# notes_search

Full-text search in your notebook. By default searches only your own notes. Pass filter_agent_id=<int> to search another agent's notebook, or "all" (or "*") for workspace-wide. Or list all notes for a person/thread by scope_ref_id.

Agent View of the PolicyLayer registry record for `notes_search`. HTML page: https://policylayer.com/tools/io-github-saloprj-dialogbrain/notes-search

## Facts

- Tool: `notes_search`
- Server: Dialogbrain (`https://api.dialogbrain.com/mcp`) — https://policylayer.com/tools/io-github-saloprj-dialogbrain.md
- Homepage: https://github.com/saloprj/dialogbrain-mcp
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 5
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `limit` | integer | no | Max results (default 10, max 50) |
| `query` | string | no | Text to search for in note keys and values. Optional if scope_ref_id is provided. |
| `scope` | string | no | Limit search to scope |
| `scope_ref_id` | string | no | Filter by specific thread_id or person_id. If provided without query, lists all notes for that ref. |
| `filter_agent_id` | string | no | Optional. Omit to search only your own notes. Pass a numeric agent_id as a string (e.g. "57") to search another agent's notebook (read-only). Pass "all" or "*" |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "notes_search",
    "arguments": {}
  }
}
```

## Why notes_search is rated Low

This tool retrieves and queries existing note data without any side effects or modifications. The ability to search across different scopes (own notes, specific agents, workspace-wide) does not elevate it beyond a Read operation. The severity is low because search operations on notes typically have minimal blast radius—they return information but do not alter system state or trigger external actions.

From the tool's own definition: "Tool performs 'full-text search' in a notebook with options to filter by agent or workspace. The description uses query-oriented language: 'search', 'list all notes'. No mention of creating, modifying, or deleting data."

## Use case

AI agents call notes_search to retrieve information from Dialogbrain without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Dialogbrain:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "notes_search": {}
  }
}
```

## Other tools on Dialogbrain (224)

- `agents_delete` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/agents-delete.md
- `agents_trigger_delete` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/agents-trigger-delete.md
- `ai_filters_delete` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/ai-filters-delete.md
- `ai_tags_delete` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/ai-tags-delete.md
- `calendar_delete_event` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/calendar-delete-event.md
- `collections_delete` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/collections-delete.md
- `files_delete` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/files-delete.md
- `folders_delete` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/folders-delete.md
- `integrations_remove_endpoints` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/integrations-remove-endpoints.md
- `messages_delete` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/messages-delete.md
- `notes_delete` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/notes-delete.md
- `reminder_cancel` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/reminder-cancel.md
- `tasks_delete` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/tasks-delete.md
- `threads_delete` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/threads-delete.md
- `widgets_delete` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/widgets-delete.md
- `youtube_delete_comment` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/youtube-delete-comment.md
- `youtube_delete_video` — Destructive — https://policylayer.com/tools/io-github-saloprj-dialogbrain/youtube-delete-video.md
- `agent_handoff` — Execute — https://policylayer.com/tools/io-github-saloprj-dialogbrain/agent-handoff.md
- `agents_simulate_inbound` — Execute — https://policylayer.com/tools/io-github-saloprj-dialogbrain/agents-simulate-inbound.md
- `android_launch_app` — Execute — https://policylayer.com/tools/io-github-saloprj-dialogbrain/android-launch-app.md
- `android_shell` — Execute — https://policylayer.com/tools/io-github-saloprj-dialogbrain/android-shell.md
- `android_ui_dump` — Execute — https://policylayer.com/tools/io-github-saloprj-dialogbrain/android-ui-dump.md
- `background_run` — Execute — https://policylayer.com/tools/io-github-saloprj-dialogbrain/background-run.md
- `browser_attach_meet` — Execute — https://policylayer.com/tools/io-github-saloprj-dialogbrain/browser-attach-meet.md
- `browser_click` — Execute — https://policylayer.com/tools/io-github-saloprj-dialogbrain/browser-click.md
- `browser_close` — Execute — https://policylayer.com/tools/io-github-saloprj-dialogbrain/browser-close.md
- `browser_drag` — Execute — https://policylayer.com/tools/io-github-saloprj-dialogbrain/browser-drag.md
- `browser_evaluate` — Execute — https://policylayer.com/tools/io-github-saloprj-dialogbrain/browser-evaluate.md
- `browser_fill` — Execute — https://policylayer.com/tools/io-github-saloprj-dialogbrain/browser-fill.md
- `browser_fill_form` — Execute — https://policylayer.com/tools/io-github-saloprj-dialogbrain/browser-fill-form.md
- …and 194 more: https://policylayer.com/tools/io-github-saloprj-dialogbrain.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-saloprj-dialogbrain · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-saloprj-dialogbrain
