# Burrow: a native macOS cleanup and monitoring app with an MCP server for AI agents

> Burrow bundles junk cleanup, app uninstall, disk maps and live system status into one MIT-licensed Mac app, and exposes the same engine to agents over MCP. It is a young project with a mixed-licence binary inside.

**caezium/burrow** — 🐹 Cleanup, app management, maintenance, disk analysis, and live status in one free, open-source, native Mac app + extensive support for AI agents.

- Repository: https://github.com/caezium/burrow
- Website: https://burrow.computer
- Stars: 1,460 · Forks: 176
- Language: Swift
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/caezium-burrow

## What Burrow actually replaces on a Mac

A typical Mac accumulates four separate problems: cache and log junk, leftover files from uninstalled apps, large files you cannot locate, and no long-range view of CPU, memory, disk or battery. Burrow's README frames the app as one place for all four: junk cleanup, a dev-artifact purge, uninstall with leftover removal, duplicate finding, maintenance tasks, disk maps and live status. The target user is a Mac owner who would otherwise install two or three utilities, and, increasingly, someone running an AI coding agent that needs machine-readable access to the same data.

The app is native Swift and SwiftUI, requires macOS 14 or later, and ships under the MIT licence. A Windows preview exists under the windows/ directory and is labelled beta, so the primary platform is clearly macOS. The README is explicit that Burrow is independent and not affiliated with mole.fit, the paid Mole for Mac app; it even tells readers to buy mole.fit if they want to fund the original `mo` CLI's development. That candour is unusual and worth noting, because it frames Burrow as a free reimplementation rather than a competitor pretending to be the original.

## One engine binary behind the whole app

Burrow does not implement cleanup logic in Swift. It bundles `burrow-engine`, described in the README as a single source-available binary whose command surface is modelled on the Mole `mo` CLI. The app is the interface; the engine does the scanning and deletion work. That split matters for two reasons. First, it means the GUI and any agent integration share the same command semantics, so an MCP tool call and a button press should reach the same code path. Second, it means the licence boundary is inside the product: the app is MIT, the engine is FSL-1.1-ALv2, and the README points readers to a separate burrow-engine repository for the engine's own terms.

On the data side, the README states that Burrow keeps months of local metric history in SQLite and runs a built-in MCP server. The screenshots show a History view described as long-range charts over that local SQLite store, and an Activity log of cleans, optimizes and scans. The MCP server is what lets Claude Code, Codex or Cursor query the machine. Safety is handled by consent gating and auditing: Trash-based removals stay recoverable until the Trash is emptied, and permanent deletion requires separate consent and cannot be undone. That is a clear two-tier deletion model, and it is the part of the design I would want documented in most detail.

## Installing Burrow with Homebrew and running a first scan

The README gives a single Homebrew cask command for macOS. Windows users are directed to the releases page instead, since the Windows build is a preview.

```bash
brew install --cask caezium/tap/burrow
```

After installation, the README's Contents list points to a Permissions & Full Disk Access section, which is where you should look before expecting disk analysis to see everything. macOS 14+ is the stated requirement. Once the app is open, the Clean view is the entry point for junk: the screenshots show a scan running with a live reclaimable total, then a completed scan listing reclaimable space. Deletions go to the Trash by default, so a mistaken clean is recoverable until you empty it.

For the agent side, the README describes pointing an MCP-capable client at Burrow. A screenshot caption names `burrow_snapshot` as a tool an agent can call and have explained in plain language, and mentions local models via LM Studio as an option alongside Claude Code. The README does not print a full MCP configuration block, so the exact client config is something you will have to take from the repository's own docs rather than from this article.

## The licence is split, and the engine is the half that matters

The repository LICENSE is MIT, but the README states plainly that `burrow-engine` is a separate source-available binary under the Functional Source License, FSL-1.1-ALv2. FSL is not an OSI open-source licence; it is source-available with a conversion to Apache 2.0 after a set period, and the README does not spell out that period here. If your organisation's policy is "MIT only" or "OSI-approved only", the app passing and the engine failing is a real outcome, and you should check the burrow-engine repository directly rather than assuming the top-level LICENSE covers the whole bundle.

The README also carries an explicit non-affiliation notice regarding mole.fit and states that Burrow's name, mark, palette and copy are original. That is a trademark and attribution posture, not a legal guarantee, and it is the kind of statement that exists because the project is modelled on another tool's command surface. If you are evaluating Burrow for commercial redistribution rather than personal use, the engine licence is the first thing to read, not the last.

## Where Burrow is the wrong tool

Burrow is a consumer-facing Mac utility, and several of its properties follow from that. The Windows build is described as a beta preview living under windows/, so anyone needing parity across a mixed fleet should not plan around it. macOS 14+ excludes older machines that still run fine with other cleaners. Full Disk Access is a stated requirement, which means granting a third-party app broad read access to your filesystem; the README has a Permissions section and a separate SECURITY.md, and those are the documents to read before granting it on a work laptop.

There is also the maintenance question. Burrow's last push to the default branch was on 2026-09-10, and the most recent release listed is v0.14.0 from 2026-08-10. That is recent activity, but the version numbers are still in the 0.x range and the release cadence in August 2026 shows three releases within two days, which reads more like rapid iteration than a settled 1.0. If you need a tool with a long support history and a formal deprecation policy, this is not that yet. And if your actual need is a scriptable CLI for servers rather than a GUI for a desktop, the engine's command surface is modelled on `mo`, so evaluating `mo` itself may be the shorter path.

## How Burrow differs from Mole and from single-purpose cleaners

The closest comparison is Mole, and the README makes the relationship explicit: Burrow's engine commands mirror Mole's `mo` CLI, and Burrow is not affiliated with mole.fit, the paid Mole for Mac app. The practical difference is packaging and price. Mole for Mac is a $19 paid app whose author also maintains the `mo` CLI; Burrow is free, MIT at the app layer, and bundles an engine binary under FSL. If you want to support the original work, the README says to buy mole.fit.

The other comparison is against single-purpose Mac cleaners that do one thing well and nothing else. Burrow's bet is consolidation plus agent access: cleanup, uninstall, disk maps, maintenance and live status in one window, with an MCP server so an agent can read the same state and act on it. That is a different product category from a cleaner that only deletes caches. Whether consolidation is an advantage depends on whether you want one app holding Full Disk Access or several narrower ones.

## Upgrade cost and what to check before trusting it

Upgrades run through the same Homebrew cask, so `brew upgrade --cask burrow` is the expected path for a cask-installed app, though the README does not document rollback. Because the app embeds an engine binary, an app upgrade can change engine behaviour, and the release notes in RELEASES.md are where that should be recorded. The repository also contains TELEMETRY.md and SECURITY.md at the top level, plus a NOTICE file, which suggests the project has thought about what it sends and what it discloses.

Before adopting, read three things in this order: TELEMETRY.md to see what leaves your machine, SECURITY.md for the threat model around an app that holds Full Disk Access, and the burrow-engine repository for the FSL terms. Then check the Permissions & Full Disk Access section of the README against your macOS version. The app's own Activity log and the Trash-first deletion model are the safety nets you are relying on; confirm both behave as described on your machine before letting an agent run cleans autonomously.

## Conclusion

Adopt Burrow if you want a single native Mac app for cleanup, uninstalls, disk maps and live status, and you are comfortable with a bundled binary under FSL-1.1-ALv2 sitting inside an otherwise MIT project. Skip it if you need a stable, audited tool for a fleet of production machines, or if you are on Windows and need more than the preview under windows/. Before relying on it, read SECURITY.md and TELEMETRY.md, confirm the Full Disk Access requirement on macOS 14+, and check the licence terms of burrow-engine separately from the app's MIT licence.

## FAQ

### What is Burrow for Mac?

Burrow is a free, MIT-licensed native macOS app that combines junk cleanup, app uninstall with leftover removal, duplicate finding, maintenance, disk maps and live system status. It requires macOS 14 or later and bundles its own engine binary, burrow-engine, so there is nothing else to install.

### How do I install Burrow on macOS?

The README gives a single Homebrew cask command: brew install --cask caezium/tap/burrow. Windows users are directed to the releases page instead, because the Windows build is a preview under the windows/ directory.

### Does Burrow work with AI agents like Claude Code or Cursor?

Yes. The README states that Burrow runs a built-in MCP server so agents such as Claude Code, Codex and Cursor can watch, query and act on the machine, with actions consent-gated and audited. A screenshot caption names burrow_snapshot as a tool an agent can call and have explained in plain language.

### Is Burrow the same as Mole for Mac?

No. The README states that Burrow is independent and not affiliated with or endorsed by mole.fit, the paid Mole for Mac app. Burrow's engine command surface is modelled on the Mole mo CLI, and the README suggests buying mole.fit if you want to fund mo's development.

### What licence is Burrow under?

The repository LICENSE is MIT, but the README states that the bundled burrow-engine binary is source-available under the Functional Source License FSL-1.1-ALv2. The two licences cover different parts of the product, so check the burrow-engine repository for the engine's terms.

## Sources

- [caezium/burrow on GitHub](https://github.com/caezium/burrow)
- [License: MIT](https://github.com/caezium/burrow/blob/main/LICENSE)
- [Project website](https://burrow.computer)
- [README](https://github.com/caezium/burrow/blob/main/README.md)
- [Releases](https://github.com/caezium/burrow/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/caezium-burrow
