Atlas / MCP servers / ivenkoolab / loci

lociSAFE

mcp/ivenkoolab/loci

A queryable second brain over your scattered notes and docs - hybrid retrieval (vector + BM25), section-level citations, and an MCP server so AI agents can use it. ~300 lines, no LangChain.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
—
Transport
stdio
License
MIT
Stars
100
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](README.md) [](README.zh-CN.md) [](README.zh-TW.md) [](README.ja.md) [](https://gitee.com/IvenKooLab/loci) [](README.ko.md)

[](https://github.com/IvenKooLab/loci/actions/workflows/ci.yml) [](https://glama.ai/mcp/servers/IvenKooLab/loci) [](https://modelscope.cn/mcp/servers/IvenKooLab/loci)

Two thousand years ago, orators stored their speeches in the rooms of a palace and walked through them to remember. loci does the same for your files. Loci is the method behind every memory palace: place knowledge in locations, recall it by walking the path.

A queryable "second brain" for the project docs, notes, and chat logs scattered across a dozen directories — and an MCP server so your AI agents can use it too.

Local files → heading-aware chunking → embeddings → hybrid retrieval (vector + BM25) → LLM answer with section-level citations. The index lives entirely on your machine; only embedding/chat calls go out, to any OpenAI-compatible API (Zhipu / DeepSeek / Kimi / OpenAI / ...).

The thesis (from studying the 90k-star platforms and the graveyard of dead lightweight tools —
Read from source at commit a1d9a344a83dOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add loci-rag -- None loci-rag==0.6.2
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/loci/http_api.py:21
print(f"auth: Authorization: Bearer {token[:8]}...  (full token in config)")
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/loci/graph.py:100
h = hashlib.sha1(content.encode("utf-8")).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/loci/loaders.py:111
return hashlib.sha1(content.encode("utf-8")).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/loci/store.py:110
hashes = [hashlib.sha1(t.encode("utf-8")).hexdigest()[:16] for t in texts]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/test_chunk_reuse.py:33
chashes = [hashlib.sha1(t["text"].encode()).hexdigest()[:16] for t in chunks]
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements-dev.txt
pytest
Why it matters. 1 requirement(s) not pinned with ==
Fix. pin exact versions
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
openai, chromadb
Why it matters. 2 requirement(s) not pinned with ==
Fix. pin exact versions
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha a1d9a344a83dfull audit observations/trust-audit/mcp-server/ivenkoolab__loci.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07a1d9a344a83dSAFEB89first audit
05

Questions

What is the loci MCP server?

A queryable second brain over your scattered notes and docs - hybrid retrieval (vector + BM25), section-level citations, and an MCP server so AI agents can use it. ~300 lines, no LangChain.

Is loci safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does loci need?

It reads BRAIN_EMBED_API_KEY and BRAIN_LLM_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does loci run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as loci-rag.

How current is this page?

The grade is for one exact copy of the source (a1d9a344a83d), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement