No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by shenmintao · LLM Plugin · ★ 237
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is marginalia safe to install? View the security audit →
Marginalia Chinese README: README.zh-CN.md Detailed design: DESIGN.md Turn your PDFs, notes, spreadsheets, logs, and archives into a private AI library that answers from original sources. Marginalia is a local-first research agent for people with messy private knowledge bases. It keeps your files in a normal folder tree, builds useful library metadata around them, and makes the agent read the relevant original file windows before it writes a cited answer. Download desktop app · CLI quickstart · Usage guide · Design notes Why Use It You have research papers, meeting notes, PDFs, tables, logs, screenshots, and archives that do not fit cleanly into one app. You want answers that cite the source material instead of a black-box vector search layer over chunks. You need both quick lookups and slower investigation-style reports over the same private library. You want local-first storage: the default backend keeps your library as readable files under . What It Does Ingests text, Markdown, PDFs, DOCX, images, spreadsheets, logs, and archives. Organizes material with folders, catalogs, tags, views, metadata, journals, and relation mining.
| Stars | 237 |
| Forks | 31 |
| Language | Python |
| Category | LLM Plugin |
| License | AGPL-3.0 |
| Quality Score | 66.9809606784692/100 |
| Last Updated | 2026-09-01 |
| Created | 2026-05-23 |
| Platforms | docker, python |
| Est. Tokens | ~17k |
These tools work well together with marginalia for enhanced workflows:
Looking for a marginalia alternative? If you're comparing marginalia with other llm plugin tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.
Local AI-powered document search and editing with first-in-class hybrid retrieval, LLM answers, WebUI, REST AP
Open-source semantic document search (RAG) engine with FastAPI and instant self-hosted deployment
Self-hosted RAG platform for AI document search across GitHub, Notion, Google Drive, local files, and web sour
Local-first AI memory archive. Import ChatGPT, Claude, and Grok exports, generate semantic embeddings, and sea
Open-source knowledge base for people and AI agents. Rich-text editing, hybrid search, GraphRAG, and MCP. Self
Local-first AI PKM for coding conversations: import Claude Code/Cursor/Codex, distill notes, semantic search,
Explore other popular llm plugin tools:
marginalia is A library-science-inspired personal knowledge management system with LLM agents. It is categorized as a LLM Plugin with 237 GitHub stars.
marginalia is primarily written in Python. It covers topics such as apple-silicon, arm64, desktop-app.
You can find installation instructions and usage details in the marginalia GitHub repository at github.com/shenmintao/marginalia. The project has 237 stars and 31 forks, indicating an active community.
marginalia is released under the AGPL-3.0 license, making it free to use and modify according to the license terms.
The top alternatives to marginalia on Agent Skills Hub include gno, Flamehaven-Filesearch, OpenDocuments. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: