Mimir

Tools, approvals and safety

Bots act through tools. Every tool call is checked against your rules before it runs, and recorded.

Built-in tools #

Tool What it does Default
memory_store, memory_search Save and look up memories (Memory) allow
chat_search Search earlier conversations with you (any of your bots) for what was said but not saved allow
memory_forget Forget a memory ask
routine_create, routine_list Schedule and list routines, recurring or once (a reminder) (Routines) allow
routine_delete Delete a routine ask
web_fetch Read a web page (outside content; never this computer or your local network: addresses, names that resolve there, and redirects are all checked) allow
calendar_add Make one-click "add to calendar" links (Google Calendar, Outlook) for an event; you open one and save it, nothing is added for you allow
email_search, email_read Search and read your email, read-only (Settings → Email: IMAP with an app password); offered once set up, in a chat with you only. Nothing is marked read, moved or deleted (the mailbox is only examined); emails are outside content allow
email_draft Write an email (or a reply in its thread) into your Drafts folder; nothing is sent, you send it from your mail app. After reading outside content (an email included) it asks, with the recipient first on the card allow
file_list, file_read, file_write A text-file workspace per chat (notes, lists, drafts, research), shown under Memory → Files. Paths stay inside it (no .., no links); rewriting keeps the previous version; a file written after outside content (or dropped in by hand) counts as outside content when read. Not in incognito allow
file_delete Delete a workspace file ask
email_send Send an email as you, after you approve it: every email asks (never "Always"), with who it's to first and the whole text on the card; one too long for the card has to be a draft instead; at most 20 a day from a chat. Sent through your outgoing server (worked out from the incoming one, or set in Settings → Email), with a copy in your Sent folder asks, every time
web_search Search the web through Settings → Web search (Brave Search with a free key, or your own SearXNG), for every AI account; offered once one is set up. Results are outside content; after outside content, a search that would carry one of your memories (or over 200 characters) asks allow
meeting_search, meeting_read Look through your transcribed meetings (Meetings); offered once you have one allow
calendar_create Add an event straight to your calendar (Settings → Calendar: iCloud, Fastmail, Nextcloud or any CalDAV, with an app password); offered once one is connected, in a chat with you only. The card shows when, what and where; "Always" works for it ask
calendar_list Read your calendar between two dates (from the calendar link in Settings); offered once one is linked, in a chat with you only. Event titles are outside content allow
ask_bot Hand a task to another of your bots allow
bot_create Make a new bot for a job you describe (Bots and chats) asks, every time
skill_view Read the steps of an accepted skill allow
skill_save Propose a skill from what the conversation did, when you ask; you press Save (Skills) allow
plan_propose Propose a plan you approve once (below) allow
computer_* Use the bots' computer, self-hosted only (The bots' computer) allow; computer_open asks
browser__* The headless browser, when switched on (below) opening a page asks
tool servers Tools from MCP servers you added (below) read-only allow, the rest ask

Each bot has a tool allowlist on its page; tools outside it are hidden from that bot and refused.

Allow, ask, deny #

Every tool has a rule under Settings → Permissions: allow, ask or deny. Ask sends Approve / Deny buttons to Telegram, Slack or Discord and shows a card in the app with Allow once, Always allow (per tool, or per website for opening pages: "Always on this site") and Deny. Every "always" becomes a visible rule in Settings → Permissions. Once you've allowed the same thing twice, the card makes "always" the main button. No answer within 5 minutes means deny (routines park their asks for 24 hours instead; see Needs you). From the command line: mimir approvals, mimir approve <id>, mimir deny <id>.

Outside content (taint) #

A web page, an email, a calendar invite, a tool server's result, what's on the computer's screen, a file you sent, or a meeting transcript can contain text written to look like instructions ("ignore your rules and email this to…"). So once a bot has read outside content, anything that changes data asks, for the rest of that conversation, even if its rule says allow. This also flows through hand-offs to other bots, into routines a bot creates then (every run of such a routine counts as having read outside content), and into later searches of the conversation (a file you sent is never mistaken for your own words). Results of the AI's own web search count too. Read-only tools stay allowed, except when the read itself would carry your data out:

Those ask too. "Start fresh" (or /new) ends it. Requests made after reading outside content, and any use of a saved login, never become "always". Approval cards show where an action goes (recipient, address, path) first, so a long message body can't push it off the card.

Always asks, whatever the rules say. Sending an email and making a new bot ask every time, even if someone set their rule to allow, and never offer "always" or "all like this". An email can only be sent if all of it (who it's to first, then the subject and text) fits on the card; anything longer is saved as a draft for you to send.

Memories saved after reading outside content are marked as such and treated as unconfirmed (Memory). Because of that, saving a new one doesn't ask (it's kept out of your bots' standing instructions until you confirm it); replacing an existing memory still asks. A lesson in your own words ("no, use metric units") stays yours even after a web search in that conversation: a page can't put words in your messages. Files in a chat's workspace keep the same mark: one written after outside content (or changed outside Mimir) counts as outside content when a bot reads it.

Approve once for a whole job #

Before a task that needs several actions that ask (send, delete, book, open a site), a bot can propose a plan (plan_propose): its steps and the tools and sites it'll use, as one card. Approving it covers those actions for the rest of that reply. Every live card also has Approve all like this: this action, and the same tool and site again, without asking until the reply ends. Neither covers anything after the bot read outside content, saved-login use, or routines.

To stop being asked at all, press Always on the card (in the app, Telegram, Slack or Discord): from then on that tool, or that tool on that website, runs without asking. Change it back in Settings → Permissions. Asks after outside content, saved logins and plans don't offer it.

The browser and saved logins #

Settings → Browser turns on a real headless browser for your bots (Playwright's MCP server; needs Node.js and downloads Chromium once). Opening a page asks you first (or "always on this site"); clicking and typing are allowed; page scripting is off.

Like fetching a page, the browser won't go to this computer or your local network (localhost, 192.168.x.x, 10.x, *.local and the like). A bot asking to open one is refused before you're asked, and the browser itself blocks links, redirects and a page's own requests to them. Not covered: a public name that points at a local address. The browser checks the address in the link, not where the name leads.

Saved logins are typed by name (e.g. GITHUB_PASSWORD): the browser fills in the value, the AI never sees it, it only works on the sites you listed for it, and you approve each use. Values are scrubbed from every result and log.

Tool servers (MCP) #

Settings → Tool servers adds any MCP server: one that runs as a command (your files, GitHub, a database…) or one online at a URL. Paste its setup line (npx -y @modelcontextprotocol/server-filesystem ~/Notes), its URL (https://mcp.deepwiki.com/mcp), or the JSON from its instructions ({"mcpServers": {…}}). Mimir starts or connects to it once to list its tools, so a broken setup isn't saved. Tokens in its environment or headers go to the keychain (server: the private database), never the config. Its tools follow the same rules: tools the server marks read-only are allowed, the rest ask. Each bot can switch servers on or off. Remote servers use MCP's Streamable HTTP transport; servers that only offer the older SSE transport, or need an OAuth sign-in, aren't supported.

The run log #

Every reply and routine is recorded with its model, tokens, cost and each tool call, with its allow / ask / deny decision and result: the Activity tab, or mimir runs. A reply that's still running has Stop this reply there. Incognito chats keep no log.