AlephBLOCK
Skill + MCP server to turn your agent into an RLM. Load context, iterate with search/code/think tools, converge on answers.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](LICENSE) [](https://www.python.org/downloads/) [](https://pypi.org/project/aleph-rlm/)
Aleph is an MCP server and skill for Recursive Language Models (RLMs). It keeps working state — search indexes, code execution, evidence, recursion — in a Python process outside the prompt window, so the LLM reasons iteratively over large codebases, long-lived projects, logs, documents, and data without burning context on raw content.
+-----------------+ tool calls +-----------------------------+ | LLM client | ---------------> | Aleph (Python process) | | (context budget)| <--------------- | search / peek / exec / sub | +-----------------+ small results +-----------------------------+
Why Aleph:
- Load once, reason many times. Data lives in Aleph memory, not the prompt.
- Compute server-side.
exec_pythonruns code over the full context and
returns only derived results. For JS/TS repos, exec_javascript and exec_typescript provide a persistent Node.js runtime over the same ctx.
- Recurse. Sub-queries and recipes split complex work across multiple
reasoning passes.
- Keep workspaces warm. Bind contexts back to files or generated workspace
manifests, refresh them, and resume long investigations later.
Quick Start
pip install "aleph-rlm[mcp]" aleph-rlm install --profile claude # or: codex, portable, api aleph-rlm doctor # verify everything is wired up
Then restart your MCP client and confirm Aleph is available:
get_status() list_contexts()
The optional /aleph (Claude Code) or $aleph (Codex) skill shortcut starts a structured RLM workflow. Install docs/prompts/aleph.md into your client's comman
525080fef9d5OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add aleph-rlm --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env LANGSMITH_API_KEY=${LANGSMITH_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- uvx aleph-rlm{
"mcpServers": {
"aleph-rlm": {
"command": "uvx",
"args": [
"aleph-rlm"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"LANGSMITH_API_KEY": "${LANGSMITH_API_KEY}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}"
}
}
}
}Exposed tools (2)
1 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add | write | return a + b |
echo | read | return text |
Trust audit
BLOCKgrade D · trust 65/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (7 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (13)
exec(exec_code, self._namespace, self._namespace)
ret = eval(eval_code, self._namespace, self._namespace)
return importlib.import_module(module_name)
module = importlib.import_module(module_name)
server_url: str = "http://127.0.0.1:8765/mcp"
_url = base_url or os.getenv("ALEPH_LLAMACPP_URL", "http://127.0.0.1:8080")p = LlamaCppProvider(api_key="sk-should-be-ignored")
export ALEPH_LLAMACPP_URL=http://127.0.0.1:8080
| `ALEPH_LLAMACPP_URL` | llama-server URL | `http://127.0.0.1:8080` |
export ALEPH_LLAMACPP_URL=http://127.0.0.1:8080
docs/2512.24601v1.pdf
When a user says "use claude backend" or "switch to gemini", call
**macOS/Linux** (add to ~/.zshrc or ~/.bashrc):
Gates applied: no_behavioural_pass.
525080fef9d5full audit observations/trust-audit/mcp-server/hmbown__aleph.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 525080fef9d5 | BLOCK | D | 65 | first audit |
Questions
What is the Aleph MCP server?
Skill + MCP server to turn your agent into an RLM. Load context, iterate with search/code/think tools, converge on answers.
What tools does Aleph expose?
2 in total: 1 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Aleph safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (65/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Aleph need?
It reads ANTHROPIC_API_KEY, LANGSMITH_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Aleph run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as aleph-rlm.
How current is this page?
The grade is for one exact copy of the source (525080fef9d5), read on 2026-10-06. The repository is watched and re-audited when it changes.