chamber
Use this MCP server to check claims against a user's notes, ask sourced questions from the indexed corpus, detect citation drift, and inspect what is indexed.
chamber_check: verify your own claims against cited notes before stating them — confirms notes are indexed and unchanged, checks numbers, capitalised names, domains, file names and counts, returns verdicts like SUPPORTED, TERMS_ABSENT, STALE, NOT_FOUND; no model; optionallyrecord: truecommits supported claims as pinned beliefs for later drift checks.chamber_ask: have Chamber's configured model answer a question from indexed notes with per-claim citation verdicts (ALLOWED / UNSUPPORTED); supportsexact,strict, andsemanticoptions; writes through the commit gate (beliefs, citation debt, spend) and says APORIA when nothing supports.chamber_verify: re-check every stored belief's pinned sources for drift — reportsnot_foundorhash_mismatchwhen evidence moved; read-only; optionalsincefilter.chamber_corpus: inspect the index — passage/file counts, citable source kinds, top folders, and export-like outliers; read-only.The server does not ingest, activate skills, or approve pending writes; it is meant to be registered with an MCP host like Claude Code.
Provides a GitHub Action for CI drift gates, running chamber verify --json in a workflow to fail builds when pinned documentation or code passages change.
Renders Chamber's verify --json drift report as a vault sidebar panel and per-note banner, showing when pinned sources change.
Integrates with OpenAI-compatible model endpoints for chamber ask, enabling answers from the indexed corpus with per-claim citations and verification.
Chamber
The check your AI agent runs on your notes. When Claude Code or any MCP host
answers from your vault, chamber_check confirms the numbers, capitalised
names and file names it quotes are really in the note it cites — and says so
when they are not, or when the note changed since it was indexed.
How it works.
You can also ask questions yourself and get answers that cite their sources, plus a daily check that tells you when a source has changed underneath a conclusion you already trusted.
Zero runtime dependencies. Everything is node:sqlite and files on your disk.
No account, no cloud call unless you point it at one.
Run the check
Checkout and the published package are different runtimes. Config is a third path, for ingest and chamber_ask.
claude mcp add -s user chamber -- npx -y @bu7umaid/chamber mcpCheckout — Node 23.6+. TypeScript runs directly from the repo, with no
build step. --experimental-strip-types has been the default since 23.6.0, so
the flag is defensive. No config, no model, no network.
git clone https://github.com/abm9111/chamber.git && cd chamber && npm ci && node --experimental-strip-types src/cli.ts tryAgent. The command above runs the published bin (dist/), not src/.
If /mcp does not list chamber_check, the host spawned with a minimal
PATH. Take the interpreter from command -v node in the shell you actually
use, and point it at the published bin or at a checkout's src/mcp_server.ts.
Those are different files.
# published bin: bin/chamber.js loads dist/. This is not src/mcp_server.ts.
claude mcp add -s user chamber -- "$(command -v node)" /path/to/node_modules/@bu7umaid/chamber/bin/chamber.js mcp
# checkout only. src/mcp_server.ts is not in the npm install.
claude mcp add -s user chamber -- "$(command -v node)" --experimental-strip-types /path/to/chamber/src/mcp_server.tsA number the note does not contain returns TERMS_ABSENT and names the term.
SUPPORTED is term presence, not entailment.
Related MCP server: Paper Memory MCP Lite
What people actually do
There is no public trail of Chamber users yet. These are the adjacent failures on X, which are the reason the check exists.
Pointing Claude Code at an Obsidian folder reads files. It does not check the sentence. Richard Kovacs, 28 Sep 2026: Claude returns a list of sources and he checks them. The remaining failure he names is confirmation bias, and he treats that as discipline.
A tool the agent must remember to call is not a gate. Saksham Arora, 2 Oct 2026: a shared-memory MCP only recalled a session if the other agent decided to search, so he put a hook before every message.
chamber_checkis the same shape. MCPinstructionsask Claude to call it. Nothing blocks the turn if it skips. A Stop hook that requires a receipt is the missing piece; it is not in this repo yet.Viral vault posts (99.7% recall, thousands of links in minutes) are not measurements. The number in this repo is the 200-claim set in
docs/KNOWN_LIMITATIONS.md§2: invented values mostly caught, negations not.
See it in two minutes
The checkout command above builds a throwaway workspace, runs the real code
paths against it, and deletes it (--keep to look around). It does not open
a database.

That recording is scripted from assets/demo.tape rather
than hand-captured, so it is regenerated when the output changes instead of
quietly showing a version of Chamber that no longer exists. Everything below is
that checkout command's actual output, trimmed:
$ chamber believe belief "Customers may return any purchase within 30 days of delivery."
committed blf_ddcf4f3c9b2e81b8
an unsourced assertion is not refused — it mints citation debt.
$ chamber debts
dbt_18bd1c1171cdbfcb [pending]
$ chamber pay-debt
proposed 2 source(s), 2 pinned; best=0.694
$ chamber verify
blf_ddcf4f3c9b2e81b8 2/2 pins verifiedThat is the ordinary state: a belief standing on evidence that still holds. Then
someone edits the note it was built on — 30 days becomes 14 days:
$ chamber ingest ./notes
ingested 2 file(s) as 4 passage(s)
$ chamber verify
blf_ddcf4f3c9b2e81b8 1/2 pins verified
hash_mismatch: refunds.md#p0Nobody asked it to re-examine that belief. The conclusion did not change; the ground under it did, and the exit code is non-zero, so a scheduled job can act on it. That is the whole product.
Four more scenarios — a rolled-back ledger caught by an outside anchor, a
sandbox that refuses rather than degrade, a hostile tool catalogue rejected —
are in demos/, and run in CI so they cannot drift from the code.
A dictionary for the words above
Everything Chamber does is rows in one SQLite file. Each term in the transcripts names a table or a hash:
Word | What it actually is |
passage | one chunk of one markdown file. |
belief | a row in |
pin | a sha-256 of a cited passage's stored title, body and ref, taken at the moment of citation and kept in |
verify | re-read every pinned passage, recompute the hash, compare. Any mismatch exits non-zero. No model involved. |
citation debt | a row in |
pay-debt | retrieval proposes passages for the indebted claim; accepting them pins them. |
APORIA | the verdict when no retrieved passage supports an answer. The reply is "I don't know", recorded as that. |
gate | a check and a write inside one SQLite transaction — both commit or neither does. |
audit log | append-only |
anchor | the log's root hash stored outside the database, so truncating the log is detectable rather than silent. |
the scheduler | a launchd/systemd job running |
None of it is hidden machinery: sqlite3 ~/.local/share/chamber/chamber.sqlite '.tables' shows the whole thing.
Answers that cite their sources
With a model configured, chamber ask judges every sentence on its own
citations. Against the same two sample notes, on a local 30B:
$ chamber ask "summarise our refund policy"
Customers may return any purchase within 30 days of delivery [2]. Refunds
are issued to the original payment method, usually within five working days
of the returned item arriving at the warehouse [2]. However, perishable goods
and personalised items cannot be returned once dispatched [1].
[ALLOWED] Customers may return any purchase within 30 days of delivery [2]. Refu
sources: refunds.md#p0 — refunds › Refund policy, refunds.md#p1 — refunds › Refund policy › ExceptionsThe model is shown [1]…[k] and never a document id or a hash, so it cannot
fabricate a citation even in principle — the numbers are resolved back to files
after the answer is written. A sentence that cites nothing is marked
UNSUPPORTED: recorded, but not treated as load-bearing. A sentence whose
numbers, names or domains are not in the passage it cites loses that citation
too, and says which terms were missing (terms_absent) — a real passage is not
evidence for a claim it does not contain. Headings in an answer print as
[HEADING] and are not recorded.
Asking something the corpus cannot answer is the more important case:
$ chamber ask "what should a customer do if they want to return a perishable
item after the office has closed?"
I don't know
[APORIA] I don't knowBoth notes are in the index and both are relevant. Neither answers the question, so nothing is composed from the pieces.
For ingest and chamber_ask, not for the check
npm link # puts `chamber` on your PATH
chamber init # writes ~/.config/chamber/config.jsonThen edit that config to add a notes folder and a model:
{
"database": "~/.local/share/chamber/chamber.sqlite",
"model": { "base": "http://127.0.0.1:8087/v1", "name": "your-model", "mode": "openai" },
"ingest": [{ "root": "~/Notes", "exclude": ["transcripts", "attachments"] }]
}model.base may name any OpenAI-compatible endpoint. A loopback address needs
no API key; anything else reads CHAMBER_API_KEY from the environment, never
from the file.
chamber ingest # index every configured root
chamber ask "..." # ask, with citations
chamber verify # re-check stored pins against the corpus
chamber corpus # what is actually in the indexSet your excludes before the first ingest. There is no default exclude list.
Pointed at a folder of exported chat logs, Chamber will happily index all of
them and answer from them — see chamber corpus and
docs/KNOWN_LIMITATIONS.md entry 11.
If the root is an Obsidian vault, exclude .obsidian, .trash, and
*sync-conflict* before that first ingest. A symlinked folder is indexed under
the link path and comes back STALE under the real path.
Use it as a CI drift gate
The same verify loop works on a repo: claims in docs pinned to passages of
code or policy, chamber verify --json failing the build when the ground
moves. One line in a workflow — this repo ships the action:
- uses: abm9111/chamber@v0.1.9docs/CI_DRIFT_GATE.md is the one-page recipe;
demos/06_ci_drift_gate.ts is the runnable
transcript.
Run it daily
deploy/launchd/com.chamber.verify.plist (macOS) and deploy/systemd/
(Linux) run ingest and verify on a schedule, and raise a notification only when
something drifted. A check that correctly reports nothing on most days is a
check you stop reading, so it stays quiet until it isn't.
Render it in Obsidian
The companion plugin Chamber Drift
renders verify --json's report as a vault sidebar panel and a per-note
banner — nothing more. It never verifies and never writes; Chamber does both,
on its own schedule, outside Obsidian. Setup, including the report-writing
one-liner and the Obsidian Sync caveat: docs/OBSIDIAN.md.
Use it from an AI coding agent
An agent that reads your vault with its own tools can check what it is about
to tell you. chamber_check takes the agent's claims and the notes it says
they came from, and answers per claim (abridged):
[SUPPORTED] One NVIDIA A100 80GB or an L40S can serve about 1,000 users for code completion.
found in: ai-coding-setups-march-2026.md#p25
[TERMS_ABSENT] One NVIDIA A100 80GB can serve about 2,000 users for code completion.
the cited text does not contain: 2000The check uses no model. It confirms the note is indexed, and unchanged on disk since
it was indexed (STALE otherwise: the agent read one text and the index holds
another, so neither verdict would be about what was read). Then it checks that
every number, capitalised name, domain, file name and count in the claim occurs
in the note. That catches invented values. It does not check lowercase names or
ordinary words, and it does not catch a negated or reversed sentence
built from the note's own words — see
docs/KNOWN_LIMITATIONS.md §2 for what it was
measured to catch. It writes nothing unless called with record: true. Then
the supported claims are committed through the gate, pinned to the passages
that hold them, and chamber_verify reports any whose pinned passage changes,
once the note is re-ingested.
The server tells the host this in its MCP instructions, which Claude Code
puts in the agent's context. That is a prompt contract, not a runtime gate.
Four tools, not three. chamber_check is the one above. The other three cover
the rest: chamber_ask (Chamber's own configured model answers, with the same
per-claim verdicts), chamber_verify (drift in recorded claims) and
chamber_corpus (what is indexed). CHAMBER_PYTHON is optional, and only for
chamber_ask's semantic retrieval; a missing onnxruntime falls back to hash
vectors. Ingest stays on the CLI so the model cannot re-index its own evidence.
Register the server with the command above. That npx runs
the published bin (dist/).
The server re-reads config on every tool call, so an edit to model takes
effect on the next call without a reconnect; a CHAMBER_* variable set in the
server's own environment still outranks the file. The database is the
exception: it stays pinned for the life of the process, because a call may be
awaiting the model with it open — reconnect the server to switch databases.
The resolved database, mode and base go to stderr on first use and whenever
they change, so the host's MCP log can settle what the server is using.
Nothing on that surface can activate a skill, approve a pending write, or ingest — the gates exist so a human passes through them, and handing a model the approval side would invert them rather than weaken them.
chamber_ask is not read-only, and the write is not just bookkeeping: every
claim goes through the commit gate, so a claim with verified citations is
recorded as a belief with its pins — which is exactly what chamber verify
later re-checks for drift. Unsourced assertions mint citation debt; spend is
recorded. This is the same behaviour as chamber ask on the command line. The
guarantee is that the gate is not bypassed, not that nothing is written.
What a verified citation does and does not prove
Chamber proves a cited passage is the passage it claims to be — unmodified, still present, still saying what the citation says it says.
It cannot tell you the claim follows from the passage. A model can cite a real source and misread it, and every layer here will pass it. That is a stated non-goal, it has been observed happening, and it is not solved.
Read docs/KNOWN_LIMITATIONS.md before trusting
any output. Eighteen limitations are documented there, including the two least
flattering. The sandbox does not isolate: a docker detection can relabel to a
subprocess, CHAMBER_SANDBOX_REQUIRED=1 does not fail closed, and a probed run
read $HOME and resolved DNS (docs/KNOWN_LIMITATIONS.md §1). That path is off
chamber_check. Do not read "sandbox" as containment. Citation debt blocks a
verbatim repeat reliably, while the paraphrase leg over it is a heuristic:
calibration found no cosine threshold that separates a restatement from a
contradiction. A numeric and negation check now removes the worst of that — an
operator correcting an indebted claim is no longer refused for restating it —
but two of five true paraphrases still slip through, and a contradiction that
is neither numeric nor negated still reads as a repeat.
The invariant
No assertion may become executable, citable, or load-bearing except through a gate whose check and write commit in one transaction — anything else may decay, park, or be defeated, but it may never silently pass.
Gate | Blocks when |
| assertion with open blocking citation debt; missing or unverifiable pins; a defeater used as a source; a belief-typed commit on the fast path |
| open holds; load-bearing stale beliefs; content ≠ last critic-cleared hash; capability manifest over-ask |
Both gates write into a hash-chained audit log — entry_hash = sha256(prev_hash || canonical JSON) with an incremental Merkle tree — so altering a past
decision breaks every hash after it. Retraction types (defeater, unknown)
commit freely and never mint blocking debt.
Defaults are refusals: memory and skill writes require approval, learned skills land in quarantine rather than applying silently, and a pending write that expires is not an approved one.
Development
npm test # 308 tests
npm run typecheck
npm run probes # adversarial probes; each one asserts a defect is absentnpm run probes passes today, and that statement is dated the moment it is
written — run it rather than trust it. Two of these probes (sandbox_escape,
debt_paraphrase) spent weeks red against real, open defects before their
fixes landed, and they are wired in as gates precisely because they can go red
again. A gate that cannot fail reports safety it never checked.
Layout
src/ask.ts retrieval → prompt → per-claim citation gate
src/mcp_server.ts MCP surface: ask, check, verify, corpus
src/commit_belief.ts the belief gate; check and write in one transaction
src/pins.ts content pins and drift verification
src/audit.ts hash-chained log + incremental Merkle
src/config.ts settings: flag → env → config file → default
src/db.ts opens the database, loads every schema
probes/ adversarial probes, run by npm run probes
demos/ the four scenarios above, run in CI so they cannot rot
docs/KNOWN_LIMITATIONS.md what does not work, and what it costs
docs/NEXT_LEVEL_PLAN.md historical plan; several items already shippedMIT.
Available Tools
4 toolschamber_askA
Have Chamber's own configured model answer a question from the user's notes, with every claim judged against its own citations. To check an answer you wrote yourself, use chamber_check instead. Each claim comes back ALLOWED (its cited passages verified against their stored hashes) or UNSUPPORTED (no verified source — recorded, not load-bearing). Cited sources are returned as file#passage references you can open. Answers only from the indexed corpus; says so when nothing matches. NOTE: this WRITES, exactly as chamber ask does — each claim goes through the commit gate, so a claim with verified citations is recorded as a belief with its pins (which is what chamber_verify later checks for drift), an unsourced assertion mints citation debt, and spend is recorded. It cannot bypass that gate, activate a skill, or approve a pending write.
| Name | Required | Description | Default |
|---|---|---|---|
| exact | No | Retrieve only passages containing the question as a literal phrase. Narrowing; use for identifiers and codenames. | |
| strict | No | Refuse assertions that have no verified source instead of minting citation debt for them. Default false. | |
| question | Yes | The question to ask. | |
| semantic | No | Vector-only retrieval, switching off the lexical leg that runs alongside it by default. Contradicts `exact`. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations declare readOnlyHint=false/idempotentHint=false, and the NOTE goes well beyond them: it spells out the commit gate, that verified claims become beliefs with pins, that unsourced assertions mint citation debt, that spend is recorded, and what it cannot do (bypass the gate, activate a skill, approve a pending write). This is unusually rich disclosure for a write tool.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Purpose and the routing alternative are front-loaded, and the return semantics (ALLOWED/UNSUPPORTED, file#passage refs) come before the NOTE. The NOTE is long but each clause carries distinct behavioral information; slightly dense rather than wasteful.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no output schema, the description still explains return values (ALLOWED vs UNSUPPORTED and their meaning, openable file#passage references) and the corpus-only limitation. For a write tool with non-idempotent semantics, the commit-gate and side-effect disclosure makes it complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so exact/semantic/strict are already documented in the schema (including that semantic contradicts exact). The description's mention of citation-debt minting and strict refusal adds context for strict's effect, but it does not add syntax or format meaning beyond the schema; baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource (have Chamber's configured model answer a question from the user's notes) plus the scope (only from the indexed corpus). It explicitly names the sibling it is not (chamber_check) and distinguishes the check-your-own-answer case, so an agent can route without opening a schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicit routing: 'To check an answer you wrote yourself, use chamber_check instead,' plus a stated boundary ('Answers only from the indexed corpus; says so when nothing matches'). When-to-use, when-not, and the named alternative are all present.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
chamber_checkA
Check your own claims against the user's notes before you state them. For each claim, give the note(s) it came from — the absolute path you read, a file.md#p3 ref from chamber_ask, or a passage id. Chamber confirms the note is indexed and unchanged on disk since indexing, then checks that every number, capitalised name, domain, file name and count in the claim occurs in that note. Verdicts: SUPPORTED, TERMS_ABSENT (names the missing terms), NO_TERMS (nothing specific to check), STALE (the note changed since indexing — not judged), NOT_FOUND, NO_SOURCE. The check uses no model and is deterministic. It does not check meaning — a negated claim built from the note's own words passes. Read-only unless record is true, which commits SUPPORTED claims through Chamber's gate (which may run the local embedder to compare against open citation debt), pinned to the passages that hold their terms, so chamber_verify reports them if a pinned passage changes once the note is re-ingested; unsupported claims are never recorded.
| Name | Required | Description | Default |
|---|---|---|---|
| claims | Yes | The claims to check, each with the notes it came from. | |
| record | No | Commit SUPPORTED claims as beliefs with pinned sources, for drift checks by chamber_verify. Default false: nothing is written. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Goes well beyond the annotations: enumerates all six verdicts, states the check is deterministic and model-free, explains that STALE notes are not judged, and details what record=true actually does (commits through Chamber's gate, may run the embedder, pins sources for later chamber_verify drift detection). The 'read-only unless record is true' framing is consistent with readOnlyHint=false.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Front-loaded with the purpose in the first sentence, then layered detail. It is dense and somewhat run-on with stacked parentheticals, but nearly every clause carries distinct information (verdicts, limitations, record semantics) rather than filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with no output schema, the description fully compensates by enumerating every verdict string the caller will see and describing the record side effect. An agent has everything needed to call it correctly and interpret results.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the baseline is 3, but the description adds real meaning: it explains the three accepted source forms (absolute path, file.md#pN ref, passage id) and, crucially, what record=true commits and how the resulting beliefs are pinned and later checked. That is more than the schema's terse property descriptions provide.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource: checking the agent's own claims against the user's notes. It distinguishes itself from siblings by naming chamber_ask as a source of refs and chamber_verify as the drift-check consumer, so an agent can place it in the workflow without opening schemas.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly says when to use it ('check your own claims ... before you state them') and clarifies the read-only default versus record=true. It also gives a clear when-not: it does not check meaning, so negated claims pass. No direct 'use X instead of Y' exclusion, but the context is strong.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
chamber_corpusARead-onlyIdempotent
Report what is actually in the index: passage and file counts, source kinds and which of them are citable, the top contributing folders, and any file far above the median passage count (the signature of an export rather than a note). Use this before trusting a 'nothing matches' answer. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description adds behavioral detail beyond the readOnlyHint and idempotentHint annotations by specifying that the tool identifies files 'far above the median passage count' and interprets them as 'the signature of an export rather than a note.' It also explicitly states 'Read-only,' reinforcing the annotation without contradiction.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences: the first enumerates the tool's report contents, the second gives usage guidance and a safety note. Every clause adds value with no redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Despite having no parameters or output schema, the description thoroughly sets expectations: it lists the report contents, explains the outlier heuristic, and tells the agent when to invoke the tool. The 'Read-only' statement also confirms safety, making this a self-contained description.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool takes zero parameters, and the input schema already reflects this with an empty properties object. The description doesn't need to explain parameter usage, so the baseline of 4 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with 'Report what is actually in the index'—a specific verb and resource—and then enumerates the exact report contents (counts, source kinds, top folders, outliers). This clearly differentiates it from the sibling tools chamber_ask and chamber_verify, which are about querying rather than inspecting the corpus.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It provides an explicit trigger for use: 'Use this before trusting a "nothing matches" answer.' This is a clear context. However, it doesn't mention when not to use it or reference alternatives by name, so it's one step below full guidance.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
chamber_verifyARead-onlyIdempotent
Re-check every stored belief's pinned sources against the corpus as it stands now, and report the ones whose evidence moved: a source that no longer exists (not_found) or whose text changed under the pin (hash_mismatch). This is drift detection — the conclusion did not change, the ground under it did. Read-only.
| Name | Required | Description | Default |
|---|---|---|---|
| since | No | Only check beliefs committed at or after this date (any format Date can parse, e.g. 2026-07-01). Omit to check all. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description adds behavioral detail beyond the annotations by explaining that the tool reports sources that no longer exist or whose text changed, and that it does not change conclusions. It explicitly states 'Read-only' matching annotations and clarifies the meaning of results, providing useful context.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two concise sentences, with the main action front-loaded. The second sentence adds conceptual context without redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
This tool has a simple optional param, no output schema, and annotations cover read-only/idempotent. The description explains what the tool reports and the meaning of results, making it complete for an agent to understand when and how to invoke it.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema fully describes the only parameter 'since' with its purpose and default behavior. The description adds no additional parameter information, but since schema coverage is 100%, the baseline of 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool re-checks stored beliefs' pinned sources against the current corpus and reports those whose evidence moved, specifying outcome types (not_found, hash_mismatch). It identifies this as drift detection, which distinctively separates it from sibling tools like chamber_ask and chamber_corpus.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explains that the tool is for drift detection, providing clear context for when it should be used. However, it does not explicitly state when not to use it or mention alternatives, so it lacks explicit exclusions.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v0.1.8- Added
chamber_check
3 tool updates
v0.1.2- First observed
chamber_ask - First observed
chamber_corpus - First observed
chamber_verify
TDQS
Scored across 4 tools
The four tools are largely distinct: ask generates answers, check validates the agent's own claims, verify detects drift on stored beliefs, and corpus reports index contents. The ask/check boundary and check/verify boundary could be momentarily confused since all involve citation judgment, but descriptions explicitly cross-reference each other and clarify intent.
All four tools use the same chamber_<verb> prefix pattern (chamber_ask, chamber_verify, chamber_check, chamber_corpus). Fully predictable and consistent.
Four tools is a tight, well-scoped set for a citation-grounded Q&A/verification system, with each tool covering a distinct operation. It is on the lean side but nothing feels redundant or missing at the count level.
Core workflows (ask, self-check, drift verify, corpus introspection) are covered, but there is no tool to ingest/re-index notes despite check and verify depending on re-ingestion, and no way to inspect stored beliefs or citation debt directly. These are notable gaps an agent would hit when trying to manage the corpus lifecycle.
Maintenance
Related MCP Connectors
Personal context for every AI: search, read, and write back to your private Markdown library.
Self-hostable shared brain for you and your AI agents — docs, flows, meetings, decisions, rationale
Portable AI memory shared across models and harnesses - plain markdown you own.
Open-source Obsidian for MDX - edit local docs with agent assistance
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceA local-first CLI and MCP server that helps you build and search a personal knowledge vault from Markdown notes, with semantic search and AI-powered features like stale note detection and session memory harvesting. It’s provider-agnostic, requires no GPU in its default mode, and exposes your vault as long-term memory to any MCP-compatible AI tool like Claude Code.62 PyPI47Apache 2.0
- AlicenseNot gradedqualityCmaintenanceLocal-first MCP server for indexing and searching research materials (papers, notes, logs, READMEs) using SQLite FTS, with tools for memory management and evidence retrieval.MIT
- AlicenseBqualityAmaintenancePersonal multi-LLM memory repository using Markdown as source of truth, SQLite FTS5 for retrieval, and MCP tools for search, context, and write proposals.74Apache 2.0
- AlicenseAqualityBmaintenanceQueryable second brain over your notes, docs, PDFs and chat exports — hybrid retrieval, cited answers, MCP server included949 PyPI100MIT