Openchronicle Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Openchronicle Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A memory database for LLM agents. Persistent semantic + keyword memory, project namespacing, git-onboard, served over HTTP REST and MCP from a single ASGI process. Runs on your hardware.
and rejected approaches that survive context compression and new conversations. Retrieve them with hybrid full-text and semantic search via Reciprocal Rank Fusion.
for one workstream doesn't leak into another.
return summaries ready for memory ingestion. Seeds long-term memory with the WHY behind existing code.
(/api/v1/*) and the MCP streamable-HTTP transport (/mcp) on the same port. Single container, single port mapping, single healthcheck.
down, search degrades cleanly to FTS5-only and surfaces the degraded state via /health. Backfill catches up when the provider returns.
.sql migrations withsavepoint atomicity. Re-runs are idempotent. Future schema changes drop in as NNN_<slug>.sql files.
Backup-before-destructive policy: vacuum runs a backup first as part of the same job. Integrity-check failures trigger emergency backups.
Open WebUI, etc. via the MCP server.
OC_API_KEYis supported but optional — disabled by default for trusted-LAN deployments. See docs/configuration/security_posture.md for the when-to-enable guidance.
to a directory next to it. Cross-device sync isn't built in (see V3_PLAN.md open question 12 for the design sketch).
By design.
From source:
pip install -e ".[mcp,openai]"
oc init
oc serveThe default oc serve binds 127.0.0.1:8000. Override with --host/--port or OC_API_HOST/OC_API_PORT.
Docker (single container, NAS-friendly):
docker run --rm \
-p 8000:8000 \
-v $(pwd)/data:/app/data \
-v $(pwd)/config:/app/config \
ghcr.io/carldog/openchronicle-mcp:latestFor a Portainer stack on a NAS, use the docker-compose.nas.yml at the repo root.
# Bootstrap the runtime tree
oc init
oc init-config
# Create a project
PROJECT_ID=$(oc init-project "my-project")
# Save your first memory
oc memory add "Decision: SQLite for storage; AGPL for license" \
--project-id $PROJECT_ID --tags decision
# Search it
oc memory search "storage decision" --project-id $PROJECT_IDOr do the same via MCP — register the server with Claude Code:
claude mcp add --scope user --transport http openchronicle \
http://127.0.0.1:8000/mcpThen ask Claude to call memory_save and memory_search.
Hexagonal: domain/ (pure types + ports) → application/ (use cases, services) → infrastructure/ (SQLite, embedding adapters, the maintenance loop). Driver-side adapters in interfaces/ host the HTTP, MCP, and CLI surfaces.
See docs/architecture/ARCHITECTURE.md for the full layout.
docs/architecture/ARCHITECTURE.md — layout, schema, ASGI designdocs/architecture/MAINTENANCE.md — maintenance loop + degradation policydocs/cli/commands.md — oc subcommand referencedocs/configuration/env_vars.md — environment variablesdocs/configuration/config_files.md — core.json schemadocs/configuration/security_posture.md — security modeldocs/integrations/mcp_client_setup.md — register the MCP serverdocs/integrations/mcp_server_spec.md — MCP tool surfacedocs/api/STABILITY.md — versioning + deprecation policypip install -e ".[dev,mcp,openai,ollama]"
pre-commit install
pytestThe architecture is enforced by tests:
tests/test_hexagonal_boundaries.py — domain/application/infrastructure layeringtests/test_architectural_posture.py — core agnostic of MCP SDKtests/test_no_secrets_committed.py, tests/test_no_soft_deprecation.py — repo hygiene~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.