Atlas / MCP servers / nhevers / MoltBrain

MoltBrainBLOCK

mcp/nhevers/moltbrain

Long-term memory layer for OpenClaw & MoltBook agents that learns and recalls your project context automatically.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
7 6r · 1w · 0d
Transport
stdio
License
NOASSERTION
Stars
252
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Long-term memory layer for OpenClaw, MoltBook & Claude Code that learns and recalls your project context automatically.

Install • Features • How It Works • Storage • Virtuals • OpenClaw • Config • API

⚡ Quick Install

╔══════════════════════════════════════════════════════════════════════╗
║                                                                      ║
║   Step 1    /plugin marketplace add nhevers/moltbrain                ║
║   Step 2    /plugin install moltbrain                                ║
║                                                                      ║
╚══════════════════════════════════════════════════════════════════════╝

That's it. MoltBrain starts working automatically.

🧠 What It Does

╭──────────────────────────────────────────────────────────────────────────────╮
│                                                                              │
│     ┌─────────────────┐                      ┌─────────────────┐             │
│     │   SESSION #1    │                      │   SESSION #47   │             │
│     │─────────────────│                      │─────────────────│             │
│     │                 │                      │                 │             │
│     │  "Set up auth   │                      │  "Add password  │             │
│     │   with OAuth"   │                      │   reset flow"   │   
Read from source at commit 232041f988d0OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add claude-recall-plugin --env GEMINI_API_KEY=${GEMINI_API_KEY} --env MOLTBRAIN_MOLTBOOK_API_KEY=${MOLTBRAIN_MOLTBOOK_API_KEY} --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "claude-recall-plugin": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "GEMINI_API_KEY": "${GEMINI_API_KEY}",
        "MOLTBRAIN_MOLTBOOK_API_KEY": "${MOLTBRAIN_MOLTBOOK_API_KEY}",
        "OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}"
      }
    }
  }
}
03

Exposed tools (7)

6 read · 1 write · 0 destructive.

ToolRiskDescription
__IMPORTANTread3-LAYER WORKFLOW (ALWAYS FOLLOW): 1. search(query) → Get index with IDs (~50-100 tokens/result) 2. timeline(anchor=ID) → Get context around interesting results 3. get_observations([IDs]) → Fetch full details ONLY for filtered IDs NEVER fetch full details without filtering first. 10x token savings.
get_observationsreadStep 3: Fetch full details for filtered IDs. Params: ids (array of observation IDs, required), orderBy, limit, project
recall_contextreadRetrieve relevant memories based on current context
save_memorywriteManually save an important piece of information
searchreadStep 1: Search memory. Returns index with IDs. Params: query, limit, project, type, obs_type, dateStart, dateEnd, offset, orderBy
search_memoriesreadSearch through stored memories
timelinereadStep 2: Get context around results. Params: anchor (observation ID) OR query (finds anchor automatically), depth_before, depth_after, project
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (10 observation(s))
Network
declared (10 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (23)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/generate-changelog.js:30
const body = exec(`gh release view ${release.tagName} --json body --jq '.body'`).trim();
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInventory / provenance · inv.hidden_file · CWE-1104
.build-info
.build-info
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.translation-cache.json
.translation-cache.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
benchmarks/compression.bench.ts:285
console.log(`    Token reduction: ${codeTokens.ratio.toFixed(2)}x`);
LOWInformation disclosure · disclose.log_secret · CWE-209, CWE-532
benchmarks/compression.bench.ts:290
console.log(`    Token reduction: ${narrativeTokens.ratio.toFixed(2)}x`);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/api/ErrorHandler.ts:8
import { logger } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/api/Server.ts:16
import { logger } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/builder/ContextConfigLoader.ts:9
import { SettingsDefaultsManager } from '../../common/SettingsDefaultsManager.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/builder/HistoryBuilder.ts:12
import { logger } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/builder/HistoryBuilder.ts:13
import { getProjectName } from '../../utils/project-name.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/public/architecture/hooks.mdx:303
2. Call: `GET http://127.0.0.1:37777/api/context/inject?project={project}`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/public/architecture/hooks.mdx:401
POST http://127.0.0.1:37777/sessions/{sessionDbId}/init
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/public/architecture/hooks.mdx:496
POST http://127.0.0.1:37777/api/sessions/observations
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/public/architecture/hooks.mdx:591
POST http://127.0.0.1:37777/api/sessions/summarize
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/public/architecture/hooks.mdx:600
POST http://127.0.0.1:37777/api/processing
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
integrations/clawd/package.json
typescript, @sinclair/typebox
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
integrations/moltbook/package.json
@modelcontextprotocol/sdk, typescript, @types/node
Why it matters. 3 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
integrations/openclaw/package.json
typescript, @sinclair/typebox
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/claude-agent-sdk, @modelcontextprotocol/sdk, ansi-to-html, express, glob, handlebars, react, react-dom
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/public/architecture/worker-service.mdx:618
- **macOS/Linux**: `curl -fsSL https://bun.sh/install | bash`
INFOInventory / provenance · inv.oversize · CWE-1104
docs/public/cm-preview.gif
docs/public/cm-preview.gif
Why it matters. 2156660 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
extension/runtime/engine-runtime.cjs
extension/runtime/engine-runtime.cjs
Why it matters. 1851465 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
plugin/scripts/worker-service.cjs
plugin/scripts/worker-service.cjs
Why it matters. 1856295 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 232041f988d0full audit observations/trust-audit/mcp-server/nhevers__moltbrain.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06232041f988d0BLOCKD69first audit
06

Questions

What is the MoltBrain MCP server?

Long-term memory layer for OpenClaw & MoltBook agents that learns and recalls your project context automatically.

What tools does MoltBrain expose?

7 in total: 6 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is MoltBrain safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does MoltBrain need?

It reads GEMINI_API_KEY, MOLTBRAIN_MOLTBOOK_API_KEY and OPENROUTER_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does MoltBrain run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as claude-recall-plugin at 9.0.9.

How current is this page?

The grade is for one exact copy of the source (232041f988d0), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement