Better BearSAFE
MCP server for Bear notes — read, search, create, edit, tag, and manage notes via CloudKit
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://glama.ai/mcp/servers/KuvopLLC/better-bear)
[](https://github.com/KuvopLLC/better-bear/actions/workflows/build-on-merge.yml) [](https://github.com/KuvopLLC/better-bear/releases/latest) [](https://www.npmjs.com/package/better-bear) [](https://github.com/KuvopLLC/better-bear/blob/main/LICENSE) [](https://glama.ai/mcp/servers/KuvopLLC/better-bear) [](https://buymeacoffee.com/mreider)
MCP server and CLI for Bear notes via CloudKit. Includes a context library — a curated, synced folder of notes optimized for LLM consumption, inspired by Karpathy's LLM Knowledge Base pattern.
Full docs: [better-bear.com](https://better-bear.com)
Install
Install the CLI, then connect to Claude:
curl -sL https://raw.githubusercontent.com/KuvopLLC/better-bear/main/install.sh | bash bcli auth bcli mcp install
This installs the bcli binary, authenticates with iCloud, and sets up the MCP server for both Claude Desktop (via .mcpb bundle) and Claude Code.
Other install methods
d94c2ad024f3OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add better-bear -- npx -y [email protected]
Exposed tools (32)
17 read · 9 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
bear_add_tag | write | Add a tag to an existing Bear note. The tag is inserted into the note |
bear_archive_note | destructive | Archive a Bear note. Archived notes are hidden from the main list but not deleted. Use |
bear_attach_file | read | Attach a file or image to an existing Bear note. The file is uploaded to iCloud and embedded in the note |
bear_context_add | write | Add a Bear note to the context library by tagging it with #context. Optionally specify a subtag for grouping (e.g., subtag |
bear_context_fetch | read | Load the full content of specific files from the context library. Pass relative paths like |
bear_context_index | read | Get the context library index — a structured table of contents of all files (Bear notes, external files, inbox). Read this FIRST before answering questions from context. Use it to identify which files to fetch, rather than loading everything. Includes cache freshness metadata. |
bear_context_ingest | read | Scan the inbox/ directory and list all untriaged files. Returns filename, size, content preview (first 500 chars), and any detected YAML front matter for each file. Does NOT modify anything — use bear_context_triage to act on files. |
bear_context_push_to_bear | write | Push an external file to Bear as a new note. Creates a Bear note from the file content, tags it with #context (+ optional subtag), and removes the original external file. Use when external content has matured enough to become a permanent Bear note. |
bear_context_remove | destructive | Remove a Bear note from the context library by removing its #context tag. Triggers a sync to delete the local file. |
bear_context_remove_external | destructive | Remove a file from the external/ directory in the context library. Deletes the file and regenerates the index. Use when external content is no longer needed. |
bear_context_search | read | Full-text search across the entire context library (Bear notes + external files + inbox). Returns matching snippets with filenames and origin labels. Use when the index alone isn |
bear_context_set_prefix | write | Change the context library |
bear_context_setup | read | Initialize a context library — a curated, synced folder of Bear notes optimized for LLM consumption. Creates the directory structure and config. After setup, tag Bear notes with #context (or a custom prefix) and use bear_context_sync to pull them in. One-time operation. |
bear_context_status | read | Get context library health and stats: Bear note count, external file count, inbox count, total tokens, last sync time, group breakdown, and warnings (stale cache, expired externals, oversized files, untriaged inbox items). |
bear_context_triage | read | Triage a file in the inbox. Three actions: |
bear_create_note | write | Create a new Bear note with a title, optional body text, tags, and YAML front matter. Hashtags written inline in the body (e.g. |
bear_delete_tag | destructive | Delete a tag from all Bear notes. The tag text is removed but notes are preserved. |
bear_edit_note | write | Edit an existing Bear note. Provide |
bear_find_duplicates | read | Find notes with duplicate titles. Returns groups of notes sharing the same title with their IDs and modification dates. Useful for cleaning up after imports or sync conflicts. |
bear_find_untagged | read | List Bear notes that have no tags assigned. |
bear_get_note | read | Get a single Bear note |
bear_get_tags | read | Get the full tag hierarchy from Bear. Returns all tags with their note counts and pin status. Useful for understanding how notes are organized. |
bear_get_todos | read | Get all TODO items from a specific Bear note. Returns each item |
bear_health_check | write | Run a health check on the Bear notes library. Reports duplicate titles, empty notes, notes stuck in trash, sync conflicts, orphaned tags, untagged notes, and oversized notes. Use this to identify cleanup opportunities or diagnose sync issues. |
bear_list_notes | read | List Bear notes with optional tag filtering. Returns an array of notes with IDs, titles, tags, pin status, and modification dates. Each note includes two tag fields: |
bear_list_todos | read | List Bear notes that have incomplete TODO items (markdown checkboxes like |
bear_note_stats | read | Get statistics about the Bear notes library: total notes, words, tags, pinned, archived, trashed, notes with TODOs, oldest/newest dates, and top 10 tags by note count. |
bear_remove_tag | destructive | Remove a tag from a specific Bear note. Works on any tag visible in |
bear_rename_tag | write | Rename a tag across all Bear notes. Every note containing the old tag will be updated. |
bear_sync | write | Trigger a sync of Bear notes from iCloud. Normally an incremental sync fetching only changes. Use |
bear_toggle_todo | read | Toggle a specific TODO item in a Bear note between complete and incomplete. The item_index is 1-based — use bear_get_todos first to see the list with index numbers. |
bear_trash_note | destructive | Move a Bear note to the trash. This is a soft delete — the note can be recovered from Bear |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
bear_archive_note, bear_context_remove, bear_context_remove_external, bear_delete_tag, bear_remove_tag, bear_trash_note
.mcpbignore
BCLI="${BCLI:-../../.build/debug/bcli}"@modelcontextprotocol/sdk, @types/node, typescript
5. All subsequent bcli operations read from Keychain.
curl -sL https://raw.githubusercontent.com/KuvopLLC/better-bear/main/install.sh | bash
<button class="copy-btn" onclick="navigator.clipboard.writeText('curl -sL https://raw.githubusercontent.com/KuvopLLC/better-bear/main/install.sh | bash');this.textContent='Copied!'">Copy</button><code>curl -sL https://raw.githubusercontent.com/KuvopLLC/better-bear/main/install.sh | bash
curl -sL https://raw.githubusercontent.com/KuvopLLC/better-bear/main/install.sh | bash
<p>When used as an MCP server, Better Bear communicates with the MCP client (Claude Desktop or Claude Code) over local stdio pipes. Note content is passed between the MCP server process and the client
Better Bear does not collect, transmit, or store any personal data on external servers. Authentication tokens and note caches are stored locally on your machine. Network requests go only to Apple Clou
Gates applied: no_behavioural_pass.
d94c2ad024f3full audit observations/trust-audit/mcp-server/kuvopllc__better-bear-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | d94c2ad024f3 | SAFE | B | 89 | first audit |
Questions
What is the Better Bear MCP server?
MCP server for Bear notes — read, search, create, edit, tag, and manage notes via CloudKit
What tools does Better Bear expose?
32 in total: 17 read-only, 9 that write, and 6 that can delete or overwrite (bear_archive_note, bear_context_remove, bear_context_remove_external, bear_delete_tag, bear_remove_tag). Every one is listed on this page with its risk.
Is Better Bear safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Better Bear need?
No credential environment variables were found in its source, so it appears to need none.
How does Better Bear run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as better-bear at 0.4.1.
How current is this page?
The grade is for one exact copy of the source (d94c2ad024f3), read on 2026-10-07. The repository is watched and re-audited when it changes.