moltis

moltis

MCP.Pizza Chef: moltis-org

This is a full personal assistant that lives on a computer or server you own instead of a company's cloud, so your conversations, memory, and files stay in your control. It can talk with you by voice, message you back on Telegram, WhatsApp, Discord, or Microsoft Teams, remember what you've told it before, run tasks automatically on a schedule, and work inside Cursor for coding help. Setting it up takes some technical comfort, using Docker, and you'll need an account with an AI provider such as OpenAI, Claude, or Gemini to give it a brain.

Coding
Communication

Use This MCP server To

Chat with my own AI assistant by voice Get replies from my assistant right in Telegram or WhatsApp Have my assistant remember details from earlier conversations Set up tasks that run automatically on a schedule Get coding help inside Cursor without sending data to someone else's cloud Keep my AI conversations private on my own computer Let my assistant handle web tasks and errands for me

README

Moltis

Moltis — A secure persistent personal agent server in Rust

One binary — sandboxed, secure, yours.

CI codecov CodSpeed License: MIT Rust Discord

Installation • Comparison • Architecture • Security • Features • How It Works • Contributing


Moltis recently hit the front page of Hacker News. Please open an issue for any friction at all. I'm focused on making Moltis excellent.

Secure by design — Your keys never leave your machine. Every command runs in a sandboxed container, never on your host.

Your hardware — Runs on a Mac Mini, a Raspberry Pi, or any server you own. One Rust binary, no Node.js, no npm, no runtime.

Full-featured — Voice, memory, cross-session recall, automatic edit checkpoints, scheduling, Telegram, Signal, Discord, browser automation, MCP servers, SSH or node-backed remote exec, managed deploy keys with host pinning in the web UI, a live Settings → Tools inventory, Cursor-compatible project context, and context-file threat scanning — all built-in. No plugin marketplace to get supply-chain attacked through.

Auditable — The agent runner and model interface fit in ~7.5K lines, with providers in ~19K more. The Rust workspace is ~270K lines across 59 modular crates you can audit independently, with 470+ Rust files containing tests. Unsafe code is isolated to FFI and precompiled runtime boundaries, not the core agent loop.

Installation

# One-liner install script (macOS / Linux)
curl -fsSL https://www.moltis.org/install.sh | sh

# macOS / Linux via Homebrew
brew install moltis-org/tap/moltis

# Docker (multi-arch: amd64/arm64)
docker pull ghcr.io/moltis-org/moltis:latest

# Or build from source
cargo install moltis --git https://github.com/moltis-org/moltis

moltis FAQ

Can I use this to get an AI assistant that texts me on WhatsApp or Telegram?
Yes — it can send and receive messages through Telegram, WhatsApp, Discord, and Microsoft Teams, so you can talk to your assistant from apps you already use.
Can I use this to keep my conversations and files private?
Yes — it runs on a computer or server you own, such as a Mac Mini or a Raspberry Pi, instead of sending your data to someone else's cloud service.
Do I need an account with an AI company to use this?
Yes. This is the assistant framework itself — you connect it to an AI provider such as OpenAI, Claude, or Gemini using your own account and access key.
Which apps does this work with?
It connects to Cursor for coding help, plus Telegram, WhatsApp, Discord, Microsoft Teams, and Signal for messaging, and it also has its own web interface you can use directly.
How hard is it to set up?
It currently takes some technical comfort — you install it with Docker or a command-line installer and edit a few configuration settings, so it suits someone willing to follow setup instructions.
Will it remember what I've told it in past conversations?
Yes — it keeps a memory of past sessions so it can recall earlier details instead of starting fresh every time you talk to it.
Can it talk to me out loud instead of just typing?
Yes — it includes built-in voice features, so you can speak to it and hear it respond back.
Is my data sent to a third-party plugin store?
No — everything runs in one program on your own hardware, and anything it does stays inside a locked-down, isolated space, so there is no outside plugin marketplace involved.