lumen — security grade SAFE, quality 66/100

Security audit verdict: SAFE · quality 66/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by ory · MCP Server · ★ 244

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is lumen safe to install? View the security audit →

About lumen

Claude reads entire files to find what it needs. Lumen gives it a map. Lumen is a 100% local semantic code search engine for AI coding agents. No API keys, no cloud, no external database, just open-source embedding models (Ollama or LM Studio), SQLite, and your CPU. A single static binary and your own local embedding server. The payoff is measurable and reproducible: across 9 benchmark runs on 9 languages and real GitHub bug-fix tasks, Lumen cuts cost in every single language — up to 39%. Output tokens drop by up to 66%, sessions complete up to 53% faster, and patch quality is maintained in every task. All verified with a transparent, open-source benchmark framework that you can run yourself.

agentic-codingclaudeclaude-aiclaude-codeclaude-plcodexcontextgeminigolanggpt-5

Quick Facts

Stars244
Forks28
LanguageGo
CategoryMCP Server
Quality Score65.976774771677/100
Open Issues20
Last Updated2026-08-11
Created2026-02-27
Platformsclaude-code, codex, gemini, go, mcp
Est. Tokens~20k

Compatible Skills

These tools work well together with lumen for enhanced workflows:

  • ox — semantic(0.19)+complementary+same_lang+similar_pop+shared_platform (52%)
  • pockode — semantic(0.18)+complementary+same_lang+similar_pop+shared_platform (51%)

lumen alternative? Top 6 similar tools

Looking for a lumen alternative? If you're comparing lumen with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • Overture by SixHq · ⭐ 641

    Overture is an open-source, locally running web interface delivered as an MCP (Model Context Protocol) server

  • ask-user-questions-mcp by paulp-o · ⭐ 147

    Better 'AskUserQuestion' - A lightweight MCP server/OpenCode plugin/Agent Skills + CLI tool that allows your L

  • claude-delegator by jarrodwatts · ⭐ 987

    Delegate tasks to Codex and Gemini directly from within Claude Code.

  • claude-talk-to-figma-mcp by arinspunk · ⭐ 662

    A Model Context Protocol (MCP) that allows Claude Desktop and other AI tools (Claude Code, Cursor, Antigravity

  • postman-mcp-server by postmanlabs · ⭐ 316

    Postman MCP Server — connect AI agents (Claude Code, Cursor, VS Code Copilot, Gemini CLI) to your Postman coll

  • holysheep-cli by holysheep123 · ⭐ 292

    🐑 One command to configure all AI coding tools — Claude Code, Codex, Gemini CLI, Cursor, Aider & more

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Go Agent Tools

Frequently Asked Questions

What is lumen?

lumen is Save 30% token costs when using Claude Code, Codex, OpenCode for free - with open source, local semantic search. Works for small and large codebases and monorepos! Enterprise-ready and fully compliant. It is categorized as a MCP Server with 244 GitHub stars.

What programming language is lumen written in?

lumen is primarily written in Go. It covers topics such as agentic-coding, claude, claude-ai.

How do I install or use lumen?

You can find installation instructions and usage details in the lumen GitHub repository at github.com/ory/lumen. The project has 244 stars and 28 forks, indicating an active community.

What are the best alternatives to lumen?

The top alternatives to lumen on Agent Skills Hub include Overture, ask-user-questions-mcp, claude-delegator. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools