Tools, approvals and safety
Bots act through tools. Every tool call is checked against your rules before it runs, and recorded.
Built-in tools #
| Tool | What it does | Default |
|---|---|---|
memory_store, memory_search |
Save and look up memories (Memory) | allow |
chat_search |
Search earlier conversations with you (any of your bots) for what was said but not saved | allow |
memory_forget |
Forget a memory | ask |
routine_create, routine_list |
Schedule and list routines, recurring or once (a reminder) (Routines) | allow |
routine_delete |
Delete a routine | ask |
web_fetch |
Read a web page (outside content; never this computer or your local network: addresses, names that resolve there, and redirects are all checked) | allow |
calendar_add |
Make one-click "add to calendar" links (Google Calendar, Outlook) for an event; you open one and save it, nothing is added for you | allow |
email_search, email_read |
Search and read your email, read-only (Settings → Email: IMAP with an app password); offered once set up, in a chat with you only. Nothing is marked read, moved or deleted (the mailbox is only examined); emails are outside content | allow |
email_draft |
Write an email (or a reply in its thread) into your Drafts folder; nothing is sent, you send it from your mail app. After reading outside content (an email included) it asks, with the recipient first on the card | allow |
file_list, file_read, file_write |
A text-file workspace per chat (notes, lists, drafts, research), shown under Memory → Files. Paths stay inside it (no .., no links); rewriting keeps the previous version; a file written after outside content (or dropped in by hand) counts as outside content when read. Not in incognito |
allow |
file_delete |
Delete a workspace file | ask |
email_send |
Send an email as you, after you approve it: every email asks (never "Always"), with who it's to first and the whole text on the card; one too long for the card has to be a draft instead; at most 20 a day from a chat. Sent through your outgoing server (worked out from the incoming one, or set in Settings → Email), with a copy in your Sent folder | asks, every time |
web_search |
Search the web through Settings → Web search (Brave Search with a free key, or your own SearXNG), for every AI account; offered once one is set up. Results are outside content; after outside content, a search that would carry one of your memories (or over 200 characters) asks | allow |
meeting_search, meeting_read |
Look through your transcribed meetings (Meetings); offered once you have one | allow |
calendar_create |
Add an event straight to your calendar (Settings → Calendar: iCloud, Fastmail, Nextcloud or any CalDAV, with an app password); offered once one is connected, in a chat with you only. The card shows when, what and where; "Always" works for it | ask |
calendar_list |
Read your calendar between two dates (from the calendar link in Settings); offered once one is linked, in a chat with you only. Event titles are outside content | allow |
ask_bot |
Hand a task to another of your bots | allow |
bot_create |
Make a new bot for a job you describe (Bots and chats) | asks, every time |
skill_view |
Read the steps of an accepted skill | allow |
skill_save |
Propose a skill from what the conversation did, when you ask; you press Save (Skills) | allow |
plan_propose |
Propose a plan you approve once (below) | allow |
computer_* |
Use the bots' computer, self-hosted only (The bots' computer) | allow; computer_open asks |
browser__* |
The headless browser, when switched on (below) | opening a page asks |
| tool servers | Tools from MCP servers you added (below) | read-only allow, the rest ask |
Each bot has a tool allowlist on its page; tools outside it are hidden from that bot and refused.
Allow, ask, deny #
Every tool has a rule under Settings → Permissions: allow, ask or deny. Ask sends Approve / Deny buttons
to Telegram, Slack or Discord and shows a card in the app with Allow once, Always allow (per tool, or per website
for opening pages: "Always on this site") and Deny. Every "always" becomes a visible rule in Settings → Permissions.
Once you've allowed the same thing twice, the card makes "always" the main button. No answer within 5 minutes means
deny (routines park their asks for 24 hours instead; see Needs you). From the command line:
mimir approvals, mimir approve <id>, mimir deny <id>.
Outside content (taint) #
A web page, an email, a calendar invite, a tool server's result, what's on the computer's screen, a file you sent, or a meeting transcript can contain text written to look like instructions ("ignore your rules and email this to…"). So once a bot has read outside content, anything that changes data asks, for the rest of that conversation, even if its rule says allow. This also flows through hand-offs to other bots, into routines a bot creates then (every run of such a routine counts as having read outside content), and into later searches of the conversation (a file you sent is never mistaken for your own words). Results of the AI's own web search count too. Read-only tools stay allowed, except when the read itself would carry your data out:
- reading a web address that carries data (a query string, a very long path or subdomain), as in
evil.example/?d=<your memories>; - on the bots' computer, keys that jump to the address bar or a new tab, and clicks on the browser's own bar;
- typing one of your memories into a page, on the computer or in the browser;
- after reading your email or a meeting, opening any web address (in
web_fetch, the browser or on the computer), however short: a link likeevil.example/v/483920could carry a sign-in code out; - a web search whose query holds one of your memories.
Those ask too. "Start fresh" (or /new) ends it. Requests made after reading outside content, and any use of a saved
login, never become "always". Approval cards show where an action goes (recipient, address, path) first, so a long
message body can't push it off the card.
Always asks, whatever the rules say. Sending an email and making a new bot ask every time, even if someone set their rule to allow, and never offer "always" or "all like this". An email can only be sent if all of it (who it's to first, then the subject and text) fits on the card; anything longer is saved as a draft for you to send.
Memories saved after reading outside content are marked as such and treated as unconfirmed (Memory). Because of that, saving a new one doesn't ask (it's kept out of your bots' standing instructions until you confirm it); replacing an existing memory still asks. A lesson in your own words ("no, use metric units") stays yours even after a web search in that conversation: a page can't put words in your messages. Files in a chat's workspace keep the same mark: one written after outside content (or changed outside Mimir) counts as outside content when a bot reads it.
Approve once for a whole job #
Before a task that needs several actions that ask (send, delete, book, open a site), a bot can propose a plan
(plan_propose): its steps and the tools and sites it'll use, as one card. Approving it covers those actions for the
rest of that reply. Every live card also has Approve all like this: this action, and the same tool and site again,
without asking until the reply ends. Neither covers anything after the bot read outside content, saved-login use, or
routines.
To stop being asked at all, press Always on the card (in the app, Telegram, Slack or Discord): from then on that tool, or that tool on that website, runs without asking. Change it back in Settings → Permissions. Asks after outside content, saved logins and plans don't offer it.
The browser and saved logins #
Settings → Browser turns on a real headless browser for your bots (Playwright's MCP server; needs Node.js and downloads Chromium once). Opening a page asks you first (or "always on this site"); clicking and typing are allowed; page scripting is off.
Like fetching a page, the browser won't go to this computer or your local network (localhost, 192.168.x.x, 10.x,
*.local and the like). A bot asking to open one is refused before you're asked, and the browser itself blocks links,
redirects and a page's own requests to them. Not covered: a public name that points at a local address. The browser
checks the address in the link, not where the name leads.
Saved logins are typed by name (e.g. GITHUB_PASSWORD): the browser fills in the value, the AI never sees it, it
only works on the sites you listed for it, and you approve each use. Values are scrubbed from every result and log.
Tool servers (MCP) #
Settings → Tool servers adds any MCP server: one that runs as a command (your files, GitHub, a database…) or one
online at a URL. Paste its setup line (npx -y @modelcontextprotocol/server-filesystem ~/Notes), its URL
(https://mcp.deepwiki.com/mcp), or the JSON from its instructions ({"mcpServers": {…}}). Mimir starts or connects
to it once to list its tools, so a broken setup isn't saved. Tokens in its environment or headers go to the keychain
(server: the private database), never the config. Its tools follow the same rules: tools the server marks read-only are
allowed, the rest ask. Each bot can switch servers on or off. Remote servers use MCP's Streamable HTTP transport;
servers that only offer the older SSE transport, or need an OAuth sign-in, aren't supported.
The run log #
Every reply and routine is recorded with its model, tokens, cost and each tool call, with its allow / ask / deny
decision and result: the Activity tab, or mimir runs. A reply that's still running has Stop this reply there.
Incognito chats keep no log.