Atlas / MCP servers / jmcentire / Kindex

KindexCAUTION

mcp/jmcentire/kindex

Knowledge index that learns from your conversations

Verdict
CAUTION
Grade
D
Trust score
61 /100
Exposed tools
3 3r · 0w · 0d
Transport
stdio
License
MIT
Stars
35
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.python.org/downloads/) [](LICENSE) [](https://github.com/wandercom/kindex/releases) [](https://pypi.org/project/kindex/) [](https://mcpmarket.com/server/kindex) [](https://github.com/wandercom/kindex/actions/workflows/ci.yml) [](#install-as-agent-mcp-plugin)

Every agent is smart inside its own silo. Kindex lets them work together.

Kindex does one thing. It knows what you know.

Claude Code, Codex, Gemini CLI, Google Antigravity, OpenCode, Cursor, and other MCP-capable agents each remember for themselves, and none of them can read the others. Kindex is the local knowledge graph they all read and write: continuity across sessions and restarts, handoffs between vendors, shared decisions and constraints, and live coordination while several of them work at once. Available as a free MCP plugin or standalone CLI.

Memory plugins capture what happened. Kindex captures what it means and how it connects. Most memory tools are session archives with search. Kindex is a weighted knowledge graph with typed nodes, provenance, and decay, that surfaces constraints and decisions and manages exactly how much context to inject based on your available token budget.

Kindex is the index for an individual and a codebase: your own graph, and the repository's git-tracked .kin/. Kinbase is the company product above it, in development: engineering direction, architecture, standards, ownership, and history, held by named authorities and composed into every coding session

Read from source at commit cc838013698fOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add kindex -- pipx kindex==0.48.1
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
memoryreadSearch this repository
scope_inforeadReport this server
taskreadKindex durable repo task service: tasks live in this worktree
04

Trust audit

CAUTIONgrade D · trust 61/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (4 observation(s))
Shell
declared (4 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/kindex/adapters/code.py:81
grammar_mod = importlib.import_module(pkg)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/kindex/config.py:591
ollama_url: str = "http://127.0.0.1:11434"
MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/test_privacy.py:19
CANARY = "sk-ant-api03-INVALID-SYNTHETIC-CREDENTIAL-" + "x" * 32
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/supervisor_acceptance/test_notifications.py:255
secret = "SYNTHETIC_PRIVATE_NOTIFICATION_CONTENT_932"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_trusted_search.py:22
TOKEN = "stateproofsearchtoken"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/test_answer.py:956
pem = "-----BEGIN RSA PRIVATE KEY-----\nMIIEowIBAAKCAQEA1234567890abcdef\nZXhhbXBsZWtleWJvZHk=\n-----END RSA PRIVATE KEY-----"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/test_kinbase_submissions.py:168
("-----BEGIN PRIVATE KEY-----\nsynthetic-secret\n-----END PRIVATE KEY-----", "concept"),
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/test_privacy.py:44
"-----BEGIN PRIVATE KEY-----\nsynthetic-key-data\n-----END PRIVATE KEY-----",
LOWInventory / provenance · inv.hidden_file · CWE-1104
.architecture-review-kindex-three-products.md
.architecture-review-kindex-three-products.md
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tests/test_ci_workflow.py:10
ci = yaml.load(
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
tests/test_ci_workflow.py:14
release = yaml.load(
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_mcp_lite.py:516
f"sys.exit(getattr(importlib.import_module({module!r}), {function!r})())"
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/kindex/attention.py:79
return hashlib.sha1(value.encode("utf-8")).hexdigest()[:16]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/kindex/code_map.py:33
return hashlib.sha1(value.encode("utf-8")).hexdigest()[:length]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
tests/supervisor_acceptance/test_health_cursor_native.py:21
workspace_id = hashlib.md5(str(b.project.resolve()).encode()).hexdigest()
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_cron_reliability.py:401
"name: app\ninherits:\n  - ../../template/.kin/config\n"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_kin_inheritance.py:262
"name: child\ndomains: [specific]\ninherits:\n  - ../../.kin/config\n"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_mcp_lite.py:300
referent="http://../../outside-secret", referent_scope="file")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_v8_config_seam.py:440
for index, value in enumerate(("../escaped", "../../escaped")):
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/supervisor-health.md:330
ollama_url: http://127.0.0.1:11434
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_ollama_review_contract.py:109
self.base_url = "http://127.0.0.1:" + str(self.server_address[1])
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_ollama_review_contract.py:328
assert defaults["ollama_url"] == "http://127.0.0.1:11434"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/test_ollama_review_contract.py:372
"https://127.0.0.1:11434",
LOWNetwork egress · net.tls_off · CWE-200, CWE-319
tests/test_ask_review_fixes.py:42
assert answer_mod.input_cap(AskConfig(verify=False, max_input_tokens=0, verify_input_tokens=9000)) is None
Why it matters. certificate verification is disabled
Fix. leave verification on
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/kindex/kinbase.py:146
signer = bytes.fromhex(doc["signer"])

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha cc838013698ffull audit observations/trust-audit/mcp-server/jmcentire__kindex.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09cc838013698fCAUTIOND61first audit
06

Questions

What is the Kindex MCP server?

Knowledge index that learns from your conversations

What tools does Kindex expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Kindex safe to connect to an agent?

With care. The audit graded it D (61/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Kindex need?

It reads LINEAR_API_KEY and MYSERVICE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Kindex run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as kindex.

How current is this page?

The grade is for one exact copy of the source (cc838013698f), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement