Bearer {token[:8]}... (full token in config)")h = hashlib.sha1(content.encode("utf-8")).hexdigest()return hashlib.sha1(content.encode("utf-8")).hexdigest()hashes = [hashlib.sha1(t.encode("utf-8")).hexdigest()[:16] for t in texts]chashes = [hashlib.sha1(t["text"].encode()).hexdigest()[:16] for t in chunks]
pytest
openai, chromadb
Gates applied: no_behavioural_pass.
a1d9a344a83dfull audit observations/trust-audit/mcp-server/ivenkoolab__loci.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | a1d9a344a83d | SAFE | B | 89 | first audit |
Questions
What is the loci MCP server?
A queryable second brain over your scattered notes and docs - hybrid retrieval (vector + BM25), section-level citations, and an MCP server so AI agents can use it. ~300 lines, no LangChain.
Is loci safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does loci need?
It reads BRAIN_EMBED_API_KEY and BRAIN_LLM_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does loci run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as loci-rag.
How current is this page?
The grade is for one exact copy of the source (a1d9a344a83d), read on 2026-10-07. The repository is watched and re-audited when it changes.