Atlas / MCP servers / mordechaipotash / Brain

BrainBLOCK

mcp/mordechaipotash/brain-3

The recorder for your AI conversations — local-first MCP memory that keeps byte-exact copies of your Claude Code, Codex and Pi sessions (Claude Code deletes its own after 30 days) and answers with a citation or abstains. DuckDB.

Verdict
BLOCK
Grade
D
Trust score
66 /100
Exposed tools
5 5r · 0w · 0d
Transport
stdio
License
MIT
Stars
78
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Your AI history is being deleted right now. Claude Code deletes session files older than cleanupPeriodDays (default 30) at startup. Run this and see your own cliff edge:

# macOS
find ~/.claude/projects -name '*.jsonl' -exec stat -f '%Sm  %N' -t '%Y-%m-%d' {} + | sort | head -3
# Linux
find ~/.claude/projects -name '*.jsonl' -printf '%TY-%Tm-%Td %p\n' | sort | head -3

The oldest date you see is where your history ends. brain-mcp records it before it goes — the whole session, subagent transcripts and saved tool output included, byte-exact, content-hashed, locally — makes it queryable with citations you can verify with sed and shasum, tells you what was deleted, and puts it back.

If Claude Code deleted it

brain-mcp health          # the receipt: "3 session(s) and 41 file(s) are gone from where the
#   agent kept them; the floor holds every one" — each re-hashed
#   against the manifest when the recorder first noticed it
brain-mcp restore --list  # what can be put back
brain-mcp restore     # writes the session (and its folder) back, byte-exact, then:
#   cd  && claude --resume 

restore never overwrites different bytes (identical bytes are a no-op), is all-or-nothing, and takes --dry-run and --to . It is a CLI verb only — no MCP tool writes outside the floor.

Install

pipx install brain-mcp           # or: uvx brain-mcp
brain-mcp install cc             # CC hooks + 60-second scheduler
brain-mcp serve                  # the MCP server (stdio) — add to your client config

Or as a Claude Code plugin (hooks + server in one step):

/plugin marketplace add mordechaipotash/brain-marketplace
/plugin install brain

What it does

  • Captures at source. Claude Code via Stop/Sessio
Read from source at commit b3418f0f3ebcOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (pypi)
claude mcp add brain-mcp -- None brain-mcp==2.1.1
03

Exposed tools (5)

5 read · 0 write · 0 destructive.

ToolRiskDescription
brain_capture_statusreadSpool depth, heartbeat file ages (side-effect mtimes, never self-report),
brain_getreadRaw floor bytes for a cited span. Pass the citation
brain_healthreadOrigin-vs-floor staleness per lane. fresh = floor holds everything the
brain_recentreadTime-ordered recent messages, every row cited. An empty result states its
brain_sessionsreadSession cards (agent, span, message counts, floor file) for a date or
04

Trust audit

BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)WARN
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (9)

CRITICALHard-coded secrets · secret.aws · CWE-798, CWE-321
brain_mcp/recorder/secrets.py:41
"AKIAAAAAAAAAAAAAAAAA",
MEDIUMPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
brain_mcp/recorder/cli.py:155
subprocess.run(["launchctl", "unload", str(plist)], capture_output=True)
MEDIUMPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
brain_mcp/recorder/cli.py:156
r = subprocess.run(["launchctl", "load", str(plist)], capture_output=True, text=True)
MEDIUMPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
brain_mcp/recorder/cli.py:158
else f"scheduler: wrote {plist}; launchctl load failed: {r.stderr.strip()}")
MEDIUMPrivilege escalation / persistence · fs.persistence · CWE-269, CWE-250
brain_mcp/recorder/cli.py:196
subprocess.run(["launchctl", "unload", str(plist)], capture_output=True)
MEDIUMPrompt injection · scope.undeclared_system · CWE-94, CWE-1427
<declared scope>
system use found in code, not declared in the description
Why it matters. the description does not admit a capability the code has
Fix. declare system use in the description, or remove it
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
brain_mcp/ingest/generic.py:134
return hashlib.md5(key.encode()).hexdigest()[:16]
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/adr/001-shelet-reference-implementation.md:16
3. **Layer-bounded permissions.** Every tool has full access to every data store. There is no structural barrier preventing an L3 synthesis tool from accidentally writing to L0 raw storage.
INFOInventory / provenance · inv.oversize · CWE-1104
assets/demo.mp4
assets/demo.mp4
Why it matters. 4062929 bytes not read

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha b3418f0f3ebcfull audit observations/trust-audit/mcp-server/mordechaipotash__brain-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07b3418f0f3ebcBLOCKD66first audit
06

Questions

What is the Brain MCP server?

The recorder for your AI conversations — local-first MCP memory that keeps byte-exact copies of your Claude Code, Codex and Pi sessions (Claude Code deletes its own after 30 days) and answers with a citation or abstains. DuckDB.

What tools does Brain expose?

5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Brain safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (66/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Brain need?

No credential environment variables were found in its source, so it appears to need none.

How does Brain run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as brain-mcp.

How current is this page?

The grade is for one exact copy of the source (b3418f0f3ebc), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement