BrainBLOCK
The recorder for your AI conversations — local-first MCP memory that keeps byte-exact copies of your Claude Code, Codex and Pi sessions (Claude Code deletes its own after 30 days) and answers with a citation or abstains. DuckDB.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Your AI history is being deleted right now. Claude Code deletes session files older than cleanupPeriodDays (default 30) at startup. Run this and see your own cliff edge:
# macOS
find ~/.claude/projects -name '*.jsonl' -exec stat -f '%Sm %N' -t '%Y-%m-%d' {} + | sort | head -3
# Linux
find ~/.claude/projects -name '*.jsonl' -printf '%TY-%Tm-%Td %p\n' | sort | head -3The oldest date you see is where your history ends. brain-mcp records it before it goes — the whole session, subagent transcripts and saved tool output included, byte-exact, content-hashed, locally — makes it queryable with citations you can verify with sed and shasum, tells you what was deleted, and puts it back.
If Claude Code deleted it
brain-mcp health # the receipt: "3 session(s) and 41 file(s) are gone from where the # agent kept them; the floor holds every one" — each re-hashed # against the manifest when the recorder first noticed it brain-mcp restore --list # what can be put back brain-mcp restore # writes the session (and its folder) back, byte-exact, then: # cd && claude --resume
restore never overwrites different bytes (identical bytes are a no-op), is all-or-nothing, and takes --dry-run and --to . It is a CLI verb only — no MCP tool writes outside the floor.
Install
pipx install brain-mcp # or: uvx brain-mcp brain-mcp install cc # CC hooks + 60-second scheduler brain-mcp serve # the MCP server (stdio) — add to your client config
Or as a Claude Code plugin (hooks + server in one step):
/plugin marketplace add mordechaipotash/brain-marketplace /plugin install brain
What it does
- Captures at source. Claude Code via Stop/Sessio
b3418f0f3ebcOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add brain-mcp -- None brain-mcp==2.1.1
Exposed tools (5)
5 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
brain_capture_status | read | Spool depth, heartbeat file ages (side-effect mtimes, never self-report), |
brain_get | read | Raw floor bytes for a cited span. Pass the citation |
brain_health | read | Origin-vs-floor staleness per lane. fresh = floor holds everything the |
brain_recent | read | Time-ordered recent messages, every row cited. An empty result states its |
brain_sessions | read | Session cards (agent, span, message counts, floor file) for a date or |
Trust audit
BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | WARN |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (9)
"AKIAAAAAAAAAAAAAAAAA",
subprocess.run(["launchctl", "unload", str(plist)], capture_output=True)
r = subprocess.run(["launchctl", "load", str(plist)], capture_output=True, text=True)
else f"scheduler: wrote {plist}; launchctl load failed: {r.stderr.strip()}")subprocess.run(["launchctl", "unload", str(plist)], capture_output=True)
system use found in code, not declared in the description
return hashlib.md5(key.encode()).hexdigest()[:16]
3. **Layer-bounded permissions.** Every tool has full access to every data store. There is no structural barrier preventing an L3 synthesis tool from accidentally writing to L0 raw storage.
assets/demo.mp4
Gates applied: critical_finding, no_behavioural_pass.
b3418f0f3ebcfull audit observations/trust-audit/mcp-server/mordechaipotash__brain-3.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b3418f0f3ebc | BLOCK | D | 66 | first audit |
Questions
What is the Brain MCP server?
The recorder for your AI conversations — local-first MCP memory that keeps byte-exact copies of your Claude Code, Codex and Pi sessions (Claude Code deletes its own after 30 days) and answers with a citation or abstains. DuckDB.
What tools does Brain expose?
5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Brain safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (66/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Brain need?
No credential environment variables were found in its source, so it appears to need none.
How does Brain run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as brain-mcp.
How current is this page?
The grade is for one exact copy of the source (b3418f0f3ebc), read on 2026-10-07. The repository is watched and re-audited when it changes.