Project-owned sample · frozen 2026-09-12

A boundary you can
inspect yourself.

The public Local Knowledge Terminal MCP bridge was reviewed at commit e750e5a. The official Python MCP SDK listed its surface, called both tools, read its resource, and exercised a project-owned multilingual fixture.

This sample is a code-and-protocol review of one revision. It is not a customer result, penetration test, security certification, or guarantee of production fitness.

Decision

GO locally.
NO-GO remotely.

GOLocal read-only use in the recorded environment, with an authorized client and the reviewed data boundary.
NO-GODirect remote exposure: the standalone HTTP bridge deliberately has no client authentication.
The result names where this server can be used and where another control is required.
2Read-only tools
1Status resource
14Focused tests passed
0Prompts or write tools

What was executed

The advertised surface matched the tested surface.

MCP 2.2.0 returned exactly query_private_knowledge, trace_private_claim, and lkt://collections/status. Both tools advertised read-only, non-destructive, idempotent, closed-world annotations.

Multilingual trace

One Japanese query reached its Chinese source evidence.

The query returned one accepted subject, its English meaning, Japanese and Chinese translations, a reviewed relation, one source excerpt, and a validated source hash. The returned database status contained English, Japanese, and Chinese, but no database path.

The fixture is project-owned PocketPolyglot material. No customer source or production database was used.

Observed controls

Labels plus enforcement.

DBSQLite opens with mode=ro and PRAGMA query_only=ON.
LIMITInputs, results, graph depth, evidence, excerpts, collections, and SQL work are bounded.
PATHUnsafe locators and the database path are withheld from responses.
HTTPThe unauthenticated standalone bridge refuses non-loopback binding.

Evidence packet

The result is small enough to verify.

02

Executed checks

The sanitized log records fourteen passing core and MCP protocol tests without local paths.

Open test.log →
03

Integrity

The manifest hashes the environment, inventory, outputs, source hashes, log, report, and summary.

Read manifest.json →

Residual risk

Read-only does not mean private.

Client disclosure

An authorized or compromised client can receive returned excerpts and send them beyond the device.

Transport

Loopback prevents direct network exposure; it does not provide user authentication or an authorization policy.

Scope boundary

This review did not attempt penetration testing, production traffic, destructive calls, remote gateway design, or certification.

Your MCP server · USD 500

Start by deciding whether ten checks are enough.

The free fit check collects repository and runtime metadata, not source or secrets. If the job fits, the exact revision, surface, cases, handling terms, deliverables, and timing are accepted before payment.