HeimdallCAUTION
Your AI Coding Assistant's Long-Term Memory
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://pypi.org/project/heimdall-mcp/) [](hhttps://github.com/lcbcFoo/heimdall-mcp-server/blob/main/README.mdttps://opensource.org/licenses/Apache-2.0) [](https://modelcontextprotocol.io/) [](https://youtu.be/7X1gntAXsao)
The Problem: Your AI coding assistant has short-lived memory. Every chat session starts from a blank slate.
The Solution: Heimdall gives your LLM a persistent, growing, cognitive memory of your specific codebase, lessons and memories carry over time.
https://github.com/user-attachments/assets/120b3d32-72d1-4d42-b3ab-285e8a711981
Key Features
- 🧠 Context-Rich Memory: Heimdall learns from your documentation, session insights, and development history, allowing your LLM to recall specific solutions and architectural patterns across conversations.
- 📚 Git-Aware Context: It indexes your project's entire git history, understanding not just what changed, but also who changed it, when, and context.
- 🔗 Isolated & Organized: Each project gets its own isolated memory space, ensuring that context from one project doesn't leak into another.
- ⚡ Efficient Integration: Built on the Model Context Protocol (MCP), it provides a standardized, low-overhead way for LLMs to access this powerful memory.
🚀 Getting Started
Prerequisites: Python 3.11+ and Docker (for Qdrant vector database).
Heimdall provides a unified heimdall CLI that manages everything from project setup to MCP integration.
1. Install Heimdall
pip install heimdall-mcp
This installs the heimdall command-line tool with all ne
69b93b124f51OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add heimdall-mcp --env MAX_TOKENS_PER_CHUNK=${MAX_TOKENS_PER_CHUNK} --env QDRANT_API_KEY=${QDRANT_API_KEY} -- uvx heimdall-mcp{
"mcpServers": {
"heimdall-mcp": {
"command": "uvx",
"args": [
"heimdall-mcp"
],
"env": {
"MAX_TOKENS_PER_CHUNK": "${MAX_TOKENS_PER_CHUNK}",
"QDRANT_API_KEY": "${QDRANT_API_KEY}"
}
}
}
}Exposed tools (6)
4 read · 0 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
delete_memories_by_tags | destructive | Delete all memories that have any of the specified tags. Provides preview for safety. |
delete_memory | destructive | Delete a single memory by its ID. Provides preview of what will be deleted for safety. |
memory_status | read | Get cognitive memory system health and statistics |
recall_memories | read | Retrieve memories based on query with rich contextual information |
session_lessons | read | Capture and consolidate key learnings from current session for future reference. This tool encourages metacognitive reflection - thinking about what you |
store_memory | read | Store new experiences or knowledge in cognitive memory for future recall |
Trust audit
CAUTIONgrade B · trust 84/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (4 observation(s))
- Shell
- declared (2 observation(s))
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (12)
module = __import__(package.replace("-", "_"))delete_memories_by_tags, delete_memory
.env.template
.pre-commit-config.yaml
"../../../etc/passwd",
"../../../etc/passwd",
"repo/../../../secret",
"valid/path/../../etc/passwd",
"/valid/path/../../../etc",
cognitive_memory/data/models/all-MiniLM-L6-v2.onnx
- [x] CLI provides full access to cognitive memory operations
Gates applied: no_behavioural_pass, no_license.
69b93b124f51full audit observations/trust-audit/mcp-server/lcbcfoo__heimdall-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 69b93b124f51 | CAUTION | B | 84 | first audit |
Questions
What is the Heimdall MCP server?
Your AI Coding Assistant's Long-Term Memory
What tools does Heimdall expose?
6 in total: 4 read-only, 0 that write, and 2 that can delete or overwrite (delete_memories_by_tags, delete_memory). Every one is listed on this page with its risk.
Is Heimdall safe to connect to an agent?
With care. The audit graded it B (84/100) and found 12 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Heimdall need?
It reads MAX_TOKENS_PER_CHUNK and QDRANT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Heimdall run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as heimdall-mcp.
How current is this page?
The grade is for one exact copy of the source (69b93b124f51), read on 2026-10-07. The repository is watched and re-audited when it changes.