ChatCrystalCAUTION
Local-first AI PKM for coding conversations: import Claude Code/Cursor/Codex, distill notes, semantic search, tag graph, MCP memory.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Local-first AI PKM for coding conversations
[](https://github.com/ZengLiangYi/ChatCrystal/releases) [](https://www.npmjs.com/package/chatcrystal) [](https://glama.ai/mcp/servers/ZengLiangYi/ChatCrystal) [](LICENSE) [](https://nodejs.org/) [](#) [](https://zengliangyi.github.io/ChatCrystal/)
Website · Download Desktop · npm · Docs · 简体中文
ChatCrystal is a local-first AI PKM app for developers who solve real problems with Claude Code, Cursor, Codex CLI, Trae, and GitHub Copilot.
It turns scattered AI coding conversations into structured notes, semantic search, a tag knowledge graph, Markdown exports, and MCP memory your agents can reuse. If this fits your workflow, a star helps more builders find a private, local-first way to keep their AI work memory.
Quick Start
Desktop App (Recommended)
Download the latest Windows installer from GitHub Releases. After installing, launch ChatCrystal, configure your LLM a
3c99fd4f21d1OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add chatcrystal --env CHATCRYSTAL_API_TOKEN=${CHATCRYSTAL_API_TOKEN} -- npx -y [email protected] mcpExposed tools (7)
6 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_note | read | |
get_relations | read | |
list_notes | read | |
recall_for_task | read | |
search_knowledge | read | |
validate_task_memory | read | |
write_task_memory | write |
Trust audit
CAUTIONgrade C · trust 78/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (6 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
CMD node -e "fetch('http://127.0.0.1:3721/api/health').then(r=>process.exit(r.ok?0:1)).catch(()=>process.exit(1))"const token = 'chatcrystal-smoke-token-1234567890';
cli-showcase.webm
feature-cli.webm
feature-mcp.webm
feature-search.webm
hero.webm
exec(sql: string, params: unknown[]) {exec(sql: string, params: unknown[]) {exec(sql: string, params: unknown[]) {exec(sql: string, params: unknown[]) {exec(sql: string, params: unknown[]) {import { isLocalBaseUrl } from '../../runtime/cloud.js';import { runRemoteImport } from '../../services/remoteImport.js';import { runtimePaths } from '../../runtime/paths.js';const { createServer } = await import('../../index.js');const serverEntry = resolve(import.meta.dirname, '../../index.js');
Local mode connects to or auto-starts ChatCrystal Core at `http://localhost:3721` and uses `~/.chatcrystal/data` by default. If a tool separately asks for an HTTP API endpoint, use `http://localhost:3
本地模式会连接或自动启动 `http://localhost:3721` 上的 ChatCrystal Core,默认数据目录为 `~/.chatcrystal/data`。如果某个工具另外要求填写 HTTP API endpoint,请使用 `http://localhost:3721`。不要填写没有端口的裸 `http://127.0.0.1`,因为 HTTP 会默认落到 80 端口。
ChatCrystal MCP uses stdio transport. Agent clients should launch it with `command` and `args`, not register it as an HTTP/SSE MCP URL. If a tool separately asks for the ChatCrystal HTTP API endpoint,
ChatCrystal MCP 使用 stdio transport。Agent client 应通过 `command` 和 `args` 启动它,不要注册成 HTTP/SSE MCP URL。如果某个工具单独要求 ChatCrystal HTTP API endpoint,请使用 `http://localhost:3721`,不要使用裸 `http://127.0.0.1`。
@react-sigma/core, @tanstack/react-query, class-variance-authority, clsx, cmdk, graphology, graphology-layout, graphology-layout-forceatlas2
@biomejs/biome, concurrently, cross-env, tsx, wait-on
react, react-dom, @types/react, typescript
@fastify/cors, @fastify/static, @modelcontextprotocol/sdk, chokidar, commander, dotenv, ink, p-queue
Gates applied: no_behavioural_pass.
3c99fd4f21d1full audit observations/trust-audit/mcp-server/zengliangyi__chatcrystal.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 3c99fd4f21d1 | CAUTION | C | 78 | first audit |
Questions
What is the ChatCrystal MCP server?
Local-first AI PKM for coding conversations: import Claude Code/Cursor/Codex, distill notes, semantic search, tag graph, MCP memory.
What tools does ChatCrystal expose?
7 in total: 6 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is ChatCrystal safe to connect to an agent?
With care. The audit graded it C (78/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does ChatCrystal need?
It reads CHATCRYSTAL_API_TOKEN, EMBEDDING_API_KEY and LLM_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does ChatCrystal run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as chatcrystal-site at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (3c99fd4f21d1), read on 2026-10-08. The repository is watched and re-audited when it changes.