Atlas / MCP servers / codefromkarl / ContextAtlas

ContextAtlasSAFE

mcp/codefromkarl/contextatlas

ContextAtlas — context infrastructure for AI coding agents: hybrid retrieval, project memory and retrieval observability via CLI, MCP server or embeddable library. Tree-sitter indexing, LanceDB vector search, FTS5 and token-aware context packing.

Verdict
SAFE
Grade
B
Trust score
85 /100
Exposed tools
30 28r · 1w · 1d
Transport
stdio
License
MIT
Stars
29
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

ContextAtlas

Stable, reusable, and observable code context infrastructure for AI agents

Hybrid Retrieval · Project Memory · MCP Server · Retrieval Observability

=20" />

简体中文 · Docs · First Use · Deployment · CLI · MCP

ContextAtlas is an open-source context infrastructure for AI coding agents — providing hybrid code retrieval, project memory, and retrieval observability as a CLI, MCP server, or embeddable library. It combines tree-sitter semantic chunking, LanceDB vector search, SQLite FTS5 full-text search, and token-aware context packing to deliver structured, high-quality code context to tools like Claude Code, Codex, and custom agent workflows.

Updates

  • 2026-04-15: added git hook auto-maintenance with --quick health check (260x speedup), stale index cleanup CLI, and three
Read from source at commit 31337e0eca77OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add context-atlas --env EMBEDDINGS_API_KEY=${EMBEDDINGS_API_KEY} --env EMBEDDING_GATEWAY_API_KEYS=${EMBEDDING_GATEWAY_API_KEYS} --env EMBEDDING_GATEWAY_REDIS_KEY_PREFIX=${EMBEDDING_GATEWAY_REDIS_KEY_PREFIX} --env OLLAMA_RERANK_MAX_TOKENS=${OLLAMA_RERANK_MAX_TOKENS} -- npx -y @codefromkarl/[email protected]
claude-desktop
{
  "mcpServers": {
    "context-atlas": {
      "command": "npx",
      "args": [
        "-y",
        "@codefromkarl/[email protected]"
      ],
      "env": {
        "EMBEDDINGS_API_KEY": "${EMBEDDINGS_API_KEY}",
        "EMBEDDING_GATEWAY_API_KEYS": "${EMBEDDING_GATEWAY_API_KEYS}",
        "EMBEDDING_GATEWAY_REDIS_KEY_PREFIX": "${EMBEDDING_GATEWAY_REDIS_KEY_PREFIX}",
        "OLLAMA_RERANK_MAX_TOKENS": "${OLLAMA_RERANK_MAX_TOKENS}"
      }
    }
  }
}
03

Exposed tools (30)

28 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
Consumerreadconsumer project
ContextAtlasreadSemantic retrieval
Producerreadsource project
assemble_contextreadAssemble phase-aware context from checkpoint, module memory, and derived code retrieval. Use this to build a minimal context package for overview/debug/implementation/verification/handoff workflows.
codebase-retrievalreadIMPORTANT: This is the PRIMARY tool for searching the codebase. It uses a hybrid engine (Semantic + Exact Match) to find relevant code. Think of it as the
contract_analysisreadcontract check
create_checkpointwriteCreate a durable task checkpoint for later resume or handoff. Use this after research, debugging, or implementation milestones when you want to preserve current task state outside the conversation transcript.
delete_memorydestructiveDelete a feature memory for the current project. This removes the feature memory and cleans coordinated derived state.
detect_changesreadAnalyze git diff changes and map changed lines back to indexed graph symbols, then summarize direct upstream/downstream impact.
find_agent_diaryreadSearch diary entries by keyword, with optional agent/topic filters.
get_dependency_chainread[CROSS-PROJECT] Get all dependencies (recursive) for a module. Uses recursive CTE to traverse the full dependency graph. Great for understanding impact of changes or debugging cascading issues. Examples: - Get all dependencies of AuthService → get_dependency_chain({ project:
get_project_profilereadGet the project profile containing tech stack, structure, and conventions. Returns comprehensive project information including: - Technology stack - Project structure - Key modules - Development conventions - Build/test commands
graph_contextreadReturn the immediate graph neighborhood for one exact symbol name, including parent, upstream, and downstream relations.
graph_impactreadAnalyze downstream / upstream code graph impact for one exact symbol name. Use this after indexing when you need to inspect immediate relations and resolved local impact.
graph_queryreadTrace graph paths from one exact entry symbol across resolved relations such as CALLS and HAS_METHOD.
list_checkpointsreadList durable task checkpoints saved for the current repository.
load_checkpointreadLoad a previously saved task checkpoint for resume or handoff.
maintain_memory_catalogreadPerform maintenance operations for the current project
manage_projectsread[CROSS-PROJECT] Manage projects in the memory hub (register, list, stats). Actions: - register: Register a new project (requires path) - list: List all registered projects - stats: Get memory hub statistics Examples: - manage_projects({ action:
old-profilereadold profile
prepare_handoffreadAssemble a handoff-ready bundle from an existing checkpoint. Use this when an agent needs a compact, structured package for resume or transfer.
read_agent_diaryreadRead recent diary entries for one agent.
record_agent_diaryreadAppend one agent diary entry as journal memory.
record_decisionreadRecord an architectural decision. Use this to document important design decisions, alternatives considered, and rationale. Creates a persistent record for future reference. Required fields: - id: Unique identifier (e.g.,
record_long_term_memoryreadRecord explicit long-term memory, including journal, evidence, and temporal facts. Use this to save durable non-code knowledge with scope and optional validity windows.
record_memoryreadRecord a new feature memory for a module. Use this to document module responsibilities, APIs, dependencies, and data flow. This creates a persistent memory that can be quickly retrieved later. Required fields: - name: Module name - responsibility: What the module does - dir: Source directory
record_result_feedbackreadRecord lightweight result feedback for retrieval quality and memory governance. Use this to mark helpful/unhelpful results, stale memories, or wrong module bindings. Feedback is stored as project-scoped long-term memory with type=
suggest_memoryread[AUTO-RECORD] Suggest memory recording for a specific module. Use this when you want to record a memory but need AI to help extract details. Examples: - suggest_memory({ moduleName:
suggest_phase_boundaryreadSuggest the next workflow phase boundary from current checkpoint and context signals. Use this to decide whether to stay in the current phase or move into implementation, verification, or handoff.
unmapped-toolreadMissing handler
04

Trust audit

SAFEgrade B · trust 85/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (10 observation(s))
Network
declared (4 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (19)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_memory
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.node-version
.node-version
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.suspicious_name · CWE-1104
tests/payload-too-large.test.ts
payload-too-large.test.ts
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/application/memory/executeCheckpoints.ts:120
id: `chk_${crypto.createHash('sha1').update(`${args.repo_path}:${args.title}:${args.goal}:${now}`).digest('hex').slice(0, 12)}`,
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/application/retrieval/resultCard.ts:1472
id: `checkpoint:${crypto.createHash('sha1').update(`${repoPath}:${informationRequest}`).digest('hex').slice(0, 12)}`,
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/db/index.ts:48
return crypto.createHash('md5').update(projectPath).digest('hex').slice(0, 10);
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/memory/MemoryAutoRecorder.ts:468
return `${prefix}-${crypto.createHash('sha1').update(input).digest('hex').slice(0, 12)}`;
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/application/memory/assembleContextFormatter.ts:13
} from '../../memory/types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/application/memory/assembleContextFormatter.ts:14
import type { AssemblyProfileName } from '../../memory/MemoryRouter.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/application/memory/assembleContextStrategy.ts:15
} from '../../memory/types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/application/memory/assembleContextStrategy.ts:16
import type { AssemblyProfileName } from '../../memory/MemoryRouter.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/application/memory/assembleContextStrategy.ts:17
import { MemoryStore } from '../../memory/MemoryStore.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/guides/deployment.md:281
EMBEDDINGS_BASE_URL=http://127.0.0.1:8787/v1/embeddings
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/assemble-context.test.ts:66
process.env.EMBEDDINGS_BASE_URL = 'http://127.0.0.1/embeddings';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/assemble-context.test.ts:69
process.env.RERANK_BASE_URL = 'http://127.0.0.1/rerank';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/codebase-retrieval.test.ts:40
process.env.EMBEDDINGS_BASE_URL = 'http://127.0.0.1/embeddings';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/codebase-retrieval.test.ts:43
process.env.RERANK_BASE_URL = 'http://127.0.0.1/rerank';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@keqingmoe/tree-sitter, @lancedb/lancedb, @modelcontextprotocol/sdk, better-sqlite3, cac, chardet, dotenv, fdir
Why it matters. 23 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
docs/architecture/contextatlas-architecture.png
docs/architecture/contextatlas-architecture.png
Why it matters. 6035494 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 31337e0eca77full audit observations/trust-audit/mcp-server/codefromkarl__contextatlas.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0831337e0eca77SAFEB85first audit
06

Questions

What is the ContextAtlas MCP server?

ContextAtlas — context infrastructure for AI coding agents: hybrid retrieval, project memory and retrieval observability via CLI, MCP server or embeddable library. Tree-sitter indexing, LanceDB vector search, FTS5 and token-aware context packing.

What tools does ContextAtlas expose?

30 in total: 28 read-only, 1 that write, and 1 that can delete or overwrite (delete_memory). Every one is listed on this page with its risk.

Is ContextAtlas safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (85/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does ContextAtlas need?

It reads EMBEDDINGS_API_KEY, EMBEDDING_GATEWAY_API_KEYS, EMBEDDING_GATEWAY_REDIS_KEY_PREFIX, OLLAMA_RERANK_MAX_TOKENS and RERANK_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does ContextAtlas run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @codefromkarl/context-atlas at 0.0.7.

How current is this page?

The grade is for one exact copy of the source (31337e0eca77), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement