Atlas / MCP servers / mi4uu / Brain.md

Brain.mdSAFE

mcp/mi4uu/brain-md

Local-first markdown notes with a first-class MCP server. 16 tools + 2 resources for Claude Code, Claude Desktop, Cursor and any MCP agent. Per-folder permissions, semantic RAG via LanceDB, single Bun binary. AGPL.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
17 16r · 1w · 0d
Transport
streamable-http
License
AGPL-3.0
Stars
33
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A local-first second brain for you — and for your AI agents.

[](LICENSE) [](https://bun.com) [](docs/mcp.md) [](#-semantic-search-rag) [](https://glama.ai/mcp/servers/mi4uu/brain.md) [](https://smithery.ai/server/mi4uu/brain-md)

What you get

Read from source at commit db3b8ed9ff75OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add web --env BRAINMD_LOG_OAUTH=${BRAINMD_LOG_OAUTH} -- npx -y @brain/[email protected]
claude-desktop
{
  "mcpServers": {
    "web": {
      "command": "npx",
      "args": [
        "-y",
        "@brain/[email protected]"
      ],
      "env": {
        "BRAINMD_LOG_OAUTH": "${BRAINMD_LOG_OAUTH}"
      }
    }
  }
}
03

Exposed tools (17)

16 read · 1 write · 0 destructive.

ToolRiskDescription
append_noteread
compare_notesread
context_for_queryread
current_datetimeread
find_orphansread
find_relatedread
find_similar_tasksread
get_backlinksread
get_tasksread
list_notesread
list_tagsread
read_noteread
search_notesread
semantic_outlineread
similar_notesread
weekly_digestread
write_notewrite
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (8 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/gen-web-assets.ts:54
const importPath = "../../../web/dist/" + rel;
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/src/web/assets.ts:11
import f0 from "../../../web/dist/.DS_Store" with { type: "file" };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/src/web/assets.ts:12
import f1 from "../../../web/dist/assets/KaTeX_AMS-Regular-BQhdFMY1.woff2" with { type: "file" };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/src/web/assets.ts:13
import f2 from "../../../web/dist/assets/KaTeX_AMS-Regular-DMm9YOAa.woff" with { type: "file" };
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
server/src/web/assets.ts:14
import f3 from "../../../web/dist/assets/KaTeX_AMS-Regular-DRggAlZN.ttf" with { type: "file" };
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
server/test/api.rag.test.ts:68
baseURL: "http://127.0.0.1:1",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
typescript
Why it matters. 1 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
server/package.json
@elysiajs/cors, @lancedb/lancedb, @modelcontextprotocol/sdk, apache-arrow, elysia, gpt-tokenizer, onnxruntime-web, yaml
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
web/package.json
@codemirror/autocomplete, @codemirror/commands, @codemirror/lang-markdown, @codemirror/language, @codemirror/search, @codemirror/state, @codemirror/view, @lezer/highlight
Why it matters. 57 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
server/src/rag/assets/ort-wasm-simd-threaded.wasm
server/src/rag/assets/ort-wasm-simd-threaded.wasm
Why it matters. 13022405 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
web/public/icon_.svg
web/public/icon_.svg
Why it matters. 1027734 bytes not read
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:121
curl -fsSL https://raw.githubusercontent.com/mi4uu/brain.md/main/install.sh | bash
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:162
curl -fsSL https://raw.githubusercontent.com/mi4uu/brain.md/main/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha db3b8ed9ff75full audit observations/trust-audit/mcp-server/mi4uu__brain-md.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09db3b8ed9ff75SAFEB89first audit
06

Questions

What is the Brain.md MCP server?

Local-first markdown notes with a first-class MCP server. 16 tools + 2 resources for Claude Code, Claude Desktop, Cursor and any MCP agent. Per-folder permissions, semantic RAG via LanceDB, single Bun binary. AGPL.

What tools does Brain.md expose?

17 in total: 16 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Brain.md safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Brain.md need?

It reads BRAINMD_LOG_OAUTH from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Brain.md run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @brain/web at 0.4.10.

How current is this page?

The grade is for one exact copy of the source (db3b8ed9ff75), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement