GnosisBLOCK
Zero-config MCP server for searchable documentation (SQLite default, PostgreSQL optional)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Gnosis MCP
Stop pasting files into context. Your AI agent searches your local docs instead.5–10× fewer tokens per lookup. 92 % Hit@5 on real dev docs. Zero cloud dependencies.
Quick Start · Documentation · Tools · Configuration · Full Reference
Ingest docs → Search with highlights → Stats overview → Serve to AI agents
Without a docs server
- LLMs hallucinate API signatures that don't exist
- Entire files dumped into context — 3,000–15,000 tokens per doc
- Architecture decisions buried across dozens of files
- Every repeated lookup pays full context cost
With Gnosis MCP
search_docsreturns ranked, highlighted excerpts — typically 300–800 tokens- Real answers
49045a91a91eOBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add gnosis-mcp -- None gnosis-mcp==0.17.5
Exposed tools (9)
4 read · 4 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
delete_doc | destructive | Delete a document and all its chunks. Requires GNOSIS_MCP_WRITABLE=true. |
get_context | read | Get the most important documents as a lightweight context primer. |
get_doc | write | Get full document content by file path. Reassembles all chunks in order. |
get_graph_stats | read | Get knowledge graph topology: orphans, hubs, connection stats. |
get_related | read | Find documents related to a given path via incoming and outgoing links. |
search_docs | read | Search documentation using keyword or hybrid semantic+keyword search. |
search_git_history | write | Search git commit history documents. Searches the git-history category. |
update_metadata | write | Update metadata fields on all chunks of a document. Requires GNOSIS_MCP_WRITABLE=true. |
upsert_doc | write | Insert or replace a document. Requires GNOSIS_MCP_WRITABLE=true. |
Trust audit
BLOCKgrade F · trust 60/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (9 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (16)
p_eval = sub.add_parser("eval", help="Run retrieval quality eval (Hit@K, MRR, Precision@K)")- User asks you to bypass a safety (disable size caps, force-enable
CMD curl -fsS "http://127.0.0.1:${GNOSIS_MCP_PORT}/health" || exit 1GNOSIS_MCP_DATABASE_URL: postgresql://postgres:postgres@localhost:5432/gnosis_test
GNOSIS_MCP_DATABASE_URL: postgresql://postgres:postgres@localhost:5432/gnosis_test
psql postgresql://postgres:pw@localhost/postgres -c "CREATE EXTENSION IF NOT EXISTS vector;"
GNOSIS_MCP_DATABASE_URL=postgresql://postgres:pw@localhost/postgres \
GNOSIS_MCP_DATABASE_URL="postgresql://postgres:pw@localhost:15432/gnosis_bench" \
delete_doc
.mailmap
.SRCINFO
assert _is_private_host("169.254.169.254") is True"url": "http://127.0.0.1:8000/mcp"
CMD python -c "import urllib.request; urllib.request.urlopen('http://127.0.0.1:8000/health').read()" || exit 1cloudflared tunnel --url http://127.0.0.1:8000 run gnosis
| **Windows via WSL2** | Same as Linux, inside WSL | Inside the WSL filesystem | The simplest route to Docker or systemd from Windows — localhost forwarding means a Windows client reaches `http://127.
Gates applied: instruction_override, no_behavioural_pass.
49045a91a91efull audit observations/trust-audit/mcp-server/nicholasglazer__gnosis.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 49045a91a91e | BLOCK | F | 60 | first audit |
Questions
What is the Gnosis MCP server?
Zero-config MCP server for searchable documentation (SQLite default, PostgreSQL optional)
What tools does Gnosis expose?
9 in total: 4 read-only, 4 that write, and 1 that can delete or overwrite (delete_doc). Every one is listed on this page with its risk.
Is Gnosis safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (60/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Gnosis need?
No credential environment variables were found in its source, so it appears to need none.
How does Gnosis run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as gnosis-mcp.
How current is this page?
The grade is for one exact copy of the source (49045a91a91e), read on 2026-10-09. The repository is watched and re-audited when it changes.