tinybrain
LLM local persistent storage for security nerds
Install / Use
claude mcp add rainmana -- npx -y github:rainmana/tinybrainIf the server publishes to npm under a different name, use that package instead — check the repo README.
MCP Server
Model Context Protocol server
Quality Score
Category
SecuritySupported Platforms
Our assessment of tinybrain
tinybrain scores 71/100 on our quality scale, 1056th of 1,121 Security skills we index.
Its MCP Server is 27 KB long, well organised into 102 sections with 21 code examples: a thorough specification that gives an agent plenty to work with.
It has 3 GitHub stars, so there is little community track record yet; judge it on its content.
Maintenance, license and trust
- The repository was last updated about 4 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
- Our last check on 2026-09-06 found the source still online.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 85/100, with 2 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
tinybrain compared with similar skills
All 4 of these similar skills score higher than tinybrain; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| tinybrain (this skill)by rainmana | 71 | 3 | 4mo ago | MCP Server |
| Agent-Reachby Panniantong | 100 | 91.6k | 20d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.4k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.8k | today | MCP Server |
Frequently asked questions
- How do I install tinybrain?
- Run
claude mcp add rainmana -- npx -y github:rainmana/tinybrain. The install tabs above show the steps for each supported agent. - Which AI agents does tinybrain work with?
- It is written for Claude Code and Claude Desktop, as a MCP Server file. Other agents that read the same format can often use it too.
- Is tinybrain safe to use?
- It is MIT-licensed and scores 85/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is tinybrain still maintained?
- The repository was last updated about 4 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
Skill content
View source on GitHubTinyBrain 🧠
Security-Focused LLM Memory Storage with Intelligence Gathering, Reverse Engineering, and MITRE ATT&CK Integration
TinyBrain is a comprehensive memory storage system designed specifically for security professionals, penetration testers, and AI assistants working on offensive security tasks. It provides intelligent memory management, pattern recognition, and comprehensive intelligence gathering capabilities through the Model Context Protocol (MCP).
📖 View Complete Documentation | 🐛 Report Issues | 💬 Discussions
✨ Key Features
🧠 Intelligence Gathering
- OSINT: Open Source Intelligence collection and analysis
- HUMINT: Human Intelligence gathering and social engineering assessment
- SIGINT: Signals Intelligence and communications analysis
- GEOINT: Geospatial Intelligence and location-based analysis
- MASINT: Measurement and Signature Intelligence
- TECHINT: Technical Intelligence and technology assessment
- FININT: Financial Intelligence and cryptocurrency tracking
- CYBINT: Cyber Intelligence and threat analysis
🔍 Reverse Engineering
- Malware Analysis: Static and dynamic malware analysis capabilities
- Binary Analysis: PE, ELF, Mach-O file format analysis
- Vulnerability Research: Fuzzing, exploit development, and vulnerability analysis
- Protocol Analysis: Network and application protocol reverse engineering
- Code Analysis: Source code and assembly analysis tools
🎯 MITRE ATT&CK Integration
- Complete Framework: All 14 Enterprise tactics and 200+ techniques
- TTP Mapping: Map findings to specific tactics, techniques, and procedures
- Attack Chain Analysis: Complete attack chain mapping and analysis
- Threat Hunting: Hunt for specific TTPs and attack patterns
- Campaign Tracking: Track attack campaigns and threat actor activities
- Real-Time Data: Live MITRE ATT&CK dataset with 823+ techniques and 14 tactics
- Intelligent Querying: Semantic search across attack techniques and procedures
🛡️ Security Patterns & Standards
- CWE Integration: Common Weakness Enumeration patterns and classifications
- OWASP Compliance: OWASP Top 10 2021 and testing guide integration
- Multi-Language Support: Security patterns for 10+ programming languages
- Authorization Templates: RBAC, ABAC, and DAC access control patterns
- Standards Compliance: NIST, ISO 27001, PTES, and industry standards
- NVD Integration: National Vulnerability Database with 314,835+ CVEs
- OWASP Testing Guide: Complete web application security testing procedures
🔬 Security Knowledge Hub
- NVD Integration: National Vulnerability Database with 314,835+ CVEs
- MITRE ATT&CK: Complete framework with 823+ techniques and 14 tactics
- OWASP Testing Guide: Comprehensive web application security testing procedures
- Intelligent Retrieval: Context-aware querying with summarization
- Real-Time Updates: Incremental data updates from official sources
- Rate Limiting: Respectful API usage with proper rate limiting
📊 Memory Management
- 30+ Memory Categories: Comprehensive categorization for intelligence, reconnaissance, and analysis data
- Intelligence Objects: Threat actors, attack campaigns, IOCs, TTPs, patterns, and correlations
- Context-Aware Storage: Automatically categorizes and prioritizes information
- Advanced Search: Semantic, exact, fuzzy, tag-based, and relationship-based search
- Access Tracking: Monitors which memories are most relevant and frequently accessed
- Context Summaries: Provides relevant memory summaries for current tasks
High Performance & Reliability
- Embedded SQLite Backend: Single binary with a pure-Go SQLite engine (no cgo) and FTS5 full-text search
- Dashboard: Web-based status dashboard at http://127.0.0.1:8090/_/ (in
servemode) - REST API: Full REST API at http://127.0.0.1:8090/api/ for external integrations
- MCP Protocol: JSON-RPC 2.0 over stdio for AI assistant integration
- Optimized Queries: Indexed searches and efficient relationship traversal
- Transaction Safety: ACID compliance for data integrity
- Concurrent Access: Thread-safe operations for multiple LLM interactions
- Zero Configuration: Works out of the box with minimal setup
AI-Enhanced Search & Intelligence
- Semantic Search: AI-powered memory search using embeddings for conceptual similarity
- Embedding Generation: Generate embeddings for text (placeholder for AI integration)
- Similarity Calculation: Calculate semantic similarity between embeddings
- Future-Ready: Complete foundation for OpenAI, Cohere, or local model integration
Real-Time Notifications & Alerts
- Memory Notifications: Real-time alerts for memory events and system activities
- High Priority Alerts: Notifications for high-priority memories (priority ≥8, confidence ≥0.8)
- Duplicate Detection: Alerts for potential duplicate memories with similarity scores
- Cleanup Notifications: Notifications for automated cleanup operations
- Notification Management: Mark notifications as read, filter by session, priority-based sorting
Developer Experience
- Simple Installation:
go install github.com/rainmana/tinybrain/v3/cmd/tinybrain@latest - Comprehensive Logging: Detailed logging with structured output
- Extensive Testing: Full test coverage for all MCP tool handlers
- Docker Support: Containerized deployment ready
- 50+ MCP Tools: Complete API for all memory management operations
- Single Binary: MCP server, REST API, and dashboard in one executable
🛠️ Complete MCP Tool Set (50+ Tools)
TinyBrain provides a comprehensive set of more than 50 MCP tools for complete LLM memory management:
Core Memory Operations (8 tools)
store_memory- Store new memory entriesget_memory- Retrieve memory by IDsearch_memories- Advanced search with multiple strategiesupdate_memory- Update existing memory entriesdelete_memory- Delete memory entriesfind_similar_memories- Find similar memories by contentcheck_duplicates- Check for duplicate memoriesget_memory_stats- Get comprehensive memory statistics
Session & Task Management (6 tools)
create_session- Create new security assessment sessionsget_session- Retrieve session informationlist_sessions- List all sessions with filteringcreate_task_progress- Create task progress entriesupdate_task_progress- Update task progresslist_task_progress- List task progress entries
Advanced Memory Features (8 tools)
create_relationship- Create memory relationshipsget_related_memories- Get related memoriescreate_context_snapshot- Create context snapshotsget_context_snapshot- Retrieve context snapshotslist_context_snapshots- List context snapshotsget_context_summary- Get memory summaries for contextexport_session_data- Export session dataimport_session_data- Import session data
Security Templates & Batch Operations (6 tools)
get_security_templates- Get predefined security templatescreate_memory_from_template- Create memories from templatesbatch_create_memories- Bulk create memory entriesbatch_update_memories- Bulk update memory entriesbatch_delete_memories- Bulk delete memory entriesget_detailed_memory_info- Get detailed memory debugging info
Memory Lifecycle & Cleanup (4 tools)
cleanup_old_memories- Age-based memory cleanupcleanup_low_priority_memories- Priority-based cleanupcleanup_unused_memories- Access-based cleanupget_system_diagnostics- Comprehensive system diagnostics
AI-Enhanced Search (3 tools)
semantic_search- AI-powered semantic searchgenerate_embedding- Generate embeddings for textcalculate_similarity- Calculate embedding similarity
Real-Time Notifications (4 tools)
get_notifications- Get notifications and alertsmark_notification_read- Mark notifications as readcheck_high_priority_memories- Check for high-priority alertscheck_duplicate_memories- Check for duplicate alerts
System Monitoring (1 tool)
health_check- Perform system health checks
🛡️ Security Standards & Source Attribution
Standards Compliance
TinyBrain's security patterns and vulnerability datasets are aligned with industry-standard security frameworks:
- OWASP Top 10 2021 - Web Application Security Risks
- CWE (Common Weakness Enumeration) - Software Weakness Classification
- NIST SP 800-115 - Technical Guide to Information Security Testing
- ISO 27001 - Information Security Management Systems
- PTES (Penetration Testing Execution Standard) - Penetration Testing Methodology
Source Attribution
Our security patterns and vulnerability datasets are based on authoritative sources:
- OWASP Code Review Guide - Comprehensive secure code review methodology
- OWASP Secure Coding Dojo - Interactive security code review training
- OWASP Testing Guide - Web application security testing methodology
- SANS Top 25 CWE - Most dangerous software errors
- NIST Cybersecurity Framework - Cybersecurity risk management
Multi-Language Coverage
Our security patterns cover 10 major programming languages with language-specific vulnerability patterns:
- JavaScript/Node.js - Web application security patterns
- Python - Backend and automation security patterns
- Java - Enterprise application security patterns
- C#/.NET - Microsoft ecosystem security patterns
- PHP - Web application security patterns
- Ruby - Web framework security patterns
- Go - System and API security patterns
- C/C++ - System-level security patterns
- TypeScript - Type-safe web application patterns
- Rust - Memory-safe system programming patterns
🚀 Quick Start
Installation
Option 1: Pre-built Binaries (Recommended)
Download the latest release for your platform from Releases:
- macOS (Apple Silicon):
tinybrain_*_Darwin_arm64.tar.gz - macOS (Intel):
tinybrain_*_Darwin_x86_64.tar.gz - Linux (x86_64):
tinybrain_*_Linux_x86_64.tar.gz - Linux (ARM64):
tinybrain_*_Linux_arm64.tar.gz - Windows:
tinybrain_*_Windows_x86_64.zip
Extract and run:
# Extract (Linux/macOS)
tar -xzf tinybrain_*_*.tar.gz
cd tinybrain_*
# Make executable
chmod +x tinybrain
# Run
./tinybrain serve
Option 2: Install from Source with go install
# Install latest version
go install github.com/rainmana/tinybrain/v3/cmd/tinybrain@latest
# Install specific version
go install github.com/rainmana/tinybrain/v3/cmd/tinybrain@latest
# The binary will
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
91.6kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.4kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Scrapling
85.8k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
