Atlas / MCP servers / bh-rat / Context Awesome

Context AwesomeBLOCK

mcp/bh-rat/context-awesome

awesome-lists now available as CLI & MCP server for your agent.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
3 3r · 0w · 0d
Transport
sse · stdio · streamable-http
License
MIT
Stars
61
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://modelcontextprotocol.io)

A Model Context Protocol (MCP) server that provides access to all the curated awesome lists and their items. It can provide the best resources for your agent from sections of the 8500+ awesome lists on github and more then 1mn+ (growing) awesome row items.

What are Awesome Lists? Awesome lists are community-curated collections of the best tools, libraries, and resources on any topic - from machine learning frameworks to design tools. By adding this MCP server, your AI agents get instant access to these high-quality, vetted resources instead of relying on random web searches.

Perfect for :

  1. Knowledge worker agents to get the most relevant references for their work
  2. The source for the best learning resources
  3. Deep research can quickly gather a lot of high quality resources for any topic.
  4. Search agents

https://github.com/user-attachments/assets/babab991-e4ff-4433-bdb7-eb7032e9cd11

Two Ways to Use Context Awesome

Both modes ship from the same npm package (context-awesome) and hit the same hosted backend.

MCP Tools

Every MCP tool has a 1:1 CLI subcommand — the server and the CLI expose t

Read from source at commit 8c2313badf65OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add context-awesome -- npx -y [email protected]
03

Exposed tools (3)

3 read · 0 write · 0 destructive.

ToolRiskDescription
find_awesome_sectionread
get_awesome_itemsread
search_awesome_itemsread
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (4)

HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
ATTRIBUTION.md:3598
- [ih0kn3m/awesome-ps4-jailbreak](https://github.com/ih0kn3m/awesome-ps4-jailbreak)
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
ATTRIBUTION.md:8470
- [yueliu1999/awesome-jailbreak-on-llms](https://github.com/yueliu1999/awesome-jailbreak-on-llms)
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, commander, node-fetch, picocolors, zod, @types/express, @types/jest, @types/node
Why it matters. 17 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 8c2313badf65full audit observations/trust-audit/mcp-server/bh-rat__context-awesome.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-088c2313badf65BLOCKD69first audit
06

Questions

What is the Context Awesome MCP server?

awesome-lists now available as CLI & MCP server for your agent.

What tools does Context Awesome expose?

3 in total: 3 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Context Awesome safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Context Awesome need?

It reads AWESOME_CONTEXT_API_KEY and CONTEXT_AWESOME_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Context Awesome run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as context-awesome at 0.1.1.

How current is this page?

The grade is for one exact copy of the source (8c2313badf65), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement