MoltBrainBLOCK
Long-term memory layer for OpenClaw & MoltBook agents that learns and recalls your project context automatically.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Long-term memory layer for OpenClaw, MoltBook & Claude Code that learns and recalls your project context automatically.
Install • Features • How It Works • Storage • Virtuals • OpenClaw • Config • API
⚡ Quick Install
╔══════════════════════════════════════════════════════════════════════╗ ║ ║ ║ Step 1 /plugin marketplace add nhevers/moltbrain ║ ║ Step 2 /plugin install moltbrain ║ ║ ║ ╚══════════════════════════════════════════════════════════════════════╝
That's it. MoltBrain starts working automatically.
🧠 What It Does
╭──────────────────────────────────────────────────────────────────────────────╮ │ │ │ ┌─────────────────┐ ┌─────────────────┐ │ │ │ SESSION #1 │ │ SESSION #47 │ │ │ │─────────────────│ │─────────────────│ │ │ │ │ │ │ │ │ │ "Set up auth │ │ "Add password │ │ │ │ with OAuth" │ │ reset flow" │
232041f988d0OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add claude-recall-plugin --env GEMINI_API_KEY=${GEMINI_API_KEY} --env MOLTBRAIN_MOLTBOOK_API_KEY=${MOLTBRAIN_MOLTBOOK_API_KEY} --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"claude-recall-plugin": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"GEMINI_API_KEY": "${GEMINI_API_KEY}",
"MOLTBRAIN_MOLTBOOK_API_KEY": "${MOLTBRAIN_MOLTBOOK_API_KEY}",
"OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}"
}
}
}
}Exposed tools (7)
6 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
__IMPORTANT | read | 3-LAYER WORKFLOW (ALWAYS FOLLOW): 1. search(query) → Get index with IDs (~50-100 tokens/result) 2. timeline(anchor=ID) → Get context around interesting results 3. get_observations([IDs]) → Fetch full details ONLY for filtered IDs NEVER fetch full details without filtering first. 10x token savings. |
get_observations | read | Step 3: Fetch full details for filtered IDs. Params: ids (array of observation IDs, required), orderBy, limit, project |
recall_context | read | Retrieve relevant memories based on current context |
save_memory | write | Manually save an important piece of information |
search | read | Step 1: Search memory. Returns index with IDs. Params: query, limit, project, type, obs_type, dateStart, dateEnd, offset, orderBy |
search_memories | read | Search through stored memories |
timeline | read | Step 2: Get context around results. Params: anchor (observation ID) OR query (finds anchor automatically), depth_before, depth_after, project |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (10 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (6 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (23)
const body = exec(`gh release view ${release.tagName} --json body --jq '.body'`).trim();.build-info
.translation-cache.json
console.log(` Token reduction: ${codeTokens.ratio.toFixed(2)}x`);console.log(` Token reduction: ${narrativeTokens.ratio.toFixed(2)}x`);import { logger } from '../../utils/logger.js';import { logger } from '../../utils/logger.js';import { SettingsDefaultsManager } from '../../common/SettingsDefaultsManager.js';import { logger } from '../../utils/logger.js';import { getProjectName } from '../../utils/project-name.js';2. Call: `GET http://127.0.0.1:37777/api/context/inject?project={project}`POST http://127.0.0.1:37777/sessions/{sessionDbId}/initPOST http://127.0.0.1:37777/api/sessions/observations
POST http://127.0.0.1:37777/api/sessions/summarize
POST http://127.0.0.1:37777/api/processing
typescript, @sinclair/typebox
@modelcontextprotocol/sdk, typescript, @types/node
typescript, @sinclair/typebox
@anthropic-ai/claude-agent-sdk, @modelcontextprotocol/sdk, ansi-to-html, express, glob, handlebars, react, react-dom
- **macOS/Linux**: `curl -fsSL https://bun.sh/install | bash`
docs/public/cm-preview.gif
extension/runtime/engine-runtime.cjs
plugin/scripts/worker-service.cjs
Gates applied: no_behavioural_pass.
232041f988d0full audit observations/trust-audit/mcp-server/nhevers__moltbrain.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 232041f988d0 | BLOCK | D | 69 | first audit |
Questions
What is the MoltBrain MCP server?
Long-term memory layer for OpenClaw & MoltBook agents that learns and recalls your project context automatically.
What tools does MoltBrain expose?
7 in total: 6 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is MoltBrain safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does MoltBrain need?
It reads GEMINI_API_KEY, MOLTBRAIN_MOLTBOOK_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does MoltBrain run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as claude-recall-plugin at 9.0.9.
How current is this page?
The grade is for one exact copy of the source (232041f988d0), read on 2026-10-06. The repository is watched and re-audited when it changes.