MimirsBLOCK
Local MCP server that gives AI coding agents persistent, searchable memory of your codebase
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
MIMIRS Named after Mímir, the Norse god of wisdom and knowledge. Persistent project memory for AI coding agents. One command to set up, nothing to maintain.
Your agent starts every session blind — guessing filenames, grepping for keywords, burning context on irrelevant files, and forgetting everything you discussed yesterday.
On one real project, a typical prompt was burning 380K tokens and ~12 seconds end-to-end.
After indexing with mimirs: 91K tokens, ~3 seconds — a 76% drop on that codebase. Your numbers will vary with repo size, query, and model.
No API keys. No cloud. No Docker.Just bun and SQLite.
Semantic Search · Auto-generated Wiki
Cross-session Memory · Dependency Graphs · Annotations
Works with: Claude Code · Cursor · Windsurf · JetBrains (Junie) · GitHub Copilot · any MCP client
Quick start
1. Prerequisites
Bun (curl -fsSL https://bun.sh/install | bash) and, on macOS, a modern SQLite — Apple's bundled one doesn't support extensions:
brew install sqlite
Linux and Windows shi
52378594b0c7OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mimirs --env NODE_TLS_REJECT_UNAUTHORIZED=${NODE_TLS_REJECT_UNAUTHORIZED} -- npx -y [email protected]{
"mcpServers": {
"mimirs": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"NODE_TLS_REJECT_UNAUTHORIZED": "${NODE_TLS_REJECT_UNAUTHORIZED}"
}
}
}
}Exposed tools (31)
23 read · 6 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
affected | read | Given changed files (or the working-tree diff against HEAD by default), report the test files that transitively import them — what to run for this change. The interactive counterpart of the |
annotate | read | Attach a persistent note to a file or symbol that surfaces inline in future read_relevant results. Call this immediately when you encounter: a known bug or race condition, fragile code that shouldn |
callees | read | |
co_change | write | Files that historically change in the same commit as a given file — logical coupling the import graph can |
connect_repo | read | Connect another repo |
create_checkpoint | write | Save a checkpoint so future sessions know what was done and why. REQUIRED: call this as your final step after completing any user-requested task, before responding to the user. Also call when hitting a blocker or changing direction mid-task. |
delete_annotation | destructive | Remove an annotation that is no longer relevant — e.g. a bug that was fixed, a constraint that no longer applies, or a note on a deleted file/symbol. Use get_annotations first to find the annotation ID. |
dependents | read | |
depends_on | read | List all files that a given file imports (its dependencies). Shows the resolved import graph — what this file actually depends on. This is FILE-level, outward direction. Routing — reverse (files that import this one) is dependents; for a single symbol |
file_history | write | Get the commit history for a specific file. Returns commits that touched the file, sorted by date (newest first). Faster than git log for indexed repositories. |
get_annotations | read | Retrieve persistent notes attached to files or symbols. Pass path to get all notes for a file. Pass query to search semantically across all annotations. Pass both to filter by file and rank by relevance. |
git_context | read | Show git context for the working tree: uncommitted changes annotated with index status, recent commits, and changed files. Use this at the start of a session to understand what has already been modified before searching or editing. |
impact | read | Symbol-level blast radius: the transitive callers of a function or method as a pruned call tree, plus the test files to run for the change. More precise than dependents (which is file-level). Use before changing a signature or behavior. Pass |
index_files | read | Index files in a directory for semantic search. Without patterns, indexes the project from config and prunes deleted or now-excluded files. With patterns, refreshes or expands only matching files and leaves the rest of the index untouched. |
index_status | read | Show the current state of the RAG index for a project directory. |
list_checkpoints | read | List conversation checkpoints, most recent first. Cross-session by default. |
project_map | read | Visualize how files relate to each other — imports, exports, and fan-in/fan-out. Faster than reading import statements across many files. Use |
read_conversation | read | |
read_relevant | read | |
remove_file | destructive | Remove a specific file from the RAG index. |
search | read | Search the full codebase by meaning — finds files that grep misses. Use natural language ( |
search_analytics | read | Show search usage analytics: query counts, zero-result queries, low-relevance queries, top searched terms. |
search_checkpoints | read | Semantic search over checkpoint titles and summaries. |
search_commits | write | Semantically search git commit history. Use this to find why code was changed, when decisions were made, or what an author worked on. Returns commits ranked by relevance to the query. |
search_conversation | read | Search through conversation history. Finds past decisions, discussions, and tool outputs from current or previous sessions. |
search_symbols | read | |
server_info | read | Show the current MCP server configuration: resolved project directory, database location, index status, embedding model, active config, and all currently connected databases. |
trace | read | Show how one symbol reaches another: the connecting call sub-graph from |
usages | read | Find call sites and references to a symbol across indexed files — with file paths, line numbers, and matching lines. Resolves aliased imports: searching the original name finds call sites that import it under an alias ( |
wiki | write | Run the wiki rebuild workflow. The |
write_relevant | write | Find the best file and location to insert new code or docs. Returns semantically appropriate insertion points with anchors for precise placement. Use this before adding a new function to find which file and position it belongs in. |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (1 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (19)
mimirs eval <file> [--dir D] Run A/B eval (with/without RAG)
"**/id_rsa", "**/id_dsa", "**/id_ecdsa", "**/id_ed25519",
"**/.npmrc", "**/.pgpass", "**/.netrc",
process.env.NODE_TLS_REJECT_UNAUTHORIZED = "0";
delete_annotation, remove_file
if (flags.length) { console.log(`\nsuspect (query names gold token absent from the bug report):`); for (const l of flags) console.log(l); }import { RagDB } from "../../src/db";import { loadConfig } from "../../src/config";import { search, searchChunks } from "../../src/search/hybrid";import { RagDB } from "../../src/db";import { loadConfig } from "../../src/config";const mark = i === kneeIdx ? " <-KNEE" : i === maxDropIdx ? " <-maxΔ" : i === maxRelIdx ? " <-maxΔ%" : "";
for (const [name, cut] of [["knee", kneeIdx + 1], ["maxΔ", maxDropIdx + 1], ["maxΔ%", maxRelIdx + 1]] as [string, number][]) {@huggingface/transformers, @modelcontextprotocol/sdk, @winci/bun-chunk, graphology, graphology-communities-louvain, gray-matter, sqlite-vec, zod
mimirs is a local code-RAG engine: it indexes a project's files into a SQLite database, embeds the chunks, and answers semantic and graph queries against them. The same engine ships in two shapes. A o
When the lock is held, the server kicks off `indexDirectory(...)` **without awaiting it**, so boot returns and the index builds in the background while tools are already answerable (`src/server/index.
`registerAllTools` is a thin fan-out: it wraps the server in a friendly-error proxy, then calls one `registerXTools(server, getDB, ...)` per group — search, indexing, graph, conversation, checkpoints,
read — common secret patterns like `.env`, `*.pem`, `*.key`, and SSH keys are
[Bun](https://bun.sh) (`curl -fsSL https://bun.sh/install | bash`) and, on macOS, a modern SQLite — Apple's bundled one doesn't support extensions:
Gates applied: no_behavioural_pass.
52378594b0c7full audit observations/trust-audit/mcp-server/thewinci__mimirs.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 52378594b0c7 | BLOCK | D | 69 | first audit |
Questions
What is the Mimirs MCP server?
Local MCP server that gives AI coding agents persistent, searchable memory of your codebase
What tools does Mimirs expose?
31 in total: 23 read-only, 6 that write, and 2 that can delete or overwrite (delete_annotation, remove_file). Every one is listed on this page with its risk.
Is Mimirs safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Mimirs need?
It reads NODE_TLS_REJECT_UNAUTHORIZED from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Mimirs run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mimirs at 1.8.0.
How current is this page?
The grade is for one exact copy of the source (52378594b0c7), read on 2026-10-08. The repository is watched and re-audited when it changes.