chamber
Checks that the numbers, capitalised names, and file names in a claim occur in the indexed note. Local, no model. It does not judge meaning. MIT.
Install / Use
claude mcp add abm9111 -- npx -y github:abm9111/chamberIf the server publishes to npm under a different name, use that package instead โ check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
Data & AnalyticsSupported Platforms
Our assessment of chamber
chamber scores 83/100 on our quality scale, 498th of 604 Data & Analytics skills we index.
Its MCP Server is 18 KB long, well organised into 17 sections with 15 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated yesterday, so chamber is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 92/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit โ read the skill file before letting an agent act on it.
chamber compared with similar skills
All 4 of these similar skills score higher than chamber; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| chamber (this skill)by abm9111 | 83 | 3 | 1d ago | MCP Server |
| claude-memby thedotmack | 100 | 99.5k | today | CLAUDE.md |
| Agent-Reachby Panniantong | 100 | 95.7k | 3d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 75.0k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.3k | today | CLAUDE.md |
Frequently asked questions
- How do I install chamber?
- Run
claude mcp add abm9111 -- npx -y github:abm9111/chamber. The install tabs above show the steps for each supported agent. - Which AI agents does chamber work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is chamber safe to use?
- It is MIT-licensed and scores 92/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is chamber still maintained?
- The repository was last updated yesterday, so chamber is actively maintained.
Skill content
View source on GitHubChamber
Catches your AI agent quoting a number or a name that isn't in the note it
cites. When Claude Code (or any MCP host) answers from your notes, it is told
to run each claim through chamber_check first. Real output, trimmed:
2 claim(s): 1 supported ยท 1 terms absent ยท 0 nothing to check ยท 0 not judged
[TERMS_ABSENT] Q3 revenue was $420k, up 18% on Q2.
the cited text does not contain: 420k
checked: q3-review.md#p0
[SUPPORTED] Enterprise renewals moved to Dana Ortiz in August.
every term Chamber recognises occurs in the cited text
checked: q3-review.md#p0
The note says $240k. The agent wrote $420k. Edit the note afterwards and
the same check returns STALE instead of a verdict, because what it is checking
against has changed.
claude mcp add -s user chamber -- npx -y @bu7umaid/chamber mcp
No model, no account, no network: the check is deterministic string matching
over node:sqlite and files on your disk. It checks numbers, capitalised
names, domains, file names and counts. It does not check meaning, so a negated
or reversed sentence built from the note's own words still passes. See
what a verified citation does and does not prove.
Beyond the check: answers that cite their sources, and a daily job that tells you when a source changed underneath a conclusion you already trusted.
Run the check
The npx line above is all most people need. Two other ways in:
From a checkout (Node 23.6+). TypeScript runs straight from the repo, with
no build step, config, model or network. try builds a throwaway workspace,
runs the real code paths and deletes it.
git clone https://github.com/abm9111/chamber.git && cd chamber && npm ci && node --experimental-strip-types src/cli.ts try
If /mcp does not list chamber_check, the host started the server with a
minimal PATH. Take the interpreter from command -v node in your own shell
and point it at the published bin or at a checkout's src/mcp_server.ts. Those
are different files:
# published bin: bin/chamber.js loads dist/. This is not src/mcp_server.ts.
claude mcp add -s user chamber -- "$(command -v node)" /path/to/node_modules/@bu7umaid/chamber/bin/chamber.js mcp
# checkout only. src/mcp_server.ts is not in the npm install.
claude mcp add -s user chamber -- "$(command -v node)" --experimental-strip-types /path/to/chamber/src/mcp_server.ts
Ingest and chamber_ask need config; the check does not. See
for ingest and chamber_ask.
What people actually do
There is no public trail of Chamber users yet. These are the adjacent failures on X, which are the reason the check exists.
- Pointing Claude Code at an Obsidian folder reads files. It does not check the sentence. Richard Kovacs, 28 Sep 2026: Claude returns a list of sources and he checks them. The remaining failure he names is confirmation bias, and he treats that as discipline.
- A tool the agent must remember to call is not a gate.
Saksham Arora, 2 Oct 2026:
a shared-memory MCP only recalled a session if the other agent decided to
search, so he put a hook before every message.
chamber_checkis the same shape. MCPinstructionsask Claude to call it. Nothing blocks the turn if it skips. A Stop hook that requires a receipt is the missing piece; it is not in this repo yet. - Viral vault posts (99.7% recall, thousands of links in minutes) are not
measurements. The number in this repo is the 200-claim set in
docs/KNOWN_LIMITATIONS.mdยง2: invented values mostly caught, negations not.
See it in two minutes
The checkout command above builds a throwaway workspace, runs the real code
paths against it, and deletes it (--keep to look around). It does not open
a database.

That recording is scripted from assets/demo.tape rather
than hand-captured, so it is regenerated when the output changes instead of
quietly showing a version of Chamber that no longer exists. Everything below is
that checkout command's actual output, trimmed:
$ chamber believe belief "Customers may return any purchase within 30 days of delivery."
committed blf_ddcf4f3c9b2e81b8
an unsourced assertion is not refused โ it mints citation debt.
$ chamber debts
dbt_18bd1c1171cdbfcb [pending]
$ chamber pay-debt
proposed 2 source(s), 2 pinned; best=0.694
$ chamber verify
blf_ddcf4f3c9b2e81b8 2/2 pins verified
That is the ordinary state: a belief standing on evidence that still holds. Then
someone edits the note it was built on โ 30 days becomes 14 days:
$ chamber ingest ./notes
ingested 2 file(s) as 4 passage(s)
$ chamber verify
blf_ddcf4f3c9b2e81b8 1/2 pins verified
hash_mismatch: refunds.md#p0
Nobody asked it to re-examine that belief. The conclusion did not change; the ground under it did, and the exit code is non-zero, so a scheduled job can act on it. That is the whole product.
Four more scenarios โ a rolled-back ledger caught by an outside anchor, a
sandbox that refuses rather than degrade, a hostile tool catalogue rejected โ
are in demos/, and run in CI so they cannot drift from the code.
A dictionary for the words above
Everything Chamber does is rows in one SQLite file. Each term in the transcripts names a table or a hash:
| Word | What it actually is |
|------|---------------------|
| passage | one chunk of one markdown file. refunds.md#p0 is file path + chunk index. |
| belief | a row in belief: one asserted sentence, linked to the passages it stands on. |
| pin | a sha-256 of a cited passage's stored title, body and ref, taken at the moment of citation and kept in belief_source. |
| verify | re-read every pinned passage, recompute the hash, compare. Any mismatch exits non-zero. No model involved. |
| citation debt | a row in citation_debt, created when an assertion commits with no source. The same claim cannot commit again until the debt is paid. |
| pay-debt | retrieval proposes passages for the indebted claim; accepting them pins them. |
| APORIA | the verdict when no retrieved passage supports an answer. The reply is "I don't know", recorded as that. |
| gate | a check and a write inside one SQLite transaction โ both commit or neither does. |
| audit log | append-only audit_event; each row's hash covers the previous row's hash, so editing history breaks every hash after it. |
| anchor | the log's root hash stored outside the database, so truncating the log is detectable rather than silent. |
| the scheduler | a launchd/systemd job running ingest + verify, notifying only on drift. |
None of it is hidden machinery: sqlite3 ~/.local/share/chamber/chamber.sqlite '.tables' shows the whole thing.
Answers that cite their sources
With a model configured, chamber ask judges every sentence on its own
citations. Against the same two sample notes, on a local 30B:
$ chamber ask "summarise our refund policy"
Customers may return any purchase within 30 days of delivery [2]. Refunds
are issued to the original payment method, usually within five working days
of the returned item arriving at the warehouse [2]. However, perishable goods
and personalised items cannot be returned once dispatched [1].
[ALLOWED] Customers may return any purchase within 30 days of delivery [2]. Refu
sources: refunds.md#p0 โ refunds โบ Refund policy, refunds.md#p1 โ refunds โบ Refund policy โบ Exceptions
The model is shown [1]โฆ[k] and never a document id or a hash, so it cannot
fabricate a citation even in principle โ the numbers are resolved back to files
after the answer is written. A sentence that cites nothing is marked
UNSUPPORTED: recorded, but not treated as load-bearing. A sentence whose
numbers, names or domains are not in the passage it cites loses that citation
too, and says which terms were missing (terms_absent) โ a real passage is not
evidence for a claim it does not contain. Headings in an answer print as
[HEADING] and are not recorded.
Asking something the corpus cannot answer is the more important case:
$ chamber ask "what should a customer do if they want to return a perishable
item after the office has closed?"
I don't know
[APORIA] I don't know
Both notes are in the index and both are relevant. Neither answers the question, so nothing is composed from the pieces.
For ingest and chamber_ask, not for the check
npm link # puts `chamber` on your PATH
chamber init # writes ~/.config/chamber/config.json
Then edit that config to add a notes folder and a model:
{
"database": "~/.local/share/chamber/chamber.sqlite",
"model": { "base": "http://127.0.0.1:8087/v1", "name": "your-model", "mode": "openai" },
"ingest": [{ "root": "~/Notes", "exclude": ["transcripts", "attachments"] }]
}
model.base may name any OpenAI-compatible endpoint. A loopback address needs
no API key; anything else reads CHAMBER_API_KEY from the environment, never
from the file.
chamber ingest # index every configured root
chamber ask "..." # ask, with citations
chamber verify # re-check stored pins against the corpus
chamber corpus # what is actually in the index
Set your excludes before the first ingest. There is no default exclude list.
Pointed at a folder of exported chat logs, Chamber will happily index all of
them and answer from them โ see chamber corpus and
docs/KNOWN_LIMITATIONS.md entry 11.
If the root is an Obsidian vault, exclude .obsidian, .trash, and
*sync-conflict* before that first ingest. A symlinked folder is indexed under
the link path and comes back STALE under the real path.
Use it as a CI drift gate
The same verify loop works on a repo: claims in docs pinned to passages of
code or policy, chamber verify --json failing the build when the ground
moves. One line in a workflow โ this repo ships the action:
- uses: abm9111/chamber@v0.1.9
docs/CI_DRIFT_GATE.md is the one-page recipe;
demos/06_ci_drift_gate.ts is the runnable
transcript.
Run it daily
deploy/launchd/com.chamber.verify.plist (macOS) and deploy/systemd/
(Linux) run ingest and verify on a schedule, and raise a notification only when
something drifted. A check that correctly reports nothing on most days is a
check you stop reading, so it stays quiet until it isn't.
Render it in Obsidian
The companion plugin Chamber Drift
renders verify --json's report as a vault sidebar panel and a per-note
banner โ nothing more. It never verifies and never writes; Chamber does both,
on its own schedule, outside Obsidian. Setup, including the report-writing
one-liner and the Obsidian Sync caveat: docs/OBSIDIAN.md.
Use it from an AI coding agent
An agent that reads your vault with its own tools can check what it is about
to tell you. chamber_check takes the agent's claims and the notes it says
they came from, and answers per claim (abridged):
[SUPPORTED] One NVIDIA A100 80GB or an L40S can serve about 1,000 users for code completion.
found in: ai-coding-setups-march-2026.md#p25
[TERMS_ABSENT] One NVIDIA A100 80GB can serve about 2,000 users for code completion.
the cited text does not contain: 2000
The check uses no model. It confirms the note is indexed, and unchanged on disk since
it was indexed (STALE otherwise: the agent read one text and the index holds
another, so neither verdict woul
Truncated for display โ read the full file on GitHub.
Related Skills
claude-mem
99.5kPersistent Context Across Sessions for Every Agent โ Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Agent-Reach
95.7kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu โ one CLI, zero API fees.
headroom
75.0kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.3kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit โ see the Safety scan above for what the skill file itself contains.
