Atlas / MCP servers / thewinci / Mimirs

MimirsBLOCK

mcp/thewinci/mimirs

Local MCP server that gives AI coding agents persistent, searchable memory of your codebase

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
31 23r · 6w · 2d
Transport
stdio
License
Apache-2.0
Stars
30
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MIMIRS Named after Mímir, the Norse god of wisdom and knowledge. Persistent project memory for AI coding agents. One command to set up, nothing to maintain.

Your agent starts every session blind — guessing filenames, grepping for keywords, burning context on irrelevant files, and forgetting everything you discussed yesterday.

On one real project, a typical prompt was burning 380K tokens and ~12 seconds end-to-end.

After indexing with mimirs: 91K tokens, ~3 seconds — a 76% drop on that codebase. Your numbers will vary with repo size, query, and model.

No API keys. No cloud. No Docker.Just bun and SQLite.

Semantic Search · Auto-generated Wiki

Cross-session Memory · Dependency Graphs · Annotations

Works with: Claude Code · Cursor · Windsurf · JetBrains (Junie) · GitHub Copilot · any MCP client

Quick start

1. Prerequisites

Bun (curl -fsSL https://bun.sh/install | bash) and, on macOS, a modern SQLite — Apple's bundled one doesn't support extensions:

brew install sqlite

Linux and Windows shi

Read from source at commit 52378594b0c7OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mimirs --env NODE_TLS_REJECT_UNAUTHORIZED=${NODE_TLS_REJECT_UNAUTHORIZED} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mimirs": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "NODE_TLS_REJECT_UNAUTHORIZED": "${NODE_TLS_REJECT_UNAUTHORIZED}"
      }
    }
  }
}
03

Exposed tools (31)

23 read · 6 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
affectedreadGiven changed files (or the working-tree diff against HEAD by default), report the test files that transitively import them — what to run for this change. The interactive counterpart of the
annotatereadAttach a persistent note to a file or symbol that surfaces inline in future read_relevant results. Call this immediately when you encounter: a known bug or race condition, fragile code that shouldn
calleesread
co_changewriteFiles that historically change in the same commit as a given file — logical coupling the import graph can
connect_reporeadConnect another repo
create_checkpointwriteSave a checkpoint so future sessions know what was done and why. REQUIRED: call this as your final step after completing any user-requested task, before responding to the user. Also call when hitting a blocker or changing direction mid-task.
delete_annotationdestructiveRemove an annotation that is no longer relevant — e.g. a bug that was fixed, a constraint that no longer applies, or a note on a deleted file/symbol. Use get_annotations first to find the annotation ID.
dependentsread
depends_onreadList all files that a given file imports (its dependencies). Shows the resolved import graph — what this file actually depends on. This is FILE-level, outward direction. Routing — reverse (files that import this one) is dependents; for a single symbol
file_historywriteGet the commit history for a specific file. Returns commits that touched the file, sorted by date (newest first). Faster than git log for indexed repositories.
get_annotationsreadRetrieve persistent notes attached to files or symbols. Pass path to get all notes for a file. Pass query to search semantically across all annotations. Pass both to filter by file and rank by relevance.
git_contextreadShow git context for the working tree: uncommitted changes annotated with index status, recent commits, and changed files. Use this at the start of a session to understand what has already been modified before searching or editing.
impactreadSymbol-level blast radius: the transitive callers of a function or method as a pruned call tree, plus the test files to run for the change. More precise than dependents (which is file-level). Use before changing a signature or behavior. Pass
index_filesreadIndex files in a directory for semantic search. Without patterns, indexes the project from config and prunes deleted or now-excluded files. With patterns, refreshes or expands only matching files and leaves the rest of the index untouched.
index_statusreadShow the current state of the RAG index for a project directory.
list_checkpointsreadList conversation checkpoints, most recent first. Cross-session by default.
project_mapreadVisualize how files relate to each other — imports, exports, and fan-in/fan-out. Faster than reading import statements across many files. Use
read_conversationread
read_relevantread
remove_filedestructiveRemove a specific file from the RAG index.
searchreadSearch the full codebase by meaning — finds files that grep misses. Use natural language (
search_analyticsreadShow search usage analytics: query counts, zero-result queries, low-relevance queries, top searched terms.
search_checkpointsreadSemantic search over checkpoint titles and summaries.
search_commitswriteSemantically search git commit history. Use this to find why code was changed, when decisions were made, or what an author worked on. Returns commits ranked by relevance to the query.
search_conversationreadSearch through conversation history. Finds past decisions, discussions, and tool outputs from current or previous sessions.
search_symbolsread
server_inforeadShow the current MCP server configuration: resolved project directory, database location, index status, embedding model, active config, and all currently connected databases.
tracereadShow how one symbol reaches another: the connecting call sub-graph from
usagesreadFind call sites and references to a symbol across indexed files — with file paths, line numbers, and matching lines. Resolves aliased imports: searching the original name finds call sites that import it under an alias (
wikiwriteRun the wiki rebuild workflow. The
write_relevantwriteFind the best file and location to insert new code or docs. Returns semantically appropriate insertion points with anchors for precise placement. Use this before adding a new function to find which file and position it belongs in.
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (1 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (19)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/cli/index.ts:58
mimirs eval <file> [--dir D]      Run A/B eval (with/without RAG)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/config/index.ts:139
"**/id_rsa", "**/id_dsa", "**/id_ecdsa", "**/id_ed25519",
Why it matters. touches a credential store
HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/config/index.ts:140
"**/.npmrc", "**/.pgpass", "**/.netrc",
Why it matters. touches a credential store
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
src/embeddings/embed.ts:44
process.env.NODE_TLS_REJECT_UNAUTHORIZED = "0";
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_annotation, remove_file
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
benchmarks/contextbench/cb-leakcheck.ts:42
if (flags.length) { console.log(`\nsuspect (query names gold token absent from the bug report):`); for (const l of flags) console.log(l); }
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
benchmarks/contextbench/ab-runner.ts:20
import { RagDB } from "../../src/db";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
benchmarks/contextbench/ab-runner.ts:21
import { loadConfig } from "../../src/config";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
benchmarks/contextbench/ab-runner.ts:22
import { search, searchChunks } from "../../src/search/hybrid";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
benchmarks/contextbench/arena-score.ts:8
import { RagDB } from "../../src/db";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
benchmarks/contextbench/arena-score.ts:9
import { loadConfig } from "../../src/config";
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
benchmarks/contextbench/knee-probe.ts:75
const mark = i === kneeIdx ? " <-KNEE" : i === maxDropIdx ? " <-maxΔ" : i === maxRelIdx ? " <-maxΔ%" : "";
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
benchmarks/contextbench/knee-probe.ts:85
for (const [name, cut] of [["knee", kneeIdx + 1], ["maxΔ", maxDropIdx + 1], ["maxΔ%", maxRelIdx + 1]] as [string, number][]) {
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@huggingface/transformers, @modelcontextprotocol/sdk, @winci/bun-chunk, graphology, graphology-communities-louvain, gray-matter, sqlite-vec, zod
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
wiki/architecture.md:3
mimirs is a local code-RAG engine: it indexes a project's files into a SQLite database, embeds the chunks, and answers semantic and graph queries against them. The same engine ships in two shapes. A o
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
wiki/runtime-lifecycle.md:65
When the lock is held, the server kicks off `indexDirectory(...)` **without awaiting it**, so boot returns and the index builds in the background while tools are already answerable (`src/server/index.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
wiki/server/start.md:72
`registerAllTools` is a thin fan-out: it wraps the server in a friendly-error proxy, then calls one `registerXTools(server, getDB, ...)` per group — search, indexing, graph, conversation, checkpoints,
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:351
read — common secret patterns like `.env`, `*.pem`, `*.key`, and SSH keys are
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:40
[Bun](https://bun.sh) (`curl -fsSL https://bun.sh/install | bash`) and, on macOS, a modern SQLite — Apple's bundled one doesn't support extensions:

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 52378594b0c7full audit observations/trust-audit/mcp-server/thewinci__mimirs.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0852378594b0c7BLOCKD69first audit
06

Questions

What is the Mimirs MCP server?

Local MCP server that gives AI coding agents persistent, searchable memory of your codebase

What tools does Mimirs expose?

31 in total: 23 read-only, 6 that write, and 2 that can delete or overwrite (delete_annotation, remove_file). Every one is listed on this page with its risk.

Is Mimirs safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Mimirs need?

It reads NODE_TLS_REJECT_UNAUTHORIZED from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Mimirs run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mimirs at 1.8.0.

How current is this page?

The grade is for one exact copy of the source (52378594b0c7), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement