SwarmVaultCAUTION
The local-first LLM Wiki: open-source knowledge graph builder, RAG knowledge base, and agent memory store. Built on Andrej Karpathy's pattern. An Obsidian alternative for personal knowledge management, AI second brain, and durable Claude Code / Codex / OpenClaw memory.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Languages: English | 简体中文 | 日本語
[](https://www.npmjs.com/package/@swarmvaultai/cli) [](https://www.npmjs.com/package/@swarmvaultai/cli) [](https://github.com/swarmclawai/swarmvault) [](LICENSE) []()
The local-first LLM Wiki, knowledge graph builder, and RAG knowledge base for AI agents. SwarmVault turns docs, code, transcripts, notes, and URLs into a durable markdown wiki plus a local graph you can inspect, query, and hand to agents. Start with one command, then learn the deeper graph, review, context-pack, and automation workflows when you need them.
Documentation on the website is currently English-first. If wording drifts between translations, README.md is the canonical source.
Try It in 30 Seconds
npm install -g @swarmvaultai/cli swarmvault quickstart ./your-repo
quickstart initializes a vault in the current directory, ingests a local file, directory, or public GitHub repo, compiles the wiki and graph, writes share artifacts, and opens the local graph viewer. It is the beginner-friendly alias for swarmvault scan.
No repo handy?
swarmvault demo
After your first compile, the most useful next commands are:
swarmvault next swarmvault query "What are the key concepts?" swarmvault graph serve swarmvault doctor swarmvault candidate list
Not sure what state the vault is in? swarmvault next is read-only and tells you whether to initialize, ingest, compile, query, review, or refresh.

53 read · 5 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
API | read | The visible API node. |
Alpha | read | Alpha concept. |
Governance | read | Governance concept from schema-aware provider. |
Queue | read | A queue connecting the API and worker. |
SwarmVault | read | Project entity |
archive_candidate | read | |
auto_promote_candidates | read | |
blast_radius | read | |
build_context_pack | read | |
cluster_graph | read | |
compile_vault | read | |
consolidate | read | |
doctor_retrieval | read | |
doctor_vault | read | |
finish_memory_task | read | |
finish_task | read | |
get_community | read | |
get_hyperedges | read | |
get_neighbors | read | |
get_node | read | |
god_nodes | read | |
graph_callers | read | |
graph_report | read | |
graph_stats | read | |
graph_status | read | |
ingest_input | read | |
javascript | read | javascript |
lint_vault | read | |
list_approvals | read | |
list_context_packs | read | |
list_memory_tasks | read | |
list_sources | read | |
list_tasks | read | |
migrate | read | |
preview_candidate_scores | read | |
promote_candidate | read | |
query_graph | read | |
query_vault | read | |
read_approval | read | |
read_context_pack | read | |
read_memory_task | read | |
read_page | read | |
read_task | read | |
rebuild_retrieval | read | |
resume_memory_task | read | |
resume_task | read | |
retrieval_status | read | |
review_decision | read | |
search_pages | read | |
shortest_path | read | |
start_memory_task | write | |
start_task | write | |
swarmvault | read | SwarmVault graph-first workflow. Use to read the compiled wiki and query the knowledge graph before broad file search. |
update_graph | write | |
update_memory_task | write | |
update_task | write | |
watch_status | read | |
workspace_info | read |
Trust audit
CAUTIONgrade B · trust 80/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (22)
"UEsDBBQAAAAIAPiQiFzT44oSCAEAAC0CAAATAAAAW0NvbnRlbnRfVHlwZXNdLnhtbJVRS07DMBDd9xSWtyhxYIEQStIFnyV0UQ4wciaJhX/yuKW9PZMWAkItUpfW+/pNvdw5K7aYyATfyOuykgK9Dp3xQyPf1s/FnRSUwXdgg8dG7pHksl3U631EEiz21Mgx53ivFOk
"second: AKIAJKLMNOPQRSTUVWXY",
const password = "swarmvault-neo4j-password";
.createHash("sha1")const labelHash = createHash("sha1").update(label).digest("hex").slice(0, 10);const viewerDistDir = path.basename(moduleDir) === "src" ? path.resolve(moduleDir, "../../viewer/dist") : path.resolve(moduleDir, "viewer");
const viewerDistDir = path.resolve(path.dirname(fileURLToPath(import.meta.url)), "../../viewer/dist");
import { rewriteCitations } from "../../src/citations/rewrite";import type { PageIdIndex } from "../../src/workspace/page-id-index";import { CliRunner } from "../../src/cli/run";"baseUrl": "http://127.0.0.1:11434/v1",
const requestUrl = request.url ? new URL(request.url, "http://127.0.0.1") : null;
baseUrl: `http://127.0.0.1:${port}`,const requestUrl = request.url ? new URL(request.url, "http://127.0.0.1") : null;
baseUrl: `http://127.0.0.1:${address.port}`,"UEsDBBQAAAAIAPiQiFzT44oSCAEAAC0CAAATAAAAW0NvbnRlbnRfVHlwZXNdLnhtbJVRS07DMBDd9xSWtyhxYIEQStIFnyV0UQ4wciaJhX/yuKW9PZMWAkItUpfW+/pNvdw5K7aYyATfyOuykgK9Dp3xQyPf1s/FnRSUwXdgg8dG7pHksl3U631EEiz21Mgx53ivFOk
"UEsDBBQAAAAIAPiQiFzT44oSCAEAAC0CAAATAAAAW0NvbnRlbnRfVHlwZXNdLnhtbJVRS07DMBDd9xSWtyhxYIEQStIFnyV0UQ4wciaJhX/yuKW9PZMWAkItUpfW+/pNvdw5K7aYyATfyOuykgK9Dp3xQyPf1s/FnRSUwXdgg8dG7pHksl3U631EEiz21Mgx53ivFOk
@biomejs/biome, @evilmartians/lefthook, playwright, typescript
commander, @types/node, tsup, vitest
@asciidoctor/core, @modelcontextprotocol/sdk, @mozilla/readability, @retorquere/bibtex-parser, @vscode/tree-sitter-wasm, chokidar, compromise, csv-parse
@types/node, esbuild, obsidian, tslib, typescript, vitest
cytoscape, highlight.js, react, react-dom, react-markdown, rehype-highlight, rehype-slug, remark-gfm
Gates applied: no_behavioural_pass.
9deacba06845full audit observations/trust-audit/mcp-server/swarmclawai__swarmvault.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-28 | 9deacba06845 | CAUTION | B | 80 | first audit |
Questions
What is the SwarmVault MCP server?
The local-first LLM Wiki: open-source knowledge graph builder, RAG knowledge base, and agent memory store. Built on Andrej Karpathy's pattern. An Obsidian alternative for personal knowledge management, AI second brain, and durable Claude Code / Codex / OpenClaw memory.
What tools does SwarmVault expose?
58 in total: 53 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is SwarmVault safe to connect to an agent?
With care. The audit graded it B (80/100) and found 22 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does SwarmVault need?
It reads ANTHROPIC_API_KEY, CEREBRAS_API_KEY, GEMINI_API_KEY, GOOGLE_API_KEY, GROQ_API_KEY, OLLAMA_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY, SWARMVAULT_TEST_NEO4J_PASSWORD, TOGETHER_API_KEY and XAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does SwarmVault run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as large-repo-example at 0.0.0.
How current is this page?
The grade is for one exact copy of the source (9deacba06845), read on 2026-09-28. The repository is watched and re-audited when it changes.