tokenknows-plugin — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited tokenknows-plugin (MCP Server) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
<p align="center"> <img src="assets/brand/png/logo-tile-512.png" alt="TokenKnows logo" width="140" /> </p> <h1 align="center">TokenKnows</h1> <p align="center"> Distill AI coding sessions into living knowledge — weekly reports, ADRs, incident reviews, books, agent skills, and a knowledge graph. </p> <p align="center"> <a href="LICENSE"><img src="https://img.shields.io/github/license/johnnywuj81/tokenknows?color=d97757" alt="License"></a> <a href="https://github.com/johnnywuj81/tokenknows/actions/workflows/ci.yml"><img src="https://github.com/johnnywuj81/tokenknows/actions/workflows/ci.yml/badge.svg" alt="CI"></a> <img src="https://img.shields.io/badge/Claude_Code-plugin-d97757" alt="Claude Code plugin"> <img src="https://img.shields.io/badge/MCP-server-241b15" alt="MCP server"> <img src="https://img.shields.io/badge/PRs-welcome-788c5d" alt="PRs welcome"> </p> <p align="center"><b>English</b> | <a href="README.zh-CN.md">简体中文</a></p>
<p align="center"> <img src="assets/demo/tokenknows-demo.gif" alt="TokenKnows demo: capture an AI coding session, distill it into a weekly report and knowledge graph" width="920" /> </p>
You spend hours pair-programming with Claude Code, Codex, and Cursor. The decisions, bug hunts, and design trade-offs from those sessions evaporate the moment the terminal closes. TokenKnows captures them automatically and distills them into structured, evidence-linked knowledge assets:
capture (6 collectors) → distill (5-stage LLM pipeline) → assets (7 document types) → review / redact / publish
cosine × trust × recency across ≥2 sources.▶ Full walkthrough: engineering_handoff/walkthrough.mp4 (5 min, Chinese narration + subtitles)
<details> <summary>All 12 screens</summary>
| 1 Workbench | 2 Event drawer | 3 Document list | 4 Document page |
|---|---|---|---|
| 5 Evidence drawer | 6 Regenerate dialog | 7 Review | 8 Redaction |
| 9 Publish dialog | 10 Publish receipt + diff | 11 LLM egress | 12 Admin |
</details>
Prerequisite: the TokenKnows backend at http://localhost:8001 and the web UI at `http://localhost:5173` (see Quick start), plus uv (the plugin pulls the MCP server from PyPI via uvx). All plugin env vars have working local defaults — export TOKENKNOWS_API_BASE / TOKENKNOWS_API_TOKEN / TOKENKNOWS_DEFAULT_PROJECT / TOKENKNOWS_WEB_BASE only for non-default setups. Register/login in the web UI and create an API token under Project Settings → MCP 接入 when your backend requires auth.
| Platform | How |
|---|---|
| Claude Code | /plugin marketplace add johnnywuj81/tokenknows → /plugin install tokenknows@tokenknows — full walkthrough in tokenknows-plugin/README.md (5-minute quickstart) |
| Codex | codex plugin marketplace add johnnywuj81/tokenknows → codex plugin add tokenknows@tokenknows (loads skills, commands and the MCP server; local-clone alternative in codex-plugin/README.md) |
| Cursor | Add the tokenknows MCP block to ~/.cursor/mcp.json (uvx config example in code/tokenknows-mcp/README.md) |
| VS Code | Download the .vsix from Releases → code --install-extension tokenknows-vscode-*.vsix |
The plugin gives your AI tool MCP tools (submit_session_events, distill_document, list_assets, get_asset, get_asset_chapters, search_entity) plus slash commands like /tokenknows:weekly and /tokenknows:adr.
# 1. (Optional but recommended) Ollama — fully local inference, zero cloud keys
ollama serve &
ollama pull minimax-m2:cloud # or gpt-oss:20b, qwen2.5, ...
# 2. Backend (FastAPI + SQLite persistence + 3-layer LLM egress gate)
cd code/tokenknows-api
python3 -m venv .venv && .venv/bin/pip install -e ".[dev]"
cp .env.local.example .env.local # defaults to Ollama; edit to add cloud providers
.venv/bin/uvicorn app.main:app --host 127.0.0.1 --port 8001
# 3. Frontend (React 19 + Vite)
cd code/tokenknows-web
npm install
npm run dev
# open http://localhost:5173 — talks to the real backend (mocks are opt-in via ?msw=1)
# (Optional) seed demo data
./engineering_handoff/demo-seed.shPlatform support: macOS — full experience (collectors auto-start via launchd). Linux — backend, frontend, and collectors all run manually (python3 plugins/<x>/sync.py --watch); the launchd scripts don't apply. Windows — untested; WSL2 recommended.
All local — no ngrok, no public webhooks. On macOS they restart on crash and on reboot (launchd).
| Collector | Source | Mode |
|---|---|---|
| claude-code | ~/.claude/projects/*.jsonl | 30s polling, incremental offsets |
| codex | ~/.codex/sessions/**/rollout-*.jsonl | 30s polling, incremental offsets |
| cursor | Cursor's state.vscdb (read-only SQLite) | 60s polling |
| github | GitHub REST API · PRs / issues / commits | 5min polling (gh auth token) |
| vscode | VS Code extension onDidSaveTextDocument | buffered, 10s flush |
| local-docs | ~/Documents .md .txt .pdf (watchdog) | realtime, 2s debounce |
./scripts/launchd/install.sh # macOS: install all 5 Python collectors as LaunchAgents
launchctl list | grep com.tokenknows
tail -f ~/Library/Logs/tokenknows/*.logEvery event carries a trust score (0.6 × source_authority + 0.4 × extraction_confidence); the evidence stage ranks citations by 0.6 × cosine + 0.25 × trust + 0.15 × recency and enforces ≥2 distinct sources.
Architecture overview
Collectors feed an event store (SQLite). A five-stage pipeline (collect → outline → content → evidence → assess) turns events into assets. The LLM Gateway unifies four providers (Anthropic / OpenAI / MiniMax / Ollama) with per-task routing and fallback chains — and refuses any cloud call unless all three egress switches are on.
| Workflow | Runner | Trigger |
|---|---|---|
ci.yml | ubuntu-latest (GitHub-hosted) | push to main + every PR |
ci-macos.yml | self-hosted macOS ARM64 | maintainer pushes to main only — never runs external PR code |
Details: PRD §6.7 data residency & egress control (Chinese).
| Topic | Doc |
|---|---|
| Product requirements, user journeys | PRD (zh) |
| Technical design, API, schema | TDD (zh) |
| Macro architecture & milestones | Architecture (zh) |
| Per-screen engineering decisions | TaskTechDesign (zh) |
| Pixel-level UI mockups | mockups/ — open in a browser |
Most in-depth docs are in Chinese (the project's working language). Code comments are predominantly Chinese too; issues and PRs in English or Chinese are both welcome.
CONTRIBUTING · Roadmap · Code of Conduct · Security policy · Issues
MIT © 2026 johnnywuj81
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.