Atlas / MCP servers / context-engine-ai / Context-Engine

Context-EngineBLOCK

mcp/context-engine-ai/context-engine-4

Context-Engine MCP - Agentic Context Compression Suite

Verdict
BLOCK
Grade
F
Trust score
55 /100
Exposed tools
25 22r · 2w · 1d
Transport
sse · stdio · streamable-http
License
MIT
Stars
402
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Context Engine

Semantic code search, memory, and symbol intelligence for AI coding assistants.

Get your free account at dev.context-engine.ai

Website · Get Started · License

Install Skills

Context Engine ships AI agent skills that teach your coding assistant how to use 30+ MCP tools for semantic search, symbol graph navigation, memory, and more.

Claude Code / Claude Desktop

Recommended: Install natively from the public GitHub repo:

# Add the marketplace (one-time)
/plugin marketplace add Context-Engine-AI/Context-Engine

# Install the skill
/plugin install context-engine

This pulls the skill directly from GitHub and auto-loads MCP tool guidance into your session.

Alternatively, copy the rules file manually:

cp -r skills/context-engine/ your-project/.claude/

Cursor

Context Engine rules are included in .cursorrules at the root of your workspace. Cursor picks this up automatically when the file is present.

# Copy to your project root
cp .cursorrules your-project/.cursorrules

Codex (OpenAI)

Recommended: Install natively using the built-in skill installer — just ask Codex:

"Install the context-engine skill from https://github.com/Context-Engine-AI/Context-Engine"

Codex will pull .codex/skills/context-engine/ (including SKILL.md and reference docs) into ~/.codex/skills/ automatically.

Or install manually:

cp -r .codex/skills/context-engine/ ~/.codex/skills/context-engine/

Windsurf

cp -r .codex/skills/ your-project/.codex/skills/

Augment Code

cp -r .augment/ your-project/.augment/

Gemini

cp GEMINI.md
Read from source at commit c39f0761d319OBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add context-engine --env CLICKHOUSE_PASSWORD=${CLICKHOUSE_PASSWORD} --env COMMIT_SUMMARY_MAX_TOKENS=${COMMIT_SUMMARY_MAX_TOKENS} --env CTXCE_AUTH_ADMIN_TOKEN=${CTXCE_AUTH_ADMIN_TOKEN} --env CTXCE_AUTH_ALLOW_OPEN_TOKEN_LOGIN=${CTXCE_AUTH_ALLOW_OPEN_TOKEN_LOGIN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "context-engine": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "CLICKHOUSE_PASSWORD": "${CLICKHOUSE_PASSWORD}",
        "COMMIT_SUMMARY_MAX_TOKENS": "${COMMIT_SUMMARY_MAX_TOKENS}",
        "CTXCE_AUTH_ADMIN_TOKEN": "${CTXCE_AUTH_ADMIN_TOKEN}",
        "CTXCE_AUTH_ALLOW_OPEN_TOKEN_LOGIN": "${CTXCE_AUTH_ALLOW_OPEN_TOKEN_LOGIN}"
      }
    }
  }
}
03

Exposed tools (25)

22 read · 2 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
change_history_for_pathreadSummarize recent change metadata for a file path from the index.
code_searchreadExact alias of repo_search (hybrid code search with reranking enabled by default).
collection_mapreadReturn collection↔repo mappings with optional Qdrant payload samples.
context_answer_compatreadCompatibility wrapper for context_answer (lenient argument handling).
context_searchreadBlend code search results with memory-store entries (notes, docs) for richer context.
expand_queryreadLLM-assisted query expansion (local llama.cpp, if enabled).
list_workspacesreadScan search_root recursively for .codebase/state.json and summarize workspaces.
memory_findreadFind memory-like entries by vector similarity (dense + lexical fusion).
memory_storereadStore a memory entry into Qdrant (dual vectors consistent with indexer).
pattern_searchreadFind structurally similar code patterns across all languages.
qdrant_indexreadIndex the workspace (/work) or a specific subdirectory.
qdrant_index_rootreadInitialize or refresh the vector index for the workspace root (/work).
qdrant_listreadList available Qdrant collections.
qdrant_prunedestructiveRemove stale points for /work (files deleted/moved but still in the index).
qdrant_statusreadSummarize collection size and recent index timestamps.
repo_searchreadZero-config code search over repositories (hybrid: vector + lexical RRF, rerank ON by default).
repo_search_compatreadCompatibility wrapper for repo_search (lenient argument handling).
search_callers_forreadHeuristic search for callers/usages of a symbol.
search_commits_forwriteSearch git commit history indexed in Qdrant.
search_config_forreadFind likely configuration files for a service/query.
search_importers_forreadFind files likely importing or referencing a module/symbol.
search_tests_forreadFind test files related to a query.
set_session_defaultswriteSet defaults (e.g., collection, mode, under) for subsequent calls.
symbol_graphreadQuery the symbol graph to find callers, definitions, or importers.
workspace_inforeadRead .codebase/state.json for the current workspace and resolve defaults.
04

Trust audit

BLOCKgrade F · trust 55/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (11 observation(s))
Shell
declared (6 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
bench/run_matrix.py:447
help="Path to query file for latency eval (one query per line)"
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
bench/run_matrix.py:451
help="Path to gold queries JSONL for quality eval (Hit@k, MRR)"
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
.DS_Store
.DS_Store
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/ast_analyzer.py:81
mod = __import__(pkg_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
scripts/ingest/tree_sitter.py:74
mod = __import__(pkg_name)
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env:240
# MCP_INDEXER_URL=http://127.0.0.1:30810/mcp
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
qdrant_prune
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.DS_Store
.DS_Store
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.indexignore
.indexignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.qdrantignore
.qdrantignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
tests/test_ts_extractors.py:54
__import__(pkg)
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/ast_analyzer.py:489
content_hash = hashlib.md5(func_content.encode()).hexdigest()[:8]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/benchmarks/core_indexer.py:388
return hashlib.md5(doc_id.encode()).hexdigest()
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/benchmarks/cosqa/dataset.py:229
content_hash = hashlib.md5(code.encode("utf-8", errors="ignore")).hexdigest()[:12]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/benchmarks/cosqa/dataset.py:245
content_hash = hashlib.md5(query.encode("utf-8", errors="ignore")).hexdigest()[:12]
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
scripts/benchmarks/experiment.py:67
idx = int(hashlib.md5(query_hash.encode()).hexdigest(), 16) % len(self.variants)
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
deploy/kubernetes/Makefile:149
docker build -t $(IMAGE_REGISTRY)/context-engine:$(IMAGE_TAG) ../../
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_upload_service_path_traversal.py:62
[{"operation": "created", "path": "../../evil.txt"}],
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_upload_service_path_traversal.py:197
"source_path": "../../escape.txt",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/test_upload_service_path_traversal.py:226
{"operation": "created", "path": "../../evil.txt"},
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
ctx-mcp-bridge/README.md:101
`http://127.0.0.1:30810/mcp`) and is what the VS Code extension uses in its
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
ctx-mcp-bridge/README.md:123
http://127.0.0.1:<port>/mcp

Gates applied: no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha c39f0761d319full audit observations/trust-audit/mcp-server/context-engine-ai__context-engine-4.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-01c39f0761d319BLOCKF55first audit
06

Questions

What is the Context-Engine MCP server?

Context-Engine MCP - Agentic Context Compression Suite

What tools does Context-Engine expose?

25 in total: 22 read-only, 2 that write, and 1 that can delete or overwrite (qdrant_prune). Every one is listed on this page with its risk.

Is Context-Engine safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (55/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Context-Engine need?

It reads CLICKHOUSE_PASSWORD, COMMIT_SUMMARY_MAX_TOKENS, CTXCE_AUTH_ADMIN_TOKEN, CTXCE_AUTH_ALLOW_OPEN_TOKEN_LOGIN, CTXCE_AUTH_BACKEND_URL, CTXCE_AUTH_DB_URL, CTXCE_AUTH_ENABLED, CTXCE_AUTH_PASSWORD, CTXCE_AUTH_SESSION_TTL_SECONDS, CTXCE_AUTH_SHARED_TOKEN, CTXCE_AUTH_TOKEN and CTXCE_AUTH_USERNAME from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Context-Engine run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as context-engine at 0.0.1.

How current is this page?

The grade is for one exact copy of the source (c39f0761d319), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement