Atlas / MCP servers / hmbown / Aleph

AlephBLOCK

mcp/hmbown/aleph

Skill + MCP server to turn your agent into an RLM. Load context, iterate with search/code/think tools, converge on answers.

Verdict
BLOCK
Grade
D
Trust score
65 /100
Exposed tools
2 1r · 1w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
218
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](LICENSE) [](https://www.python.org/downloads/) [](https://pypi.org/project/aleph-rlm/)

Aleph is an MCP server and skill for Recursive Language Models (RLMs). It keeps working state — search indexes, code execution, evidence, recursion — in a Python process outside the prompt window, so the LLM reasons iteratively over large codebases, long-lived projects, logs, documents, and data without burning context on raw content.

+-----------------+    tool calls     +-----------------------------+
|   LLM client    | ---------------> |  Aleph (Python process)     |
| (context budget)| <--------------- |  search / peek / exec / sub |
+-----------------+   small results  +-----------------------------+

Why Aleph:

  • Load once, reason many times. Data lives in Aleph memory, not the prompt.
  • Compute server-side. exec_python runs code over the full context and

returns only derived results. For JS/TS repos, exec_javascript and exec_typescript provide a persistent Node.js runtime over the same ctx.

  • Recurse. Sub-queries and recipes split complex work across multiple

reasoning passes.

  • Keep workspaces warm. Bind contexts back to files or generated workspace

manifests, refresh them, and resume long investigations later.

Quick Start

pip install "aleph-rlm[mcp]"
aleph-rlm install --profile claude   # or: codex, portable, api
aleph-rlm doctor                     # verify everything is wired up

Then restart your MCP client and confirm Aleph is available:

get_status()
list_contexts()

The optional /aleph (Claude Code) or $aleph (Codex) skill shortcut starts a structured RLM workflow. Install docs/prompts/aleph.md into your client's comman

Read from source at commit 525080fef9d5OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add aleph-rlm --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env LANGSMITH_API_KEY=${LANGSMITH_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- uvx aleph-rlm
claude-desktop
{
  "mcpServers": {
    "aleph-rlm": {
      "command": "uvx",
      "args": [
        "aleph-rlm"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "LANGSMITH_API_KEY": "${LANGSMITH_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (2)

1 read · 1 write · 0 destructive.

ToolRiskDescription
addwritereturn a + b
echoreadreturn text
04

Trust audit

BLOCKgrade D · trust 65/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (7 observation(s))
Shell
declared (4 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (13)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
aleph/repl/sandbox.py:789
exec(exec_code, self._namespace, self._namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
aleph/repl/sandbox.py:791
ret = eval(eval_code, self._namespace, self._namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
aleph/integrations/langgraph_rlm.py:104
return importlib.import_module(module_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
aleph/mcp/io_utils.py:126
module = importlib.import_module(module_name)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
aleph/integrations/langgraph_rlm.py:80
server_url: str = "http://127.0.0.1:8765/mcp"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
aleph/providers/llamacpp.py:64
_url = base_url or os.getenv("ALEPH_LLAMACPP_URL", "http://127.0.0.1:8080")
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/test_llamacpp_provider.py:67
p = LlamaCppProvider(api_key="sk-should-be-ignored")
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:172
export ALEPH_LLAMACPP_URL=http://127.0.0.1:8080
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CONFIGURATION.md:35
| `ALEPH_LLAMACPP_URL`                 | llama-server URL                                  | `http://127.0.0.1:8080`      |
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/CONFIGURATION.md:77
export ALEPH_LLAMACPP_URL=http://127.0.0.1:8080
INFOInventory / provenance · inv.oversize · CWE-1104
docs/2512.24601v1.pdf
docs/2512.24601v1.pdf
Why it matters. 8250587 bytes not read
INFOPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
docs/prompts/aleph.md:412
When a user says "use claude backend" or "switch to gemini", call
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
docs/prompts/install-aleph.md:129
**macOS/Linux** (add to ~/.zshrc or ~/.bashrc):
Why it matters. instructs the agent to persist itself in the user's environment

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 525080fef9d5full audit observations/trust-audit/mcp-server/hmbown__aleph.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06525080fef9d5BLOCKD65first audit
06

Questions

What is the Aleph MCP server?

Skill + MCP server to turn your agent into an RLM. Load context, iterate with search/code/think tools, converge on answers.

What tools does Aleph expose?

2 in total: 1 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Aleph safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (65/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Aleph need?

It reads ANTHROPIC_API_KEY, LANGSMITH_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Aleph run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as aleph-rlm.

How current is this page?

The grade is for one exact copy of the source (525080fef9d5), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement