io.github.ellmos-ai/ellmos-homebase-mcp — Model Context Protocol (MCP) Server
The MCP server “ellmos-homebase-mcp” provides local-first LLM orchestration, including memory, knowledge, routing, swarm patterns, API probing, persistent state, automation planning, tests, and plugin discovery. It runs as a stdio server and is designed primarily to work with local LLMs via an MCP-capable harness.
🛠️ Key Features
Local-first LLM orchestration
Memory and knowledge components
Routing and swarm patterns
API probing
Persistent state
Tests and automation planning
Plugin discovery (stdio MCP server)
SQLite-based persistence
🚀 Use Cases
Orchestrating local LLMs (e.g., Ollama, Qwen, Llama)
Managing LLM memory and knowledge with persistent storage
Discovering and integrating MCP-capable plugins
Probing available APIs during orchestration
⚡ Developer Benefits
MCP server access via stdio
SQLite persistence with no cloud dependency
Works with MCP-capable harnesses for locally hosted models
Supports connection to external LLM providers as MCP
⚠️ Limitations
Labeled “Alpha MCP server”
Primary focus is local LLMs; external providers depend on MCP connectivity
Alpha MCP server for local-first LLM orchestration: memory, knowledge, routing, swarm patterns, API probing, persistent state, tests, automation planning, and plugin discovery in one stdio server.
Homebase is designed primarily for local LLMs (Ollama, Qwen, Llama, or any locally-hosted model via a MCP-capable harness). All persistent storage uses SQLite with no cloud dependency. External LLM providers (Claude, Codex, Gemini, OpenAI) can also connect as MCP clients, but local, offline-capable setups are the primary target.
Discoverability: Published on npm as ellmos-homebase-mcp and maintained in the ellmos-ai organization.
NOTE
For AI Assistants & LLM Agents: Machine-readable architecture summary, index, and tool capabilities are published in llms.txt. MCP registry metadata is available in server.json.
sequenceDiagram
autonumber
participant Client as MCP Client (Local LLM / Claude / Codex)
participant Stdio as Transport Layer (stdio)
participant Server as Server & Registry (homebase)
participant Module as Functional Module (hb_mem / hb_state / hb_route)
participant Engine as Engine Seam (Bundled vs Canonical)
participant DB as SQLite Storage (~/.homebase/)
Client->>Stdio: JSON-RPC 2.0 Request (tools/call: hb_mem_store, agent_id="agent-01")
Stdio->>Server: Decode & dispatch tool call
Server->>Module: Validate arguments & inject agent provenance
alt Bundled Engine Mode (Default)
Module->>DB: Execute SQLite query (WAL mode, busy timeout)
DB-->>Module: Return structured records / mutation status
else Canonical Engine Mode ([engines].mode = "canonical")
Module->>Engine: Seam check (Gardener / TASKPLAN / USMC)
alt Engine Available
Engine-->>Module: Delegate to canonical subsystem
else Engine Unreachable
Engine-->>Module: Raise CanonicalEngineUnavailable (Fail-Closed)
end
end
Module-->>Server: Format response in requested language (i18n: en/de/es/zh/ja/ru)
Server-->>Stdio: Encode JSON-RPC 2.0 Response
Stdio-->>Client: Result payload (Zero cloud egress, 100% local)
Core Capabilities & Security Invariants
Capability / Invariant
Guarantee
Technical Implementation
100% Local-First & Zero-Egress
Complete privacy and offline operation; no unexpected cloud communication or telemetry.
All persistent memory, knowledge, and state are saved in local SQLite (~/.homebase/).
Strict Engine Seams & Fail-Closed
No silent fallback into disconnected databases when requesting canonical systems.
MODE-CONTRACT.md enforcement: raises CanonicalEngineUnavailable if target is unreachable.
Team-Memory Provenance (agent_id)
Deterministic audit trail and filterable ownership for multi-agent workflows.
Native agent_id tracking across memory facts, knowledge entries, and task state.
Credential-Free Discovery & Planning
Zero secret exposure during local routing recommendations and API probing.
hb_route_*, hb_swarm_*, and hb_api_* run without transmitting API keys or private tokens.
Safe Plan-and-Queue Adapters
Safe queueing and chain staging without arbitrary remote code execution.
hb_conn_* and hb_auto_* maintain plan-only queues and offline staging records.
Full Native i18n Localization
Seamless multilingual developer and agent interaction.
Localized tool descriptions and JSON schemas for en, de, es, zh, ja, ru.
Non-Elevation & Secret Hygiene
Unprivileged execution and strict credential exclusion from distribution.
Non-root compatibility; live configs/secrets ignored in .gitignore and .npmignore.
Multi-OS CI Smoke Integrity
Verified cross-platform reliability on all major operating systems.
Multi-version CI matrix covering Python 3.10–3.13 and Node.js 20–24 on Linux/Windows/macOS.
Governance & Runtime Invariants
Invariant ID
Title & Scope
Guarantee & Technical Enforcement
Verification Seam
INV-LOCAL-01
100% Local-First & Zero-Egress
All persistent memory, knowledge entries, and task states are stored locally in SQLite (~/.homebase/). Zero telemetry, analytics, or unrequested outbound cloud network calls.
MODE-CONTRACT.md enforcement: switching [engines].mode = "canonical" never silently falls back to bundled storage if the canonical engine is unreachable.
tests/test_engine_seams.py
INV-SEAM-03
Canonical-Only Isolation
hb_policy_*, hb_ticket_*, and hb_lock_* provide read-only views into policy-registry, ticket-master, and lock-master. They possess no bundled imitation and fail closed unconditionally.
tests/test_new_seams.py
INV-PROV-04
Deterministic Provenance & Team-Memory
Multi-agent coordination requires strict isolation. All memories, knowledge facts, and task transitions record agent_id attribution with SQLite WAL concurrency and busy timeouts.
tests/test_module_contracts.py
INV-CRED-05
Credential-Free Discovery & Probing
Model routing suggestions (hb_route_*), swarm pattern blueprints (hb_swarm_*), and API schema probing (hb_api_*) function without private API keys, tokens, or credentials.
tests/test_module_contracts.py
INV-STAGE-06
Plan-Only Staging & Bounded Offline Queues
Connector queues (hb_conn_*) and automation plans (hb_auto_*) record offline blueprints and dry-run staging manifests without executing arbitrary remote code or side-effects.
tests/test_module_contracts.py
INV-I18N-07
Native Multilingual Schema Parity
All 51 tool definitions, input schemas, and validation errors maintain 100% complete localization across 6 supported languages (en, de, es, zh, ja, ru).
tests/test_i18n_completeness.py
INV-PERM-08
Non-Elevation & RunAsInvoker Principle
Homebase runs strictly in unprivileged user space. It requires no administrator or root privileges and ignores sensitive local dotfiles and system credentials.
tests/test_repository_hygiene.py
INV-SYNC-09
Multi-Host Lock & Conflict Discipline
Strict exclusion of conflict copies (*.sync-conflict-*, *-conflict-*) and honor of multi-agent lock mechanisms (LOCK.*, *.lock) to preserve database integrity across hosts.
Security disclosures sent to security@ellmos.ai, support@lukasgeiger.com, or security@open-bricks.org receive guaranteed initial response in <=48h, triage within 5 business days, and verified remediation within 30 calendar days.
SECURITY.md, tests/test_metadata.py
Target Personas & Discoverability
Homebase is purpose-built to solve architectural and operational challenges across four core technical audiences:
[PERSONA-01] Local LLM & Edge AI Developers
Profile & Objective: AI engineers building offline or edge applications with Ollama, Qwen, or Llama models who need a robust orchestration harness.
Package status: public alpha package under ellmos-ai
Release metadata: MIT LICENSE, NOTICE, CHANGELOG.md, llms.txt, and MCP Registry metadata in server.json
Test gate: GitHub Actions covers Python 3.10/3.11/3.12/3.13 plus Node.js 20/22/24 smoke and npm package checks
Current core: module discovery, MCP tool listing, MCP tool dispatch, config fallbacks, local planning/probing/queue/dry-run adapters
Real local SQLite modules: hb_mem_*, hb_kb_*, hb_garden_*, hb_state_*
Engine seams: hb_garden_*, hb_state_task_* and hb_mem_* can delegate to the real
canonical Gardener/Rinnsal/USMC engines instead of the bundled SQLite copies via
[engines].mode = "canonical" (default remains "bundled" for a zero-dependency install).
No silent fallback: if you request canonical and the engine is unreachable, those tools
return an error rather than quietly using the bundled DB — the server still starts and lists
its tools. Binding rule and migration notes: MODE-CONTRACT.md;
mechanism: KONZEPT.md.
Canonical-only seams (no bundled alternative at all): hb_policy_* (policy-registry),
hb_ticket_* (ticket-master), hb_lock_* (lock-master) — all read-only in v1. A locally
faked copy of live policy/ticket/lock state would mislead rather than help, so these three
always attempt the canonical module and fail closed unconditionally if it is unreachable.
Team-memory basics: agent_id provenance and filters for memory, knowledge, state memory, and tasks; SQLite uses WAL plus a busy timeout for safer concurrent agents
i18n: fully localized MCP tool descriptions, input-schema field descriptions, and unknown-tool errors for en, de, es, zh, ja, ru (English fallback for any unset key)
Roadmap: optional real LLM/API integrations and explicit execution backends
Install
The npm package contains a Node wrapper that starts the Python server. You still need Python 3.10+ and the Python package mcp>=1.0.0.
Avoid creating a .venv inside cloud-synced folders if your sync client locks files. If you need an isolated environment, create it outside that folder.
Start From Source
powershell
$env:PYTHONPATH = "src"
python -m homebase.server
MCP Client Configuration
Homebase uses the standard stdio mcpServers configuration format. The same snippet works in any MCP-capable client or harness: BACH/Buddha (local Ollama), Claude Code, Codex, Cursor, or any other MCP host.
Note on local LLMs: A bare Ollama instance does not speak MCP natively — you need a MCP-capable harness on top of it (e.g., BACH, an open-source MCP proxy, or another orchestration layer). Configure that harness to include Homebase as an MCP server using the snippet below.
Language can be configured with [server].language, HOMEBASE_LANG, or HOMEBASE_LOCALE.
The writing agent can be passed per tool call as agent_id; otherwise modules use
HOMEBASE_AGENT_ID, AGENT_ID, a module-level agent_id, or unknown.
Modules with missing optional dependencies are skipped without blocking server startup.
Tools
Important tool groups:
hb_mem_* for SQLite-backed memory
hb_kb_* for SQLite-backed knowledge entries
hb_state_* for persistent SQLite state and tasks
hb_garden_* for a small SQLite garden store
hb_route_* for credential-free model-routing recommendations and feedback stats
hb_swarm_* for credential-free swarm planning patterns
hb_api_* for passive HTTP API discovery with SQLite history
hb_test_* for built-in metadata and smoke self-tests
hb_conn_* for a local connector registry plus SQLite-backed inbox/outbox queues without network sends
hb_auto_* for local automation chain definitions and queued plan-only runs without backend execution
hb_plug_* for local plugin discovery and dry-run records without executing plugin code
hb_policy_* (read-only, canonical-only) for resolving/listing policy-registry rules
hb_ticket_* (read-only, canonical-only) for listing/showing ticket-master tickets by lifecycle folder
hb_lock_* (read-only, canonical-only) for checking/listing active lock-master locks
Discovery Context
Use ellmos-homebase-mcp when searching for a local-first, offline-capable MCP server that gives local LLMs (Ollama, Qwen, Llama, or similar) persistent memory, knowledge management, routing, and orchestration — without requiring any cloud dependency. External LLM providers can also use it as an MCP server, but local-first setups are the primary design target.
Good search phrases:
ellmos Homebase MCP server
local-first LLM orchestration MCP
MCP server SQLite memory knowledge routing
offline agent orchestration MCP server
MCP swarm planning persistent state API discovery
Not the same as Elmo/ELMO voice tools, AllenAI ELMo embeddings, Eclipse LMOS, generic cloud agent platforms, or single-purpose MCP memory servers.
ellmos-ai Ecosystem
This MCP server is part of the ellmos-ai ecosystem — AI infrastructure, MCP servers, and intelligent tools.
ellmos-homebase-mcp is verified to contain 0% copyleft dependencies. All runtime dependencies are permissively licensed (MIT, BSD-2-Clause, Apache-2.0, PSFL).
Full inventory, Level 1 SBOM Invariant Cross-Reference Matrix, and non-elevation certifications are documented in THIRD_PARTY_LICENSES.md and plain-text companion THIRD_PARTY_LICENSES.txt. Canonical copyright and author attribution is maintained in NOTICE.
Security & Vulnerability Reporting
ellmos-homebase-mcp strictly adheres to local-first, zero-egress, and non-elevation security principles. Full policies, SLAs, and security guarantees are documented in SECURITY.md:
Supported Versions: 0.1.0-alpha.x
Response SLA: Initial acknowledgment and triage within 48 hours. Detailed triage within 5 business days; remediation within 30 calendar days.
Security Contacts: security@ellmos.ai, support@lukasgeiger.com, and security@open-bricks.org.
ellmos-homebase-mcp is open-source software licensed under the MIT License.
Canonical attribution to Lukas Geiger, the ellmos-ai family, and the open-bricks ecosystem is formally preserved in NOTICE.
Third-party component licenses are cataloged in THIRD_PARTY_LICENSES.md.
This software is made available free of charge as an open-source project. Under German statutory law governing gratuitous software provision (§ 521 BGB Gefälligkeitsrecht):
Liability Limitation: The author and contributors are liable only in cases of intentional misconduct (Vorsatz) or gross negligence (grobe Fahrlässigkeit).
Warranty Limitation: In accordance with §§ 523, 524 BGB, warranty claims for material and legal defects (Sach- und Rechtsmängel) are excluded, except in cases where defects have been fraudulently concealed (arglistiges Verschweigen).
Local-First & Non-Elevation Principle: ellmos-homebase-mcp is provided on an "as is" and "as available" basis without any express or implied warranty. Operators run Homebase in unprivileged user mode (RunAsInvoker) at their own discretion.
Coordinated Security Response SLA
For vulnerability reporting or security inquiries, our coordinated disclosure policy guarantees an initial response within 48 hours and triage within 5 business days:
Homebase MCP remains a standalone local-first MCP server. In the V4
composition it is an optional MCP access surface of the
ellmos-memory-human-context-bundle: a configured system may use it to reach
memory and human-context capabilities. This access role does not make Homebase
the canonical owner of every memory, knowledge, state, routing or automation
function; the selected host and system manifests retain those bindings.
Canonical or bundled engines are integration partners selected by explicit
configuration, not implicit replacements for this server. Authoritative
bundle membership, versions, profiles and private composition recipes remain
in the corresponding bundle manifests. This public section is discovery-only.