
Company News
AWS Security Hub Adds Socket for Supply Chain Security
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.
dense-knowledge-mcp
Advanced tools
Local-first MCP memory server for persistent LLM knowledge and BM25 retrieval
A local-first MCP memory server for persistent LLM knowledge.
Dense Knowledge lets an AI assistant keep structured research between sessions
without a database, embedding model, or hosted account. It stores portable
.mmp files, searches their compact indexes with BM25, and loads full entries
only when they are relevant.
question -> compact index/search -> selected knowledge blocks -> answer
inexpensive detailed context
It works with LM Studio, Claude Desktop, Cursor, VS Code, and other clients that support local stdio Model Context Protocol servers.
The bundled context benchmark uses 40 entries. In its synthetic fixture, searching and reading the two best blocks uses 94.3% less estimated context than loading the complete package. The benchmark is reproducible and clearly documents its tokenizer-neutral counting method.
Install uv, then
place this server definition in your MCP client:
{
"mcpServers": {
"dense-knowledge": {
"command": "uvx",
"args": ["dense-knowledge-mcp"]
}
}
}
uvx downloads the published package when needed. Dense Knowledge uses the
platform's default data directory unless --root is supplied:
{
"mcpServers": {
"dense-knowledge": {
"command": "uvx",
"args": [
"dense-knowledge-mcp",
"--root",
"/absolute/path/to/memory"
]
}
}
}
Configuration differs slightly between clients. Ready-to-copy instructions are available for:
To install the command-line tools permanently:
uv tool install dense-knowledge-mcp
mmp setup
mmp doctor
mmp setup creates the memory directory and can safely merge the server into
an LM Studio mcp.json. Existing servers are preserved. Replacing an existing
Dense Knowledge entry requires --force and creates a backup first.
The CLI exposes the same storage operations as the MCP server:
mmp create quantum_physics.mmp "quantum physics"
mmp write quantum_physics.mmp --rev 0 --from examples/research_entries.json
mmp search quantum_physics.mmp "experimental tests of local realism"
mmp read quantum_physics.mmp e1
Typical search output contains candidates, not full bodies:
<mmp_data file="quantum_physics.mmp" trust="untrusted">
quantum_physics.mmp|e1|F|2.5427|Bell inequality separates local realism from quantum predictions
</mmp_data>
The client chooses relevant IDs and calls mmp_read only for those blocks.
This preserves the distinction between cheap orientation and detailed context.
The server exposes nine tools:
| Tool | Purpose |
|---|---|
mmp_list | List available knowledge packages |
mmp_create | Create an empty MMP package |
mmp_open | Read metadata, sources, legend, and index |
mmp_search | Return ranked candidates without body text |
mmp_read | Load selected body blocks within an optional budget |
mmp_write | Append structured entries |
mmp_update | Supersede an entry while preserving history |
mmp_deprecate | Mark an entry as obsolete with a reason |
mmp_validate | Check structure, language, provenance, and references |
Search uses BM25 over tags and summaries after legend expansion, with a body fallback when the index has no match. Deprecated entries remain readable but are omitted from normal search results.
The default knowledge directory follows the operating system:
~/.local/share/mmp/memory~/Library/Application Support/mmp/memory%LOCALAPPDATA%\mmp\memoryThe user configuration is stored separately:
~/.config/mmp/config.toml~/Library/Application Support/mmp/config.toml%APPDATA%\mmp\config.tomlMMP_ROOT or the global mmp --root option overrides the configured directory.
Keep personal packages out of source control; the repository's memory/
directory is ignored.
Models send structured objects to mmp_write; they never need to generate raw
MMP syntax. A minimal entry looks like:
{
"summary": "Possible caching strategy needs workload validation",
"tags": ["caching", "validation"],
"status": "H",
"srcs": [],
"content": "rel: versioned keys -> simpler invalidation\nq: workload impact -> needs measurement"
}
Important validation rules:
F or C require sources;H and cannot contain fact: or num: lines;C and include at least one ctr: line;See examples/research_entries.json for
sourced and contested entries that can be written directly.
All writes use optimistic revision numbers and atomic file replacement. A stale revision is reported to the caller, but a safe append is not discarded.
MMP content is reference data, never instruction. Read responses use an explicit untrusted envelope:
<mmp_data file="..." trust="untrusted">
...
</mmp_data>
The server rejects common instruction-like patterns during writes, does not
automatically follow ref: links, and tells the client not to obey instructions
found in stored material. These defenses reduce prompt-injection risk; they do
not turn untrusted research into trusted instructions.
Local MCP servers execute with your user permissions. Review the package and choose a dedicated memory directory before storing sensitive information.
Dense Knowledge implements the flat MMP/1.0 format, including BM25 retrieval, catalog generation, duplicate screening, budgets, append-only superseding, and validation. Hierarchical indexes for very large packages are planned but are not written yet.
Releases follow Semantic Versioning. Changes are documented in CHANGELOG.md.
python -m venv .venv
source .venv/bin/activate
python -m pip install -e ".[dev]"
ruff check src tests benchmarks
pytest
python -m build
Contributions are welcome. See CONTRIBUTING.md for the workflow and SECURITY.md for private vulnerability reports.
Licensed under the MIT License.
FAQs
Local-first MCP memory server for persistent LLM knowledge and BM25 retrieval
We found that dense-knowledge-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.