// HACKER NEWS — CYBERSECURITY
Show HN: Mole – Deep research agent for your terminal
A deep-research agent with an enforced budget, verified quotes, and a privacy
boundary for local data.
Ask a question. mole decomposes it, searches, reads sources, extracts claims,
checks each claim against the text it came from, looks for contradictions between
them, and writes an answer with citations. Every model call is reserved against a
budget before it happens and settled after, so the ceiling you set is the ceiling
it hits.
It runs as a single static binary on your machine, uses your own API keys, and
speaks MCP so a coding agent can drive it — either by handing mole a question and
collecting the answer, or, in toolkit mode, by doing the reasoning with its own
model while mole supplies the parts that are not model calls.
Three things mole does that a chat interface with web search does not.
The budget is enforced, not estimated. Every call is reserved before it is
made and settled after, against a ledger with non-negative constraints in the
database schema itself. --usd 0.50 means the run stops at fifty cents. Measured
overshoot across the test corpus is 0%.
Every claim carries a quote, checked against the source. A claim whose quote
does not appear verbatim in the page it was mined from is discarded at extraction,
before it can reach an answer. Claims that survive can be re-read against their
source afterwards, and one that turns out not to be supported is marked as such in
the report rather than quietly dropped.
Your local data stays local. Point mole at a CSV or a folder and it will
analyse it without the contents leaving your machine: the model chooses a
hypothesis template and column names, mole renders and runs the SQL, and only
aggregates — counts, means, test results, buckets covering at least five records —
are allowed back. mole crossings shows you exactly what left.
Downloads the release archive for your platform, verifies its SHA-256 against the
checksums published with the release, and installs mole and mole-mcp into
~/.local/bin (or /usr/local/bin if that is writable). It uses sudo only if
the target directory needs it, and --dry-run shows what it would do. If piping a
script into a shell makes you uneasy — reasonable — read it first, or use one of
the paths below.
Fully qualified, and it has to be: an unrelated mole (a macOS cleanup tool) is in
homebrew/core, so brew install mole will always mean that one. Both install a
binary called mole, so only one can be linked at a time.
Not mole: that name and mole-bin on the AUR belong to an SSH tunnelling tool
that has held them since 2020. The package installs /usr/bin/mole and declares
the conflict, so pacman will tell you rather than overwrite anything.