Atlas / MCP servers / lcbcfoo / Heimdall

HeimdallCAUTION

mcp/lcbcfoo/heimdall-1

Your AI Coding Assistant's Long-Term Memory

Verdict
CAUTION
Grade
B
Trust score
84 /100
Exposed tools
6 4r · 0w · 2d
Transport
stdio
License
—
Stars
105
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pypi.org/project/heimdall-mcp/) [](hhttps://github.com/lcbcFoo/heimdall-mcp-server/blob/main/README.mdttps://opensource.org/licenses/Apache-2.0) [](https://modelcontextprotocol.io/) [](https://youtu.be/7X1gntAXsao)

The Problem: Your AI coding assistant has short-lived memory. Every chat session starts from a blank slate.

The Solution: Heimdall gives your LLM a persistent, growing, cognitive memory of your specific codebase, lessons and memories carry over time.

https://github.com/user-attachments/assets/120b3d32-72d1-4d42-b3ab-285e8a711981

Key Features

  • 🧠 Context-Rich Memory: Heimdall learns from your documentation, session insights, and development history, allowing your LLM to recall specific solutions and architectural patterns across conversations.
  • 📚 Git-Aware Context: It indexes your project's entire git history, understanding not just what changed, but also who changed it, when, and context.
  • 🔗 Isolated & Organized: Each project gets its own isolated memory space, ensuring that context from one project doesn't leak into another.
  • ⚡ Efficient Integration: Built on the Model Context Protocol (MCP), it provides a standardized, low-overhead way for LLMs to access this powerful memory.

🚀 Getting Started

Prerequisites: Python 3.11+ and Docker (for Qdrant vector database).

Heimdall provides a unified heimdall CLI that manages everything from project setup to MCP integration.

1. Install Heimdall

pip install heimdall-mcp

This installs the heimdall command-line tool with all ne

Read from source at commit 69b93b124f51OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add heimdall-mcp --env MAX_TOKENS_PER_CHUNK=${MAX_TOKENS_PER_CHUNK} --env QDRANT_API_KEY=${QDRANT_API_KEY} -- uvx heimdall-mcp
claude-desktop
{
  "mcpServers": {
    "heimdall-mcp": {
      "command": "uvx",
      "args": [
        "heimdall-mcp"
      ],
      "env": {
        "MAX_TOKENS_PER_CHUNK": "${MAX_TOKENS_PER_CHUNK}",
        "QDRANT_API_KEY": "${QDRANT_API_KEY}"
      }
    }
  }
}
03

Exposed tools (6)

4 read · 0 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
delete_memories_by_tagsdestructiveDelete all memories that have any of the specified tags. Provides preview for safety.
delete_memorydestructiveDelete a single memory by its ID. Provides preview of what will be deleted for safety.
memory_statusreadGet cognitive memory system health and statistics
recall_memoriesreadRetrieve memories based on query with rich contextual information
session_lessonsreadCapture and consolidate key learnings from current session for future reference. This tool encourages metacognitive reflection - thinking about what you
store_memoryreadStore new experiences or knowledge in cognitive memory for future recall
04

Trust audit

CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (4 observation(s))
Shell
declared (2 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (12)

MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
heimdall/cognitive_system/health_checker.py:219
module = __import__(package.replace("-", "_"))
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_memories_by_tags, delete_memory
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_git_history_miner.py:69
"../../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_git_security.py:58
"../../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_git_security.py:59
"repo/../../../secret",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_git_security.py:60
"valid/path/../../etc/passwd",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_git_security.py:61
"/valid/path/../../../etc",
INFOInventory / provenance · inv.oversize · CWE-1104
cognitive_memory/data/models/all-MiniLM-L6-v2.onnx
cognitive_memory/data/models/all-MiniLM-L6-v2.onnx
Why it matters. 90417949 bytes not read
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/progress/004_phase1_interfaces.md:233
- [x] CLI provides full access to cognitive memory operations

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha 69b93b124f51full audit observations/trust-audit/mcp-server/lcbcfoo__heimdall-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0769b93b124f51CAUTIONB84first audit
06

Questions

What is the Heimdall MCP server?

Your AI Coding Assistant's Long-Term Memory

What tools does Heimdall expose?

6 in total: 4 read-only, 0 that write, and 2 that can delete or overwrite (delete_memories_by_tags, delete_memory). Every one is listed on this page with its risk.

Is Heimdall safe to connect to an agent?

With care. The audit graded it B (84/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Heimdall need?

It reads MAX_TOKENS_PER_CHUNK and QDRANT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Heimdall run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as heimdall-mcp.

How current is this page?

The grade is for one exact copy of the source (69b93b124f51), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement