26 sources.
One question.
Knowledge lives across different formats, authorities, and naming systems.
01 - source sprawlA research teammate for the agentic security stack
BlackBook turns scattered cybersecurity research into answers an AI agent can actually defend - indexed, ranked, and linked back to the exact source excerpt.
One investigation can touch writeups, cheat sheets, standards, PDFs, and bug bounty reports. The signal is there - buried under tabs, duplicated evidence, and sources that refuse to agree.
Knowledge lives across different formats, authorities, and naming systems.
01 - source sprawlAn answer without an exact excerpt is only a confident guess.
02 - citation debtLexical hits alone cannot connect a technique to the case around it.
03 - missing contextBlackBook is not query → embedding → dump. It is a deliberate retrieval pipeline that keeps the corpus visible at every step.
Read the architecture ↗A research surface shaped for real investigations: diverse evidence, defensible answers, and a clean boundary between knowing and doing.
SQLite FTS5 BM25 is the always-available backbone. Optional local semantic search catches paraphrased questions without sending embeddings away.
Every result carries a reference that resolves through its chunk_id to the exact indexed text. BlackBook never fabricates a citation.
Evidence-linked relationships enrich technique dossiers and similar-case results. The knowledge graph makes retrieval smarter without ever blocking it.
No command execution. No host scanning. No arbitrary URL fetching. BlackBook tells the agent what is documented - another MCP can handle action.
Connect through MCP over stdio - the client spawns BlackBook for you. Or run a long-lived streamable HTTP server when the whole team needs one shared research surface.
See setup snippets ↗BlackBook is a local-first Python MCP. Install it with uv or pip, copy the example config, ingest your sources, then let your MCP client launch the stdio server.
Full installation guide ↗# clone the MCP
git clone https://github.com/Daniel-wambua/BlackBook.git
cd BlackBook
# recommended install
uv pip install -e .
# configure your local corpus
cp config.example.yaml ~/.blackbook/config.yaml
# ingest, then launch the MCP
blackbook ingest
blackbook serveReport archives are labeled with unknown authority and treated as local research data - not official guidance.
BlackBook keeps the honest parts of research visible: where the claim came from, how results were balanced, and what the corpus cannot answer.
Nothing is presented as fact unless it traces to an indexed source chunk.
Search a technique. Pull the exact section. Walk the graph. Find the similar case. Keep the agent grounded while it reasons.
Read the README ↗THE NEXT QUERY STARTS HERE