Lore Db — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Lore Db (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A local, vector-based knowledge base with semantic search, a web UI, and an MCP server for use with Claude and other AI tools.
get, search, create, update, delete, verify, stale, reindex) over HTTP or stdioX-KB-Namespace header or KB_NAMESPACE env varproxy (nginx :8765)
├── /api/ → backend (FastAPI :8000)
├── /mcp/ → mcp (FastMCP :8000, streamable-http)
└── / → frontend (nginx :80, React SPA)| Module | Description |
|---|---|
backend/app/vector_store.py | SQLite document store + all-MiniLM-L6-v2 semantic embeddings |
backend/app/api.py | FastAPI CRUD, search, reindex, analytics, namespace endpoints |
backend/app/mcp_server.py | MCP tools (stdio, SSE, streamable-http transports) |
backend/app/service.py | Per-namespace KB instances with LRU caching |
backend/app/analytics.py | MCP event logging in a global analytics.db |
frontend/ | Vite + React + TypeScript, TanStack Router, Tailwind |
npm run startRuns docker compose up --build -d. The app is available at http://localhost:8765.
npm run stop # docker compose down
npm run restart # down + up --build -dnpm run devRuns docker compose -f docker-compose.dev.yml up --build. The app is available at http://localhost:8766.
--reload).localdata/backend-dev/ so dev never touches prod dataSQLite databases are stored on the host and are gitignored:
| Path | Contents |
|---|---|
.localdata/backend/knowledge_base*.db | Document store (one file per namespace) |
.localdata/backend/analytics.db | MCP event log |
The MCP server is exposed at http://localhost:8765/mcp/ using the streamable-http transport.
Add a .mcp.json in the directory where you start Claude:
{
"mcpServers": {
"knowledge-base": {
"type": "http",
"url": "http://localhost:8765/mcp/",
"headers": {
"X-KB-Namespace": "my-project"
}
}
}
}Set X-KB-Namespace to any alphanumeric slug. Each unique namespace gets its own isolated database.
| Tool | Description |
|---|---|
get_document(document_id) | Fetch full document content |
search_documents(query, limit) | Semantic + lexical search with freshness decay |
create_document(title, content) | Add a new document |
update_document(document_id, ...) | Update title and/or content |
delete_document(document_id) | Remove a document |
verify_document(document_id) | Confirm a document is still accurate (bumps freshness timestamp) |
get_stale_documents(days_threshold) | Find documents that may be outdated |
reindex_documents | Re-embed all documents (run after first deploy or model changes) |
For direct CLI invocation without the HTTP server:
{
"mcpServers": {
"knowledge-base": {
"type": "stdio",
"command": "docker",
"args": [
"compose",
"exec",
"-T",
"-e",
"KB_NAMESPACE=my-project",
"backend",
"python",
"-m",
"app.mcp_server"
]
}
}
}Run reindex_documents() via MCP tool, the Settings page, or curl after:
all-MiniLM-L6-v2curl -X POST http://localhost:8765/api/reindex -H "X-Kb-Namespace: my-project"Normal create and update operations always auto-embed — no manual reindex needed.
cd backend
python -m pytest tests/ -v~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.