KindexCAUTION
Knowledge index that learns from your conversations
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.python.org/downloads/) [](LICENSE) [](https://github.com/wandercom/kindex/releases) [](https://pypi.org/project/kindex/) [](https://mcpmarket.com/server/kindex) [](https://github.com/wandercom/kindex/actions/workflows/ci.yml) [](#install-as-agent-mcp-plugin)
Every agent is smart inside its own silo. Kindex lets them work together.
Kindex does one thing. It knows what you know.
Claude Code, Codex, Gemini CLI, Google Antigravity, OpenCode, Cursor, and other MCP-capable agents each remember for themselves, and none of them can read the others. Kindex is the local knowledge graph they all read and write: continuity across sessions and restarts, handoffs between vendors, shared decisions and constraints, and live coordination while several of them work at once. Available as a free MCP plugin or standalone CLI.
Memory plugins capture what happened. Kindex captures what it means and how it connects. Most memory tools are session archives with search. Kindex is a weighted knowledge graph with typed nodes, provenance, and decay, that surfaces constraints and decisions and manages exactly how much context to inject based on your available token budget.
Kindex is the index for an individual and a codebase: your own graph, and the repository's git-tracked .kin/. Kinbase is the company product above it, in development: engineering direction, architecture, standards, ownership, and history, held by named authorities and composed into every coding session
cc838013698fOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add kindex -- pipx kindex==0.48.1
Exposed tools (3)
3 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
memory | read | Search this repository |
scope_info | read | Report this server |
task | read | Kindex durable repo task service: tasks live in this worktree |
Trust audit
CAUTIONgrade D · trust 61/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (4 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
grammar_mod = importlib.import_module(pkg)
ollama_url: str = "http://127.0.0.1:11434"
CANARY = "sk-ant-api03-INVALID-SYNTHETIC-CREDENTIAL-" + "x" * 32
secret = "SYNTHETIC_PRIVATE_NOTIFICATION_CONTENT_932"
TOKEN = "stateproofsearchtoken"
pem = "-----BEGIN RSA PRIVATE KEY-----\nMIIEowIBAAKCAQEA1234567890abcdef\nZXhhbXBsZWtleWJvZHk=\n-----END RSA PRIVATE KEY-----"
("-----BEGIN PRIVATE KEY-----\nsynthetic-secret\n-----END PRIVATE KEY-----", "concept"),"-----BEGIN PRIVATE KEY-----\nsynthetic-key-data\n-----END PRIVATE KEY-----",
.architecture-review-kindex-three-products.md
ci = yaml.load(
release = yaml.load(
f"sys.exit(getattr(importlib.import_module({module!r}), {function!r})())"return hashlib.sha1(value.encode("utf-8")).hexdigest()[:16]return hashlib.sha1(value.encode("utf-8")).hexdigest()[:length]workspace_id = hashlib.md5(str(b.project.resolve()).encode()).hexdigest()
"name: app\ninherits:\n - ../../template/.kin/config\n"
"name: child\ndomains: [specific]\ninherits:\n - ../../.kin/config\n"
referent="http://../../outside-secret", referent_scope="file")
for index, value in enumerate(("../escaped", "../../escaped")):ollama_url: http://127.0.0.1:11434
self.base_url = "http://127.0.0.1:" + str(self.server_address[1])
assert defaults["ollama_url"] == "http://127.0.0.1:11434"
"https://127.0.0.1:11434",
assert answer_mod.input_cap(AskConfig(verify=False, max_input_tokens=0, verify_input_tokens=9000)) is None
signer = bytes.fromhex(doc["signer"])
Gates applied: no_behavioural_pass.
cc838013698ffull audit observations/trust-audit/mcp-server/jmcentire__kindex.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | cc838013698f | CAUTION | D | 61 | first audit |
Questions
What is the Kindex MCP server?
Knowledge index that learns from your conversations
What tools does Kindex expose?
3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Kindex safe to connect to an agent?
With care. The audit graded it D (61/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Kindex need?
It reads LINEAR_API_KEY and MYSERVICE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Kindex run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as kindex.
How current is this page?
The grade is for one exact copy of the source (cc838013698f), read on 2026-10-09. The repository is watched and re-audited when it changes.