The main Mulch memory workflow is mostly legitimate, but the package includes broader, under-disclosed behaviors that users should review before installing.
Review before installing. Use project-local, narrowly matched hooks instead of global always-on hooks; record only sanitized technical lessons; do not store secrets, credentials, customer data, private conversations, or sensitive code snippets in Mulch. Treat the Telegram notification feature as unspecified unless you verify the exact implementation. Remove or separately review the bundled visual-explainer folder if you only want the self-improvement memory workflow, because it can scan repos, write persistent HTML files, open a browser, and optionally send project-derived prompts to external image tooling.