Atlas / MCP servers / kuvopllc / Better Bear

Better BearSAFE

mcp/kuvopllc/better-bear-1

MCP server for Bear notes — read, search, create, edit, tag, and manage notes via CloudKit

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
32 17r · 9w · 6d
Transport
stdio
License
MIT
Stars
66
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://glama.ai/mcp/servers/KuvopLLC/better-bear)

[](https://github.com/KuvopLLC/better-bear/actions/workflows/build-on-merge.yml) [](https://github.com/KuvopLLC/better-bear/releases/latest) [](https://www.npmjs.com/package/better-bear) [](https://github.com/KuvopLLC/better-bear/blob/main/LICENSE) [](https://glama.ai/mcp/servers/KuvopLLC/better-bear) [](https://buymeacoffee.com/mreider)

MCP server and CLI for Bear notes via CloudKit. Includes a context library — a curated, synced folder of notes optimized for LLM consumption, inspired by Karpathy's LLM Knowledge Base pattern.

Full docs: [better-bear.com](https://better-bear.com)

Install

Install the CLI, then connect to Claude:

curl -sL https://raw.githubusercontent.com/KuvopLLC/better-bear/main/install.sh | bash
bcli auth
bcli mcp install

This installs the bcli binary, authenticates with iCloud, and sets up the MCP server for both Claude Desktop (via .mcpb bundle) and Claude Code.

Other install methods

Read from source at commit d94c2ad024f3OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add better-bear -- npx -y [email protected]
03

Exposed tools (32)

17 read · 9 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
bear_add_tagwriteAdd a tag to an existing Bear note. The tag is inserted into the note
bear_archive_notedestructiveArchive a Bear note. Archived notes are hidden from the main list but not deleted. Use
bear_attach_filereadAttach a file or image to an existing Bear note. The file is uploaded to iCloud and embedded in the note
bear_context_addwriteAdd a Bear note to the context library by tagging it with #context. Optionally specify a subtag for grouping (e.g., subtag
bear_context_fetchreadLoad the full content of specific files from the context library. Pass relative paths like
bear_context_indexreadGet the context library index — a structured table of contents of all files (Bear notes, external files, inbox). Read this FIRST before answering questions from context. Use it to identify which files to fetch, rather than loading everything. Includes cache freshness metadata.
bear_context_ingestreadScan the inbox/ directory and list all untriaged files. Returns filename, size, content preview (first 500 chars), and any detected YAML front matter for each file. Does NOT modify anything — use bear_context_triage to act on files.
bear_context_push_to_bearwritePush an external file to Bear as a new note. Creates a Bear note from the file content, tags it with #context (+ optional subtag), and removes the original external file. Use when external content has matured enough to become a permanent Bear note.
bear_context_removedestructiveRemove a Bear note from the context library by removing its #context tag. Triggers a sync to delete the local file.
bear_context_remove_externaldestructiveRemove a file from the external/ directory in the context library. Deletes the file and regenerates the index. Use when external content is no longer needed.
bear_context_searchreadFull-text search across the entire context library (Bear notes + external files + inbox). Returns matching snippets with filenames and origin labels. Use when the index alone isn
bear_context_set_prefixwriteChange the context library
bear_context_setupreadInitialize a context library — a curated, synced folder of Bear notes optimized for LLM consumption. Creates the directory structure and config. After setup, tag Bear notes with #context (or a custom prefix) and use bear_context_sync to pull them in. One-time operation.
bear_context_statusreadGet context library health and stats: Bear note count, external file count, inbox count, total tokens, last sync time, group breakdown, and warnings (stale cache, expired externals, oversized files, untriaged inbox items).
bear_context_triagereadTriage a file in the inbox. Three actions:
bear_create_notewriteCreate a new Bear note with a title, optional body text, tags, and YAML front matter. Hashtags written inline in the body (e.g.
bear_delete_tagdestructiveDelete a tag from all Bear notes. The tag text is removed but notes are preserved.
bear_edit_notewriteEdit an existing Bear note. Provide
bear_find_duplicatesreadFind notes with duplicate titles. Returns groups of notes sharing the same title with their IDs and modification dates. Useful for cleaning up after imports or sync conflicts.
bear_find_untaggedreadList Bear notes that have no tags assigned.
bear_get_notereadGet a single Bear note
bear_get_tagsreadGet the full tag hierarchy from Bear. Returns all tags with their note counts and pin status. Useful for understanding how notes are organized.
bear_get_todosreadGet all TODO items from a specific Bear note. Returns each item
bear_health_checkwriteRun a health check on the Bear notes library. Reports duplicate titles, empty notes, notes stuck in trash, sync conflicts, orphaned tags, untagged notes, and oversized notes. Use this to identify cleanup opportunities or diagnose sync issues.
bear_list_notesreadList Bear notes with optional tag filtering. Returns an array of notes with IDs, titles, tags, pin status, and modification dates. Each note includes two tag fields:
bear_list_todosreadList Bear notes that have incomplete TODO items (markdown checkboxes like
bear_note_statsreadGet statistics about the Bear notes library: total notes, words, tags, pinned, archived, trashed, notes with TODOs, oldest/newest dates, and top 10 tags by note count.
bear_remove_tagdestructiveRemove a tag from a specific Bear note. Works on any tag visible in
bear_rename_tagwriteRename a tag across all Bear notes. Every note containing the old tag will be updated.
bear_syncwriteTrigger a sync of Bear notes from iCloud. Normally an incremental sync fetching only changes. Use
bear_toggle_todoreadToggle a specific TODO item in a Bear note between complete and incomplete. The item_index is 1-based — use bear_get_todos first to see the list with index numbers.
bear_trash_notedestructiveMove a Bear note to the trash. This is a soft delete — the note can be recovered from Bear
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (11)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
bear_archive_note, bear_context_remove, bear_context_remove_external, bear_delete_tag, bear_remove_tag, bear_trash_note
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
mcp-server/.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
mcp-server/test-integration.sh:7
BCLI="${BCLI:-../../.build/debug/bcli}"
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
mcp-server/package.json
@modelcontextprotocol/sdk, @types/node, typescript
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
PRD.md:174
5. All subsequent bcli operations read from Keychain.
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:21
curl -sL https://raw.githubusercontent.com/KuvopLLC/better-bear/main/install.sh | bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/index.html:232
<button class="copy-btn" onclick="navigator.clipboard.writeText('curl -sL https://raw.githubusercontent.com/KuvopLLC/better-bear/main/install.sh | bash');this.textContent='Copied!'">Copy</button>
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/index.html:233
<code>curl -sL https://raw.githubusercontent.com/KuvopLLC/better-bear/main/install.sh | bash
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
mcp-server/README.md:15
curl -sL https://raw.githubusercontent.com/KuvopLLC/better-bear/main/install.sh | bash
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/privacy.html:69
<p>When used as an MCP server, Better Bear communicates with the MCP client (Claude Desktop or Claude Code) over local stdio pipes. Note content is passed between the MCP server process and the client
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
mcp-server/README.md:91
Better Bear does not collect, transmit, or store any personal data on external servers. Authentication tokens and note caches are stored locally on your machine. Network requests go only to Apple Clou
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha d94c2ad024f3full audit observations/trust-audit/mcp-server/kuvopllc__better-bear-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07d94c2ad024f3SAFEB89first audit
06

Questions

What is the Better Bear MCP server?

MCP server for Bear notes — read, search, create, edit, tag, and manage notes via CloudKit

What tools does Better Bear expose?

32 in total: 17 read-only, 9 that write, and 6 that can delete or overwrite (bear_archive_note, bear_context_remove, bear_context_remove_external, bear_delete_tag, bear_remove_tag). Every one is listed on this page with its risk.

Is Better Bear safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Better Bear need?

No credential environment variables were found in its source, so it appears to need none.

How does Better Bear run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as better-bear at 0.4.1.

How current is this page?

The grade is for one exact copy of the source (d94c2ad024f3), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement